name: codeql concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions permissions: contents: read on: push: branches: - 'master' tags: - '*' pull_request: branches: - 'master' schedule: - cron: '0 12 * * 6' jobs: codeql: runs-on: ubuntu-latest permissions: # same as global permissions contents: read # required for code scanning security-events: write steps: - name: Checkout uses: actions/checkout@v5 with: fetch-depth: 2 - name: Checkout HEAD on PR if: ${{ github.event_name == 'pull_request' }} run: | git checkout HEAD^2 - name: Initialize CodeQL uses: github/codeql-action/init@v4 with: languages: go - name: Autobuild uses: github/codeql-action/autobuild@v4 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v4