| # For most projects, this workflow file will not need changing; you simply need |
| # to commit it to your repository. |
| # |
| # You may wish to alter this file to override the set of languages analyzed, |
| # or to provide custom queries or build logic. |
| # |
| # ******** NOTE ******** |
| # We have attempted to detect the languages in your repository. Please check |
| # the `language` matrix defined below to confirm you have the correct set of |
| # supported CodeQL languages. |
| # |
| name: "CodeQL JAVA" |
| |
| on: |
| push: |
| branches: [ master ] |
| pull_request: |
| # The branches below must be a subset of the branches above |
| branches: [ master ] |
| workflow_dispatch: |
| schedule: |
| - cron: '38 1 * * 0' |
| |
| env: |
| DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }} |
| |
| # Cancel superseded runs on the same PR, but never cancel master/scheduled runs |
| concurrency: |
| group: ${{ github.workflow }}-${{ github.ref }} |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} |
| |
| jobs: |
| analyze: |
| name: Analyze |
| runs-on: ubuntu-latest |
| steps: |
| - name: Checkout repository |
| uses: actions/checkout@v5 |
| |
| # Initializes the CodeQL tools for scanning. |
| - name: Initialize CodeQL |
| uses: github/codeql-action/init@v3 |
| with: |
| config-file: ./.github/codeql/codeql-config.yml |
| languages: java |
| # If you wish to specify custom queries, you can do so here or in a config file. |
| # By default, queries listed here will override any specified in a config file. |
| # Prefix the list here with "+" to use these queries and those in the config file. |
| # queries: ./path/to/local/query, your-org/your-repo/queries@main |
| |
| - name: Set up JDK 17 |
| uses: actions/setup-java@v5 |
| with: |
| distribution: 'temurin' |
| java-version: '17' |
| cache: 'maven' |
| - run: mvn -U -ntp -e clean install -DskipTests |
| |
| # Keep only third-party dependencies in the post-job Maven cache: Unomi's own |
| # snapshots are rebuilt every run and would only bloat the cache / risk staleness |
| - name: Clean Unomi artifacts from Maven cache |
| if: always() |
| run: rm -rf ~/.m2/repository/org/apache/unomi |
| |
| - name: Perform CodeQL Analysis |
| uses: github/codeql-action/analyze@v3 |
| with: |
| upload: false |