Add custom workflow for CodeQL Analysis #659
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Changes
Branch-Specific Execution
Runs exclusively on
mainanddevbranches for:JavaScript / TypeScript & GitHub Actions Analysis
Expands coverage to include both application code and workflow definitions.
Comprehensive Security Scanning
Uses both
security-extendedandsecurity-and-qualityquery suites for deeper vulnerability detection and maintainability insights.Scheduled Analysis
Automatically runs every Monday at 06:00 AM UTC to proactively catch new issues.
Optimized Build Process
npm cifor reproducible environmentsPost-Action Steps Added
Proper Permissions
Configured with only the required permissions for reading code and writing security events.
Who should review your contribution? (Use @mention)
@cernus76
Checklist before submitting