Files
vscode/.github/workflows/codeql.yml
T
Dmitriy VasyuraandCopilot efc2c86f03 Create custom CodeQL workflow (#334739)
* Create custom CodeQL workflow

* build: Exclude nested esbuild scripts from CodeQL

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* build: Align CodeQL coverage with packaged files

Keep Markdown build/test scripts out of the extension package and restore scanning of the shipped chat-library postinstall script.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* ci: Expand CodeQL release coverage and scope permissions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-06 11:03:23 +00:00

52 lines
1.3 KiB
YAML

name: CodeQL
on:
push:
branches:
- main
- 'release/**/*'
pull_request:
branches:
- main
- 'release/**/*'
schedule:
- cron: '17 19 * * 6'
permissions: {}
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
packages: read
security-events: write
strategy:
fail-fast: false
matrix:
# Other detected languages occur only in test fixtures or build tooling.
include:
- language: javascript-typescript
build-mode: none
- language: rust
build-mode: none
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Initialize CodeQL
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
dependency-caching: true
config-file: ./.github/codeql/codeql-config.yml
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
category: /language:${{ matrix.language }}