--- # yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json name: "CodeQL" on: push: branches: ["main"] pull_request: branches: ["main"] schedule: - cron: "30 1 * * 0" merge_group: permissions: {} jobs: analyze: name: Analyze runs-on: ubuntu-latest permissions: actions: read contents: read packages: read security-events: write strategy: fail-fast: false matrix: language: ["actions", "javascript"] steps: - name: CodeQL Analysis uses: ivuorinen/actions/codeql-analysis@97105fc2a909360678588cb50caf0be5144be486 # v2026.03.06 with: language: ${{ matrix.language }} queries: security-and-quality