Sha256: f559c7312cdb27aa425a0c5deea5fbee4d3d575a594ecaaa8566082e1e1b34a2

Contents?: true

Size: 1.25 KB

Versions: 3

Compression:

Stored size: 1.25 KB

Contents

name: CodeQL

on:
  merge_group:
  pull_request:
    types:
      - opened
      - synchronize
  push:
    branches:
      - master
  schedule:
    - cron: "37 10 * * 2"

permissions:
  actions: read
  contents: read
  security-events: write

concurrency:
  group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
  cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}

jobs:
  analyze:
    name: Check for Vulnerabilities
    runs-on: ubuntu-latest

    strategy:
      fail-fast: false
      matrix:
        language: [ruby]

    steps:
      - if: github.actor == 'dependabot[bot]' || github.event_name == 'merge_group'
        run: exit 0 # Skip unnecessary test runs for dependabot and merge queues. Artifically flag as successful, as this is a required check for branch protection.

      - name: Checkout
        uses: actions/checkout@v4

      - name: Initialize CodeQL
        uses: github/codeql-action/init@v2
        with:
          languages: ${{ matrix.language }}
          queries: +security-and-quality

      - name: Autobuild
        uses: github/codeql-action/autobuild@v2

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@v2
        with:
          category: "/language:${{ matrix.language }}"

Version data entries

3 entries across 3 versions & 1 rubygems

Version Path
auth0-5.16.0 .github/workflows/codeql.yml
auth0-5.15.0 .github/workflows/codeql.yml
auth0-5.14.2 .github/workflows/codeql.yml