Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 54 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
name: "CodeQL Advanced"

on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
schedule:
- cron: '37 7 * * 4'

Comment thread
AviBackToBlack marked this conversation as resolved.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
# Preserve completed push-to-main analyses; only supersede stale PR runs.
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-24.04
permissions:
# required for all workflows
security-events: write

# required to fetch internal or private CodeQL packs
packages: read

# only required for workflows in private repositories
actions: read
contents: read

strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
- language: javascript-typescript
build-mode: none
- language: python
build-mode: none
Comment thread
AviBackToBlack marked this conversation as resolved.
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Initialize CodeQL
uses: github/codeql-action/init@988661ebb5e81487b3fb31b2185d2856c0a10679 # v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Comment thread
AviBackToBlack marked this conversation as resolved.

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@988661ebb5e81487b3fb31b2185d2856c0a10679 # v4
with:
category: "/language:${{matrix.language}}"
Comment thread
AviBackToBlack marked this conversation as resolved.
2 changes: 1 addition & 1 deletion docs/operations.md
Original file line number Diff line number Diff line change
Expand Up @@ -168,7 +168,7 @@ Four automated layers run against `main` (plus the opt-in ZAP scan below):
|---|---|---|
| `pip-audit`, `bandit` (medium+), `npm audit` (high+) | `make test-security`, so every CI run | **Yes** — any finding fails the build |
| Snyk Code (SAST) + Snyk Open Source (SCA) | `.github/workflows/snyk-security.yml`, on push/PR to `main` | No — findings are uploaded to the GitHub **Security → Code scanning** tab for review |
| CodeQL | GitHub *default setup* (repo Settings → Code security), weekly + on push. Note there is **no workflow file** for it — it won't show up in `.github/workflows/` | No — reports to the same Code scanning tab |
| CodeQL | `.github/workflows/codeql.yml`, on push/PR to `main` and weekly | No — reports to the same Code scanning tab |
| Dependabot | `.github/dependabot.yml` — pip, npm (`frontend/`, `tests/e2e/`), github-actions, docker-compose, devcontainers | No — opens PRs |

Two Snyk gotchas worth knowing before you debug that workflow:
Expand Down
Loading