| # |
| # Licensed to the Apache Software Foundation (ASF) under one or more |
| # contributor license agreements. See the NOTICE file distributed with |
| # this work for additional information regarding copyright ownership. |
| # The ASF licenses this file to you under the Apache License, Version 2.0 |
| # (the "License"); you may not use this file except in compliance with |
| # the License. You may obtain a copy of the License at |
| # |
| # http://www.apache.org/licenses/LICENSE-2.0 |
| # |
| # Unless required by applicable law or agreed to in writing, software |
| # distributed under the License is distributed on an "AS IS" BASIS, |
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| # See the License for the specific language governing permissions and |
| # limitations under the License. |
| # |
| |
| name: codeql-analysis |
| |
| on: |
| push: |
| # These filters apply only to the current branch (`2.x`) and new branches cut from it: |
| # only `release/2*` branches automatically inherit this workflow. |
| branches: |
| - "2.x" |
| - "release/2*" |
| pull_request: |
| schedule: |
| - cron: '32 12 * * 5' |
| |
| # Cancel in-progress runs when a newer commit lands on the same PR; pushes to 2.x run to completion. |
| concurrency: |
| group: ${{ github.workflow }}-${{ github.ref }} |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} |
| |
| permissions: read-all |
| |
| jobs: |
| |
| analyze: |
| uses: apache/logging-parent/.github/workflows/codeql-analysis-reusable.yaml@gha/v0 |
| with: |
| java-version: | |
| 8 |
| 17 |
| # Permissions required to publish Security Alerts |
| permissions: |
| actions: read |
| contents: read |
| security-events: write |