ee3606e3cb
fix(ci): consolidate CodeQL workflows with proper permissions ( #473 )
...
* fix(ci): consolidate CodeQL workflows with proper permissions
Merge codeql.yml and codeql-analysis.yml into a single workflow.
Add top-level permissions block to fix Checkov CKV2_GHA_1.
Changes:
- Add top-level permissions (actions: read, contents: read)
- Add merge_group trigger
- Enable security-and-quality query suite
- Use javascript-typescript language with build-mode: none
- Remove redundant codeql-analysis.yml
* fix(ci): include all required permissions at job level
Job-level permissions override top-level permissions in GitHub Actions
rather than extending them. Add actions: read and contents: read to
the job-level block so the analyze job retains all required permissions.
2026-02-26 22:20:14 +02:00
79ea896d8e
chore(deps): update dependencies, release config
2026-02-25 21:41:04 +02:00
renovate[bot]
9744eabce9
chore(deps): update github/codeql-action action (v4.32.3 → v4.32.4) ( #471 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-22 04:46:45 +00:00
renovate[bot]
e9ae91a8d7
chore(deps): update ivuorinen/actions action (v2026.02.10 → v2026.02.18) ( #470 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-20 04:51:31 +00:00
renovate[bot]
77d4ab15e8
chore(deps): update github/codeql-action action (v4.32.2 → v4.32.3) ( #467 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-15 04:50:26 +00:00
renovate[bot]
ebb6cfce3d
chore(deps): update ivuorinen/actions action (v2026.02.03 → v2026.02.10) ( #465 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 06:31:47 +00:00
renovate[bot]
722fa145d2
chore(deps): update simek/yarn-lock-changes action (v0.14.0 → v0.14.1) ( #464 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-09 10:37:35 +00:00
renovate[bot]
acc2da1f37
chore(deps): update github/codeql-action action (v4.32.1 → v4.32.2) ( #463 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-07 04:51:24 +00:00
renovate[bot]
3340f5d4e2
chore(deps): update ivuorinen/actions action (v2026.01.21 → v2026.02.03) ( #462 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-05 14:00:28 +00:00
renovate[bot]
65ea3e0ffb
chore(deps): update github/codeql-action action (v4.32.0 → v4.32.1) ( #461 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-04 04:24:28 +00:00
renovate[bot]
6845253eab
chore(deps): update simek/yarn-lock-changes action (v0.12.2 → v0.14.0) ( #460 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-01 22:08:18 +02:00
renovate[bot]
d48f64b4d9
chore(deps): update actions/cache action (v5.0.2 → v5.0.3) ( #459 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-31 18:45:12 +02:00
renovate[bot]
4c06a97439
chore(deps): update github/codeql-action action (v4.31.11 → v4.32.0) ( #457 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-28 06:32:40 +00:00
renovate[bot]
fc68ba7fb5
chore(deps): update github/codeql-action action (v4.31.10 → v4.31.11) ( #456 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-25 04:45:02 +00:00
renovate[bot]
649bdef76e
chore(deps): update actions/checkout action (v6.0.1 → v6.0.2) ( #455 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-24 01:25:25 +02:00
renovate[bot]
f920836b58
chore(deps): update ivuorinen/actions action (v2026.01.13 → v2026.01.21) ( #454 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-22 11:20:14 +00:00
renovate[bot]
65d80f2a3a
chore(deps): update actions/cache action (v5.0.1 → v5.0.2) ( #450 )
2026-01-18 15:31:31 +02:00
renovate[bot]
9bf1d397fc
chore(deps): update actions/setup-node action (v6.1.0 → v6.2.0) ( #448 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-17 04:40:17 +00:00
renovate[bot]
c994b011fd
chore(deps): update ivuorinen/actions action (v2026.01.09 → v2026.01.13) ( #446 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-15 13:15:01 +00:00
renovate[bot]
a7cf077c64
chore(deps): update github/codeql-action action (v4.31.9 → v4.31.10) ( #445 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-14 06:36:46 +00:00
renovate[bot]
5c99268e50
chore(deps): update ivuorinen/actions action (v2026.01.06 → v2026.01.09) ( #444 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-11 04:29:09 +00:00
renovate[bot]
7c065e968e
chore(deps)!: update ivuorinen/actions (v2025.12.31 → v2026.01.06) ( #442 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-07 16:26:47 +02:00
renovate[bot]
a2026b02d5
chore(deps): update ivuorinen/actions action (v2025.12.06 → v2025.12.31) ( #443 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-07 14:24:42 +00:00
d819a7b257
security(ci): update permissions in publish.yml
2026-01-07 16:07:37 +02:00
renovate[bot]
44832a01b5
chore(deps): update github/codeql-action action (v4.31.8 → v4.31.9) ( #441 )
2025-12-18 09:39:17 +02:00
renovate[bot]
28b230e931
chore(deps): update github/codeql-action action (v4.31.7 → v4.31.8) ( #440 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-14 09:39:50 +00:00
renovate[bot]
45603a51e8
chore(deps): update actions/cache action (v5.0.0 → v5.0.1) ( #439 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-14 05:57:42 +00:00
renovate[bot]
ad15143559
chore(deps)!: update actions/cache (v4.3.0 → v5.0.0) ( #437 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-12 12:14:31 +02:00
8fb98907cd
chore: linting and semantic-commit plugins
2025-12-06 23:54:07 +01:00
2a7f8490be
fix: codeql analysis
2025-12-06 23:35:29 +01:00
5400c02639
feat: release pipeline, packages, yarn upgrade
2025-12-06 23:33:17 +01:00
renovate[bot]
58b803734d
chore(deps): update actions/setup-node action (v6.0.0 → v6.1.0) ( #436 )
2025-12-05 16:55:05 +02:00
renovate[bot]
4dc6db66c2
chore(deps): update actions/checkout action (v6.0.0 → v6.0.1) ( #435 )
2025-12-04 12:06:22 +02:00
renovate[bot]
e19014ab75
chore(deps): update github/codeql-action action (v4.31.5 → v4.31.6) ( #434 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-03 07:37:22 +00:00
renovate[bot]
82765078d3
chore(deps)!: update actions/checkout (v5.0.1 → v6.0.0) ( #427 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-27 16:30:07 +02:00
383a494113
chore(deps): upgrade yarn ( #430 )
...
* chore(deps): upgrade yarn
* chore(ci): enable corepack
2025-11-27 16:24:59 +02:00
renovate[bot]
e6e3327e3b
chore(deps): update github/codeql-action action (v4.31.4 → v4.31.5) ( #429 )
2025-11-26 16:52:32 +02:00
renovate[bot]
466a785448
chore(deps): update ivuorinen/actions action (v2025.11.02 → v2025.11.23) ( #428 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-25 05:58:43 +00:00
renovate[bot]
b375c6deec
chore(deps): update github/codeql-action action (v4.31.3 → v4.31.4) ( #426 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-20 10:06:40 +00:00
renovate[bot]
5b542d5c0c
chore(deps): update actions/checkout action (v5.0.0 → v5.0.1) ( #425 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-20 04:44:12 +00:00
renovate[bot]
90865b0cf0
chore(deps): update github/codeql-action action (v4.31.2 → v4.31.3) ( #423 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-17 16:52:45 +02:00
352774c709
fix(ci): add missing permission to publish workflow
2025-11-16 11:14:41 +02:00
renovate[bot]
5a1c93d401
chore(deps): update ivuorinen/actions action (v2025.10.26 → v2025.11.02) ( #419 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-04 02:41:02 +00:00
renovate[bot]
4f6418b60d
chore(deps): update github/codeql-action action (v4.31.0 → v4.31.2) ( #418 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-11-01 04:46:49 +00:00
renovate[bot]
0c106bbdb4
chore(deps)!: update ivuorinen/actions (25.10.25 → v2025.10.26) ( #414 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-27 13:53:51 +02:00
renovate[bot]
96dc784f4d
chore(deps): update ivuorinen/actions action (25.10.20 → 25.10.25) ( #415 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-27 13:28:42 +02:00
renovate[bot]
042db5c6be
chore(deps): update github/codeql-action action (v4.30.9 → v4.31.0) ( #413 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-26 05:07:43 +00:00
renovate[bot]
f59226b92b
chore(deps): update ivuorinen/actions action (25.10.18 → 25.10.20) ( #410 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-22 09:31:52 +03:00
renovate[bot]
2d8107adbe
chore(deps): update simek/yarn-lock-changes action (v0.12.1 → v0.12.2) ( #411 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-22 09:28:53 +03:00
renovate[bot]
a6b634341c
chore(deps): update ivuorinen/actions action (25.10.16 → 25.10.18) ( #409 )
...
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-10-20 16:37:13 +00:00