name: "CodeQL" on: pull_request: # The branches below must be a subset of the branches above branches: [master] schedule: - cron: "30 5,17 * * *" permissions: contents: read jobs: analyze: permissions: security-events: write # for github/codeql-action/autobuild to send a status report name: Analyze if: github.repository_owner == 'mattermost' runs-on: ubuntu-24.04 strategy: fail-fast: false matrix: language: ["go", "javascript"] steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL uses: github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6 with: languages: ${{ matrix.language }} debug: false config-file: ./.github/codeql/codeql-config.yml - name: Build JavaScript uses: github/codeql-action/autobuild@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6 if: ${{ matrix.language == 'javascript' }} - name: Setup go uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0 with: go-version-file: server/go.mod if: ${{ matrix.language == 'go' }} - name: Build Golang run: | cd server make setup-go-work make build-linux-amd64 if: ${{ matrix.language == 'go' }} # Perform Analysis - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6