# CodeQL — placeholder (disabled). # # CodeQL on a private personal repo requires GitHub Advanced Security (GHAS), # which is only available on Enterprise plans. When this repo either: # (a) becomes public, or # (b) gains a code-scanning subscription (GHAS or equivalent), # re-activate by replacing the `on:` block below with: # # on: # push: # branches: [main, develop] # pull_request: # branches: [main, develop] # schedule: # - cron: "0 6 * * 1" # # Until then the workflow is manual-trigger-only (workflow_dispatch) so it # does not fire on pushes/PRs and does not pollute CI with guaranteed # failures. name: CodeQL on: workflow_dispatch: permissions: actions: read contents: read security-events: write jobs: analyze: name: Analyze (${{ matrix.language }}) runs-on: ubuntu-latest strategy: fail-fast: false matrix: include: - language: python build-mode: none - language: javascript-typescript build-mode: none steps: - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 - name: Initialize CodeQL uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v4 with: category: "/language:${{ matrix.language }}"