Skip to content

ci: introduce CodeQL #10

ci: introduce CodeQL

ci: introduce CodeQL #10

Workflow file for this run

---
# vi: ts=2 sw=2 et:
name: "CodeQL"
on:
push:
branches:
- main
pull_request:
branches:
- main
jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
security-events: write
concurrency:
group: ${{ github.workflow }}-${{ matrix.ref }}-${{ matrix.language }}
cancel-in-progress: true
strategy:
fail-fast: false
matrix:
language: ['c-cpp', 'javascript-typescript', 'python' ]
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: +security-extended,security-and-quality
- name: Install dependencies
if: ${{ matrix.language == 'c-cpp' }}
run: |
sudo add-apt-repository -y --no-update --enable-source
sudo apt update
sudo apt build-dep -y policykit-1
# polkit in Ubuntu Jammy (ATTOW) doesn't have the latest build dependencies yet
sudo apt install -y duktape-dev meson
# Can't use autobuild here, since it doesn't build tests, examples, and other stuff
- name: Build polkit
if: ${{ matrix.language == 'c-cpp' }}
run: |
meson build -Dtests=true -Dexamples=true -Dintrospection=true -Dsession_tracking=libsystemd-login
ninja -C build
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:${{matrix.language}}"