--- # vi: ts=2 sw=2 et: name: "CodeQL" on: push: branches: - master pull_request: branches: - master permissions: contents: read jobs: analyze: name: Analyze runs-on: ubuntu-22.04 concurrency: group: ${{ github.workflow }}-${{ matrix.language }}-${{ github.ref }} cancel-in-progress: true permissions: actions: read security-events: write strategy: fail-fast: false matrix: language: ['cpp', 'python'] steps: - name: Checkout repository uses: actions/checkout@v4 - name: Initialize CodeQL uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} queries: +security-extended,security-and-quality config: | query-filters: - exclude: id: cpp/path-injection - exclude: id: cpp/uncontrolled-process-operation - exclude: id: cpp/world-writable-file-creation - name: Install dependencies run: sudo -E .github/workflows/cibuild-setup-ubuntu.sh env: COMPILER: gcc - name: Autobuild uses: github/codeql-action/autobuild@v3 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v3