From 965b4af7f7c7c0e3db5637a608b941035c455b3d Mon Sep 17 00:00:00 2001 From: Carlos Navarro <68403497+0xnavarro@users.noreply.github.com> Date: Sun, 20 Sep 2026 22:59:39 -0600 Subject: [PATCH] ci(security): add CodeQL scanning --- .github/workflows/codeql.yml | 40 ++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..527b2c3 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,40 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + - cron: '17 4 * * 1' + +permissions: + contents: read + security-events: write + +concurrency: + group: codeql-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + analyze: + name: CodeQL (JavaScript/TypeScript) + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - name: Checkout source without persisted credentials + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + fetch-depth: 0 + + - name: Initialize CodeQL + uses: github/codeql-action/init@e429ea58a9912cadc53f8132ad35562b54de1b30 # v3.38.1 + with: + languages: javascript-typescript + build-mode: none + + - name: Analyze + uses: github/codeql-action/analyze@e429ea58a9912cadc53f8132ad35562b54de1b30 # v3.38.1 + with: + category: /language:javascript-typescript