Skip to content

File tree

1 file changed

+19
-6
lines changed

1 file changed

+19
-6
lines changed

.github/workflows/codeql-analysis.yml

+19-6
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
name: "CodeQL"
1+
name: CodeQL
22

33
on:
44
push:
@@ -9,20 +9,33 @@ on:
99
schedule:
1010
- cron: '0 13 * * 6'
1111

12+
permissions: {}
13+
1214
jobs:
1315
analyze:
1416
name: Analyze
1517
runs-on: ubuntu-latest
18+
permissions:
19+
security-events: write
20+
actions: read
1621

1722
steps:
23+
- uses: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423 # v2.6.0
24+
with:
25+
disable-sudo: true
26+
egress-policy: audit
27+
1828
- name: Checkout repository
19-
uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4
29+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
30+
with:
31+
persist-credentials: false
2032

2133
- name: Initialize CodeQL
22-
uses: github/codeql-action/init@v2
34+
uses: github/codeql-action/init@74483a38d39275f33fcff5f35b679b5ca4a26a99 # v2.22.5
2335
with:
24-
languages: 'javascript'
25-
config-file: ./.github/codeql/codeql-config.yml
36+
languages: javascript-typescript
37+
config-file: .github/codeql/codeql-config.yml
2638

2739
- name: Perform CodeQL Analysis
28-
uses: github/codeql-action/analyze@v2
40+
uses: github/codeql-action/analyze@74483a38d39275f33fcff5f35b679b5ca4a26a99 # v2.22.5
41+

0 commit comments

Comments
 (0)