Skip to content

Remove the openapi-war-overlay module #325

Remove the openapi-war-overlay module

Remove the openapi-war-overlay module #325

Workflow file for this run

name: "CodeQL"
on:
push:
branches: [ 'master' ]
pull_request:
branches: [ 'master' ]
schedule:
# Weekly run, Mondays at 03:27 UTC
- cron: '27 3 * * 1'
# Allows running this workflow manually from the Actions tab or via the gh CLI.
workflow_dispatch:
# Cancel superseded runs on the same ref to avoid the long-running,
# eventually-cancelled analyses seen with the previous default setup.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
timeout-minutes: 360
permissions:
# Required to upload results to code scanning.
security-events: write
# Only needed for workflows in private repositories.
actions: read
contents: read
strategy:
fail-fast: false
matrix:
include:
# This large multi-module Maven build is expensive to compile, so we
# use build-mode 'none': CodeQL builds its model straight from the
# Java/Kotlin sources without invoking Maven. This avoids the long,
# eventually-cancelled autobuild that the previous default setup hit.
#
# For higher precision (dataflow through compiled dependencies) switch
# this to 'manual' and uncomment the "Build with Maven" step below.
- language: java-kotlin
build-mode: none
# Interpreted languages: no compilation, extracted straight from source.
- language: javascript-typescript
build-mode: none
- language: python
build-mode: none
# Scans the repository's own GitHub Actions workflows.
- language: actions
build-mode: none
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
queries: security-and-quality
# Exclude test and integration-test sources. With build-mode 'none'
# CodeQL extracts straight from source, so paths-ignore reliably
# scopes the analysis (it is honored for compiled languages only when
# build-mode is 'none').
config: |
paths-ignore:
- '**/src/test/**'
- '**/src/it/**'
# Third-party / vendored JavaScript — analysing it only adds noise.
- '**/*.min.js'
- '**/node_modules/**'
- '**/webjars/**'
- '**/doc-maven-plugin/src/main/resources/js/**'
# --- Manual build (only used when build-mode is 'manual') -------------
# - name: Set up JDK 11
# uses: actions/setup-java@v5
# with:
# java-version: '11'
# distribution: 'zulu'
# - name: Cache Maven packages
# uses: actions/cache@v6
# with:
# path: ~/.m2/repository
# key: ${{ runner.os }}-m2-repository-${{ hashFiles('**/pom.xml') }}
# restore-keys: ${{ runner.os }}-m2-repository
# - name: Build with Maven
# env:
# MAVEN_OPTS: -Dhttps.protocols=TLSv1.2 -Dmaven.wagon.httpconnectionManager.ttlSeconds=120 -Dmaven.wagon.http.retryHandler.requestSentEnabled=true -Dmaven.wagon.http.retryHandler.count=10
# run: mvn --batch-mode --errors -DskipTests -Dmaven.test.skip=true clean compile --file pom.xml
# ---------------------------------------------------------------------
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{ matrix.language }}"