-
Notifications
You must be signed in to change notification settings - Fork 277
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Scan for security vulnerabilities with GitHub CodeQL #645
Labels
🧽 chore
Administrative task: documentation, build, test, release, git, etc.
Milestone
Comments
rgoldberg
added
the
🧽 chore
Administrative task: documentation, build, test, release, git, etc.
label
Nov 20, 2024
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Nov 21, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Nov 21, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Nov 21, 2024
Other cleanup from the release improvements PR to ensure that this workflow doesn't cause any other issues for this PR. Resolve mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 1, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 1, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 1, 2024
Other cleanup from the release improvements PR to ensure that this workflow doesn't cause any other issues for this PR. Resolve mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 2, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 2, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 2, 2024
Other cleanup from the release improvements PR to ensure that this workflow doesn't cause any other issues for this PR. Resolve mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 27, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 27, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 27, 2024
Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 27, 2024
Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 30, 2024
Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 31, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 31, 2024
Use `runs-on: macos-15`. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 31, 2024
Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 31, 2024
Scan for security vulnerabilities with GitHub CodeQL by adding `codeql.yml` workflow. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
rgoldberg
added a commit
to rgoldberg/mas
that referenced
this issue
Dec 31, 2024
Allow manual runs. Run on all pushes & pull requests. Use `runs-on: macos-15`. Analyze GitHub workflows. Don't analyze `ruby` or `c-cpp`. Perform `security-and-quality` queries. Remove parentheses from job name. Remove unnecessary settings. Remove unnecessary comments. Remove unnecessary quotes. Fix lint spacing violations. Use double quotes instead of single quotes. Partial mas-cli#645 Signed-off-by: Ross Goldberg <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Scan for security vulnerabilities with GitHub CodeQL by adding
.github/workflows/codeql.yml
workflow.Use CodeQL for as much as possible:
swift
actions
(GitHub Workflows)Package.resolved
,.swift-format
)Also ensure dependabot is setup properly:
https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide
The text was updated successfully, but these errors were encountered: