Unverified Commit 849b6cac authored by Yifan Xiong's avatar Yifan Xiong Committed by GitHub
Browse files

CI/CD - Add code security scanning (#206)

Add code security scanning.

__Major Revisions__
* enable dependabot auto updates
* scan code with CodeQL
parent c9cffdf1
version: 2
updates:
# enable version updates for pip
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
allow:
- dependency-type: "direct"
labels:
- "dependencies"
assignees:
- "guoshzhao"
# enable version updates for npm
- package-ecosystem: "npm"
directory: "/website/"
schedule:
interval: "weekly"
labels:
- "dependencies"
assignees:
- "abuccts"
name: "CodeQL"
on:
push:
branches:
- main
- release/*
pull_request:
branches:
- main
- release/*
schedule:
- cron: "30 1 * * 1"
jobs:
analyze:
name: CodeQL analyze ${{ matrix.language }}
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
language:
- python
- javascript
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
with:
languages: ${{ matrix.language }}
- name: Autobuild
uses: github/codeql-action/autobuild@v1
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
analyze-cpp:
name: CodeQL analyze cpp
runs-on: ubuntu-latest
container:
image: nvcr.io/nvidia/pytorch:20.12-py3
permissions:
actions: read
contents: read
security-events: write
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
with:
languages: cpp
- name: Build
run: make cppbuild -j
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment