1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556 |
- name: CodeQL (daily)
- on:
- schedule:
- # daily at 1:30 UTC
- - cron: "30 1 * * *"
- workflow_dispatch:
- permissions:
- contents: read
- jobs:
- analyze:
- permissions:
- actions: read # for github/codeql-action/init to get workflow details
- security-events: write # for github/codeql-action/analyze to upload SARIF results
- runs-on: ubuntu-latest
- steps:
- - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- - name: Free disk space
- run: .github/scripts/gha-free-disk-space.sh
- - name: Set up Java 17
- uses: actions/setup-java@99b8673ff64fbf99d8d325f52d9a5bdedb8483e9 # v4.2.1
- with:
- distribution: temurin
- java-version-file: .java-version
- - name: Initialize CodeQL
- uses: github/codeql-action/init@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
- with:
- languages: java
- # using "latest" helps to keep up with the latest Kotlin support
- # see https://github.com/github/codeql-action/issues/1555#issuecomment-1452228433
- tools: latest
- - name: Setup Gradle
- uses: gradle/actions/setup-gradle@d9336dac04dea2507a617466bc058a3def92b18b # v3.4.0
- - name: Build
- # skipping build cache is needed so that all modules will be analyzed
- run: ./gradlew assemble -x javadoc --no-build-cache --no-daemon
- - name: Perform CodeQL analysis
- uses: github/codeql-action/analyze@23acc5c183826b7a8a97bce3cecc52db901f8251 # v3.25.10
- workflow-notification:
- needs:
- - analyze
- if: always()
- uses: ./.github/workflows/reusable-workflow-notification.yml
- with:
- success: ${{ needs.analyze.result == 'success' }}
|