codeql-analysis.yml 1.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849
  1. name: "CodeQL"
  2. on:
  3. push:
  4. branches: [main]
  5. pull_request:
  6. branches: [main]
  7. schedule:
  8. - cron: '0 1 * * 0'
  9. permissions:
  10. contents: read
  11. jobs:
  12. analyze:
  13. name: Analyze
  14. runs-on: ubuntu-latest
  15. permissions:
  16. actions: read
  17. security-events: write
  18. env:
  19. # Enable format attributes in ncurses headers
  20. # Enable fortified memory/string handling
  21. CPPFLAGS: -DGCC_PRINTF -DGCC_SCANF -D_FORTIFY_SOURCE=2
  22. steps:
  23. - name: Checkout Repository
  24. uses: actions/checkout@v4
  25. - name: Initialize CodeQL
  26. uses: github/codeql-action/init@v3
  27. with:
  28. languages: cpp
  29. - name: Install Dependencies
  30. run: sudo apt-get install --no-install-recommends libncursesw5-dev libhwloc-dev libnl-3-dev libnl-genl-3-dev libsensors4-dev libcap-dev
  31. - name: Bootstrap
  32. run: ./autogen.sh
  33. - name: Configure
  34. run: ./configure --enable-werror --enable-openvz --enable-vserver --enable-ancient-vserver --enable-unicode --enable-hwloc --enable-delayacct --enable-sensors --enable-capabilities
  35. - name: Build
  36. run: make
  37. - name: Perform CodeQL Analysis
  38. uses: github/codeql-action/analyze@v3