From a24ecda6c1cd84865eeeab3330f47f6238ab745b Mon Sep 17 00:00:00 2001 From: Ytemiloluwa Date: Tue, 10 Dec 2024 13:19:42 +0100 Subject: [PATCH 1/2] Add CodeQL Analysis workflow (#565) --- .github/workflows/CodeQL-Analysis.yml | 30 +++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 .github/workflows/CodeQL-Analysis.yml diff --git a/.github/workflows/CodeQL-Analysis.yml b/.github/workflows/CodeQL-Analysis.yml new file mode 100644 index 00000000..534144dc --- /dev/null +++ b/.github/workflows/CodeQL-Analysis.yml @@ -0,0 +1,30 @@ +name: "CodeQL Analysis" +on: + push: + branches: + - main + pull_request: + branches: + - main + +jobs: + security-scan: + name: Run CodeQL Analysis + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v3 + + - name: Set up CodeQL + uses: github/codeql-action/init@v2 + with: + languages: 'swift' + + - name: Autobuild + uses: github/codeql-action/autobuild@v2 + + - name: Run CodeQL Analysis + uses: github/codeql-action/analyze@v2 + with: + category: security From e06ce5f410cc2585850b143f74af162e531f8c62 Mon Sep 17 00:00:00 2001 From: Ytemiloluwa Date: Fri, 13 Dec 2024 21:43:49 +0100 Subject: [PATCH 2/2] Add CodeQL analysis workflow --- .github/workflows/CodeQL-Analysis.yml | 20 ++++++++------------ 1 file changed, 8 insertions(+), 12 deletions(-) diff --git a/.github/workflows/CodeQL-Analysis.yml b/.github/workflows/CodeQL-Analysis.yml index 534144dc..f3e70c37 100644 --- a/.github/workflows/CodeQL-Analysis.yml +++ b/.github/workflows/CodeQL-Analysis.yml @@ -1,4 +1,5 @@ -name: "CodeQL Analysis" +name: CodeQL Analysis + on: push: branches: @@ -8,23 +9,18 @@ on: - main jobs: - security-scan: - name: Run CodeQL Analysis + analyze: + name: Analyze CodeQL runs-on: ubuntu-latest steps: - - name: Checkout code + - name: Checkout repository uses: actions/checkout@v3 - - name: Set up CodeQL + - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: - languages: 'swift' - - - name: Autobuild - uses: github/codeql-action/autobuild@v2 + languages: swift - - name: Run CodeQL Analysis + - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v2 - with: - category: security