docs: add Signed commits section to CONTRIBUTING (#79) #211
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: PMPL-1.0-or-later | |
| # This workflow is managed by gh actions-lock. | |
| name: CodeQL Security Analysis | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: [main, master] | |
| schedule: | |
| - cron: '0 6 * * 1' | |
| # Estate guardrail: cancel superseded runs so re-pushes don't pile up | |
| # queued runs across the estate. Safe here because this workflow only | |
| # performs read-only checks/lint/test/scan with no publish or mutation. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| # The estate is heterogeneous (Rust, Idris2, Agda, Elixir, AffineScript, | |
| # occasional JS/TS/Python). A hard-coded `javascript-typescript` matrix | |
| # made CodeQL exit with a "no source / configuration error" on every | |
| # non-JS/TS repo — a permanent false-red `analyze` on most repos' main. | |
| # Detect the languages the repo ACTUALLY contains and only analyse the | |
| # CodeQL-supported, buildless-safe ones; skip entirely when none apply. | |
| detect: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| langs: ${{ steps.pick.outputs.langs }} | |
| steps: | |
| - name: Pick CodeQL languages from repo language stats | |
| id: pick | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| stats=$(gh api "repos/${{ github.repository }}/languages" --jq 'keys[]' 2>/dev/null || echo "") | |
| out="" | |
| add() { out="$out $1"; } | |
| echo "$stats" | grep -qix 'Rust' && add rust | |
| echo "$stats" | grep -qixE 'JavaScript|TypeScript' && add javascript-typescript | |
| echo "$stats" | grep -qix 'Python' && add python | |
| echo "$stats" | grep -qix 'Ruby' && add ruby | |
| echo "$stats" | grep -qix 'Go' && add go | |
| arr=$(printf '%s\n' $out | grep . | sort -u | jq -R . | jq -s -c .) | |
| [ -z "$arr" ] && arr='[]' | |
| echo "Detected CodeQL languages: $arr" | |
| echo "langs=$arr" >> "$GITHUB_OUTPUT" | |
| analyze: | |
| needs: detect | |
| if: needs.detect.outputs.langs != '[]' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| security-events: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: ${{ fromJSON(needs.detect.outputs.langs) }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@v4.38.1 | |
| with: | |
| languages: ${{ matrix.language }} | |
| build-mode: none | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@v4.38.1 | |
| with: | |
| category: "/language:${{ matrix.language }}" |