Add CodeQL workflow for GitHub code scanning (#34)

Co-authored-by: LGTM Migrator <lgtm-migrator@users.noreply.github.com>
This commit is contained in:
lgtm-com[bot]
2022-12-07 08:42:22 -06:00
committed by GitHub
parent e07095cfcc
commit eddb6bf92f

58
.github/workflows/codeql.yml vendored Normal file
View File

@@ -0,0 +1,58 @@
name: "CodeQL"
on:
push:
branches: [ "master" ]
pull_request:
branches: [ "master" ]
schedule:
- cron: "45 7 * * 5"
jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
language: [ cpp ]
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Configure
run: |
export DEPS_BUILD_DIR=$RUNNER_TEMP/deps
mkdir -p $DEPS_BUILD_DIR
git clone https://github.com/emp-toolkit/emp-tool.git
cd emp-tool
cmake -DENABLE_FLOAT=True -DCMAKE_INSTALL_PREFIX=$DEPS_BUILD_DIR .
make -j4
make install
git clone https://github.com/emp-toolkit/emp-ot.git
cd emp-ot
cmake -DCMAKE_INSTALL_PREFIX=$DEPS_BUILD_DIR .
make -j4
make install
- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: ${{ matrix.language }}
queries: +security-and-quality
- name: Build cpp
run: |
export DEPS_BUILD_DIR=$RUNNER_TEMP/deps
cmake -DCMAKE_INSTALL_PREFIX=$DEPS_BUILD_DIR . && make
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
with:
category: "/language:${{ matrix.language }}"