Files
PowerShell-PowerShell/.github/workflows/analyze-reusable.yml
T
dependabot[bot] 467059c9cb Bump github/codeql-action from 4.32.0 to 4.32.1 (#26741)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-03 12:46:51 -05:00

78 lines
2.4 KiB
YAML

name: CodeQL Analysis (Reusable)
on:
workflow_call:
inputs:
runner_os:
description: 'Runner OS for CodeQL analysis'
type: string
required: false
default: ubuntu-latest
permissions:
actions: read # for github/codeql-action/init to get workflow details
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/analyze to upload SARIF results
env:
DOTNET_CLI_TELEMETRY_OPTOUT: 1
DOTNET_NOLOGO: 1
POWERSHELL_TELEMETRY_OPTOUT: 1
__SuppressAnsiEscapeSequences: 1
nugetMultiFeedWarnLevel: none
jobs:
analyze:
name: Analyze
runs-on: ${{ inputs.runner_os }}
strategy:
fail-fast: false
matrix:
# Override automatic language detection by changing the below list
# Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
language: ['csharp']
# Learn more...
# https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection
steps:
- name: Checkout repository
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
with:
fetch-depth: '0'
- uses: actions/setup-dotnet@v5
with:
global-json-file: ./global.json
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v3.29.5
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# queries: ./path/to/local/query, your-org/your-repo/queries@main
- run: |
Import-Module .\tools\ci.psm1
Show-Environment
name: Capture Environment
shell: pwsh
- run: |
Import-Module .\tools\ci.psm1
Invoke-CIInstall -SkipUser
name: Bootstrap
shell: pwsh
- run: |
Import-Module .\tools\ci.psm1
Invoke-CIBuild -Configuration 'StaticAnalysis'
name: Build
shell: pwsh
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v3.29.5