文件
websafe-kb/08-threat-intel/config-examples/github/.github/workflows/codeql-javascript.yml

42 行
894 B
YAML

# LAB ONLY
# 用途: JavaScript / TypeScript 静态安全分析
# 目标范围: 自有代码仓、自有测试项目
# 风险: 可能出现需要人工甄别的误报
# 不适用: 未经规则调优直接作为生产发布门禁
name: codeql-javascript
on:
push:
branches:
- main
pull_request:
workflow_dispatch:
permissions:
actions: read
contents: read
security-events: write
jobs:
analyze:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
language:
- javascript-typescript
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
- name: Autobuild
uses: github/codeql-action/autobuild@v3
- name: Analyze
uses: github/codeql-action/analyze@v3