# Licensed to the Apache Software Foundation (ASF) under one or more # contributor license agreements. See the NOTICE file distributed with # this work for additional information regarding copyright ownership. # The ASF licenses this file to You under the Apache license, Version 2.0 # (the "License"); you may not use this file except in compliance with # the License. You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the license for the specific language governing permissions and # limitations under the license. name: "CodeQL" on: push: branches: - 'support/struts-6-x-x' - 'release/*' pull_request: permissions: # Needed to upload the results to code-scanning dashboard. security-events: write actions: read contents: read # Needed to access OIDC token. id-token: write jobs: analyze: name: Analyze runs-on: ubuntu-latest permissions: actions: read contents: read security-events: write strategy: fail-fast: false matrix: language: [ 'java' ] steps: - name: Checkout repository uses: actions/checkout@v4 - name: Setup Java JDK uses: actions/setup-java@v4 with: distribution: temurin java-version: 17 cache: 'maven' - name: Initialize CodeQL uses: github/codeql-action/init@v3.28.8 with: languages: ${{ matrix.language }} - name: Autobuild uses: github/codeql-action/autobuild@v3.28.8 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v3.28.8 with: category: "/language:${{matrix.language}}"