Repository navigation
104 lines (90 loc) · 3.27 KB
/
Copy pathcodeql.yml
File metadata and controls
104 lines (90 loc) · 3.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
name: CodeQL
# Security automation: static analysis plus a dependency advisory gate.
# Kept out of `ci.yml` on purpose - CodeQL takes several minutes and must not
# sit on the critical path of a one-line pull request.
on:
push:
branches:
- main
pull_request:
branches:
- main
schedule:
# Mondays 04:00 UTC. Weekly is enough for a codebase this size, and it
# catches newly published queries against unchanged code.
- cron: "0 4 * * 1"
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
analyze:
name: Analyze (javascript-typescript)
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
security-events: write
# Required by github/codeql-action to read workflow runs and enable
# incremental analysis. Without it the action fails with
# "Resource not accessible by integration".
actions: read
steps:
- name: Check out repository
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: javascript-typescript
# This is an interpreted-language analysis: there is nothing to
# autobuild, and skipping the build keeps the job a few minutes
# shorter.
build-mode: none
queries: security-and-quality
- name: Perform CodeQL Analysis
# The SARIF upload requires GitHub Advanced Security, which is paywalled
# on private repositories: the analysis runs but the upload fails with
# "Advanced Security must be enabled for this repository".
# TODO: remove `continue-on-error` once the repository is public (or
# GHAS is enabled) so upload failures become visible again.
continue-on-error: true
uses: github/codeql-action/analyze@v4
with:
category: "/language:javascript-typescript"
audit:
name: Dependency audit
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@v7
- name: Set up Node.js
uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
- name: Audit production dependencies
# Blocking gate. `--omit=dev` scopes it to what actually ships in the
# runtime image; a high or critical advisory on a shipped package is a
# release blocker, one on a test-only package is not.
#
# `npm audit` resolves the tree straight from package-lock.json, so no
# install step is needed.
#
# Note: `package.json` carries an `overrides` block that pins
# transitive dependencies out of known advisories. Removing it will
# turn this job red.
run: npm audit --audit-level=high --omit=dev
- name: Audit all dependencies (informational)
# Non-blocking: development-only advisories are reported for awareness
# but must not stop a release.
continue-on-error: true
run: |
{
echo '## npm audit (including dev dependencies)'
echo
echo '```'
npm audit 2>&1 || true
echo '```'
} >> "$GITHUB_STEP_SUMMARY"