diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 3807670..026d7bb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,24 +1,26 @@ --- # yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json name: "CodeQL" + on: push: branches: ["main"] pull_request: branches: ["main"] schedule: - - cron: " - cron: '30 1 * * 0' # Run at 1:30 AM UTC every Sunday" + - cron: "30 1 * * 0" merge_group: -permissions: - actions: read - contents: read +permissions: {} jobs: analyze: name: Analyze runs-on: ubuntu-latest permissions: + actions: read + contents: read + packages: read security-events: write strategy: fail-fast: false @@ -26,6 +28,6 @@ jobs: language: ["actions", "javascript-typescript"] steps: - name: CodeQL Analysis - uses: ivuorinen/actions/codeql-analysis@main + uses: ivuorinen/actions/codeql-analysis@97105fc2a909360678588cb50caf0be5144be486 # v2026.03.06 with: language: ${{ matrix.language }}