From 3addda58b06b022521cb3f2f9ea6dd020621c9e8 Mon Sep 17 00:00:00 2001 From: Ismo Vuorinen Date: Sat, 7 Mar 2026 17:49:59 +0200 Subject: [PATCH] fix: correct codeql workflow language, queries, permissions, and action ref - Use 'javascript' instead of 'javascript-typescript' for CodeQL language - Add queries: security-and-quality parameter - Set root-level permissions to {} - Add job-level permissions (actions, contents, packages, security-events) - Pin action ref to commit hash with version comment - Fix mangled cron schedule --- .github/workflows/codeql.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 026d7bb..62bde7c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -25,9 +25,10 @@ jobs: strategy: fail-fast: false matrix: - language: ["actions", "javascript-typescript"] + language: ["actions", "javascript"] steps: - name: CodeQL Analysis uses: ivuorinen/actions/codeql-analysis@97105fc2a909360678588cb50caf0be5144be486 # v2026.03.06 with: language: ${{ matrix.language }} + queries: security-and-quality