Commit 3721761
chore: add CodeQL workflow and pin actions to commit SHAs (#3)
Adds .github/workflows/codeql.yml running CodeQL static analysis on
push, pull_request, and a weekly schedule (Sun 00:00). Targets the
javascript-typescript language pack since the spec ships with TS
generation tooling.
Pins every third-party action invocation (actions/checkout,
actions/setup-node, github/codeql-action/*) to a full commit SHA with
the corresponding semver tag in a trailing comment. Pinning to SHA
closes the supply-chain hole where a compromised or rewritten tag
could ship malicious code into CI.
Adds a least-privilege top-level `permissions: contents: read` block
to the existing validate workflow.
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>1 parent f8dc295 commit 3721761
2 files changed
Lines changed: 41 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 | | |
15 | 18 | | |
16 | 19 | | |
17 | 20 | | |
18 | 21 | | |
19 | 22 | | |
20 | 23 | | |
21 | | - | |
| 24 | + | |
22 | 25 | | |
23 | 26 | | |
24 | | - | |
| 27 | + | |
25 | 28 | | |
26 | 29 | | |
27 | 30 | | |
| |||
0 commit comments