diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 2a643989e0a8a652e47e209dbe92fbe6f29e2c64..6b6434d27c0ad923d41f8f0ade4a2cffa7717cd0 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -35,17 +35,6 @@ jobs: - run: git checkout HEAD^2 if: ${{ github.event_name == 'pull_request' }} - - name: Initialize CodeQL - uses: github/codeql-action/init@v3 - with: - languages: go, javascript - - - name: Autobuild - uses: github/codeql-action/autobuild@v3 - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 - spelling: runs-on: ubuntu-latest steps: diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml new file mode 100644 index 0000000000000000000000000000000000000000..ed69aed789d7f946a740ce4d8f4d455a41eb9386 --- /dev/null +++ b/.github/workflows/scan.yml @@ -0,0 +1,32 @@ +name: scan + +on: + push: + branches: [ master ] + pull_request: + branches: [ master ] + schedule: + - cron: '0 12 * * 6' + +permissions: + security-events: write + +jobs: + codeql: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + with: + fetch-depth: 2 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: go, javascript + + - name: Autobuild + uses: github/codeql-action/autobuild@v3 + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3