1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
# Static analysis, CodeQL. A landing writes this file only under the
# recorded code-scanning opt-in with codeql chosen, and only where the
# binding's declared licence is OSI-approved: CodeQL's terms cover an
# open-source codebase, and a run over anything else needs a paid seat, so
# a landing that guessed would write a licence violation. bindings/rust.md
# states which field the licence is read from and what the two other
# providers cost.
#
# The scan reads the binding's own language and no other. The actions
# language is left out on purpose: the exclusion that would spare a
# generated release workflow is undocumented for it, so a scan there
# reports findings on a file this convention does not write.
#
# This workflow does not trigger on a pull request, and that is deliberate.
# The forge resolves a job's needs inside one workflow file, so a second
# request-reporting workflow holds no merge whatever it proves, and the
# trunk protection requires one project-owned context beside the title
# check. forges/github.md states the rule.
name: code-scanning
on:
push:
branches:
schedule:
# Weekly. A query pack updates upstream, so a scan finds what a scan at
# the last push could not.
- cron: '17 3 * * 1'
permissions:
jobs:
code-scanning:
name: code-scanning
runs-on: ubuntu-latest
permissions:
contents: read
# The scan uploads its SARIF to this repository's code scanning.
security-events: write
# Only a private repository needs this, and the upload fails without it
# there: the action reads the workflow run it is reporting against. It is
# granted unconditionally because the landing does not know whether the
# target is private, and read access to this repository's own runs costs a
# public target nothing. A private target fetching private CodeQL packs
# adds `packages: read` beside it; the default query packs need none.
actions: read
steps:
- name: check out the trunk
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
persist-credentials: false
- name: the database is built
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4
with:
languages: rust
# Rust needs no build to produce a database.
build-mode: none
- name: the queries run and the result uploads
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4