diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4abb2c94..1d9d1812 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -77,6 +77,20 @@ jobs: - name: Build final image run: docker build -t final-image . + codeql: + runs-on: ubuntu-latest + permissions: + actions: read + contents: read + security-events: write + steps: + - uses: actions/checkout@v3 + - uses: github/codeql-action/init@v2 + with: + languages: go + - uses: github/codeql-action/autobuild@v2 + - uses: github/codeql-action/analyze@v2 + publish: if: | github.event.pull_request.head.repo.full_name == github.repository && @@ -86,7 +100,7 @@ jobs: github.event_name == 'release' || (github.event_name == 'pull_request' && github.actor != 'dependabot[bot]') ) - needs: [verify] + needs: [verify, codeql] permissions: actions: read contents: read diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index 643ba37e..00000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,25 +0,0 @@ -name: "CodeQL" - -on: - push: - branches: [ master ] - pull_request: - # The branches below must be a subset of the branches above - branches: [ master ] - schedule: - - cron: '44 9 * * 0' - -jobs: - analyze: - runs-on: ubuntu-latest - permissions: - actions: read - contents: read - security-events: write - steps: - - uses: actions/checkout@v3 - - uses: github/codeql-action/init@v2 - with: - languages: go - - uses: github/codeql-action/autobuild@v2 - - uses: github/codeql-action/analyze@v2