Add codeql.

This commit is contained in:
Stephan Schnabel 2022-01-25 10:03:24 +01:00
parent 8fbe1b526a
commit 10170c8044
Signed by: stephan.schnabel
GPG key ID: E07AF5BA239FE543
3 changed files with 31 additions and 2 deletions

28
.github/workflows/codeql.yaml vendored Normal file
View file

@ -0,0 +1,28 @@
name: CodeQL
"on":
workflow_dispatch: {}
push:
branches: [main]
pull_request:
branches: [main]
paths:
- '**/*.java'
- pom.xml
schedule:
- cron: '0 0 * * 0'
jobs:
codeql:
runs-on: ubuntu-latest
permissions:
security-events: write
actions: read
contents: read
steps:
- uses: actions/checkout@v2
- uses: github/codeql-action/init@v1
with:
languages: java
- uses: github/codeql-action/autobuild@v1
- uses: github/codeql-action/analyze@v1

View file

@ -20,6 +20,7 @@ jobs:
with: with:
distribution: temurin distribution: temurin
java-version: 11 java-version: 11
cache: maven
server-id: sonatype-nexus server-id: sonatype-nexus
server-username: SERVER_USERNAME server-username: SERVER_USERNAME
server-password: SERVER_PASSWORD server-password: SERVER_PASSWORD

View file

@ -6,7 +6,7 @@ name: Snapshot
jobs: jobs:
lint-yaml: yaml:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v2 - uses: actions/checkout@v2
@ -15,7 +15,7 @@ jobs:
format: colored format: colored
strict: true strict: true
lint-markdown: markdown:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v2 - uses: actions/checkout@v2