v0.11 item 2: the anchor, and the truncation it makes detectable #358
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CodeQL | |
| # Static analysis on every pull request, so a finding arrives while the change is still being | |
| # read rather than in a weekly digest nobody opens. `security-and-quality` rather than the | |
| # default suite: this is a small codebase in the execution path of consequential actions, and | |
| # the extra queries cost a few minutes that a project this size can afford. | |
| # | |
| # Findings land in the repository's code-scanning tab. Nothing here gates a merge -- the | |
| # required checks stay `check (3.11)` through `check (3.14)` and `package` -- because a static | |
| # analyser's first run on an unfamiliar codebase is a reading list, not a verdict. | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| schedule: | |
| - cron: "41 5 * * 1" | |
| permissions: | |
| contents: read | |
| jobs: | |
| analyze: | |
| name: Analyze Python | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| permissions: | |
| security-events: write # to upload the findings to code scanning | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| languages: python | |
| # The core is stdlib plus pyyaml and click, and every extra is imported lazily, so | |
| # there is nothing to build and nothing to install for the analyser to see the code. | |
| build-mode: none | |
| queries: security-and-quality | |
| # Which of that suite's queries this repository acts on, and why two of them are not. | |
| config-file: ./.github/codeql/codeql-config.yml | |
| - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| category: "/language:python" |