From 41a8fd8e68f77dc99b5bb086bf9d138a2ea02d46 Mon Sep 17 00:00:00 2001 From: Tom Hromatka Date: Wed, 12 Jan 2022 12:32:22 -0700 Subject: [PATCH] github: Add a code security scan Add a code security scan, CodeQL to the Github Actions continuous integration. Signed-off-by: Tom Hromatka Reviewed-by: Kamalesh Babulal --- .github/workflows/continuous-integration.yml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/.github/workflows/continuous-integration.yml b/.github/workflows/continuous-integration.yml index bea76597..61718eb8 100644 --- a/.github/workflows/continuous-integration.yml +++ b/.github/workflows/continuous-integration.yml @@ -34,6 +34,22 @@ jobs: echo "Cleaning up previous run" rm -rf "${{ github.workspace }}" + codeql: + name: CodeQL + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v2 + with: + submodules: false + - uses: github/codeql-action/init@v1 + with: + languages: cpp, python + - name: Initialize the directory + uses: ./.github/actions/setup-libcgroup + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v1 + doxygen: name: Doxygen # Only run Doxygen against the main branch -- 2.47.2