Skip to content

fix(ci): drop invalid timeout-minutes from reusable-workflow calls (p… #86

fix(ci): drop invalid timeout-minutes from reusable-workflow calls (p…

fix(ci): drop invalid timeout-minutes from reusable-workflow calls (p… #86

Workflow file for this run

# // Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
# SPDX-License-Identifier: MPL-2.0
# Analyses the GitHub Actions workflows in this repo. This is a Julia
# package registry: source content is TOML and the only executable
# surface is the workflows themselves -- so `language: actions` is the
# matrix that produces meaningful SAST results (closing the
# `scorecard/StaticAnalysis` nominal-SAST finding).
name: CodeQL Security Analysis
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
schedule:
- cron: '0 6 * * 1'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
analyze:
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Initialize CodeQL
uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v3
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@7188fc363630916deb702c7fdcf4e481b751f97a # v3
with:
category: "/language:${{ matrix.language }}"