Skip to content

Commit 205c573

Browse files
committed
codeql: also check JavaScript code
Let's exclude GitWeb from being scanned; It is not distributed by us. Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
1 parent f171166 commit 205c573

File tree

2 files changed

+6
-3
lines changed

2 files changed

+6
-3
lines changed

.github/codeql/codeql-config.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,9 @@ name: "CodeQL config"
33
queries:
44
- uses: security-extended
55

6+
paths-ignore:
7+
- gitweb/**/*.js # GitWeb is not distributed
8+
69
query-filters:
710
- exclude:
811
# yes, this extra indentation is intentional

.github/workflows/codeql.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
strategy:
2020
fail-fast: false
2121
matrix:
22-
language: ["cpp"]
22+
language: ["cpp", "javascript"]
2323

2424
steps:
2525
- name: Checkout repository
@@ -57,10 +57,10 @@ jobs:
5757
- name: publish sarif for debugging
5858
uses: actions/upload-artifact@v4
5959
with:
60-
name: sarif-results
60+
name: sarif-results-${{ matrix.language }}
6161
path: sarif-results
6262

6363
- name: Upload SARIF
6464
uses: github/codeql-action/upload-sarif@v3
6565
with:
66-
sarif_file: sarif-results/cpp.sarif
66+
sarif_file: sarif-results/${{ matrix.language }}.sarif

0 commit comments

Comments
 (0)