# LAB ONLY # 用途: JavaScript / TypeScript 静态安全分析 # 目标范围: 自有代码仓、自有测试项目 # 风险: 可能出现需要人工甄别的误报 # 不适用: 未经规则调优直接作为生产发布门禁 name: codeql-javascript on: push: branches: - main pull_request: workflow_dispatch: permissions: actions: read contents: read security-events: write jobs: analyze: runs-on: ubuntu-latest strategy: fail-fast: false matrix: language: - javascript-typescript steps: - name: Checkout uses: actions/checkout@v4 - name: Initialize CodeQL uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} - name: Autobuild uses: github/codeql-action/autobuild@v3 - name: Analyze uses: github/codeql-action/analyze@v3