]> nmode's Git Repositories - signal-cli/blobdiff - .github/workflows/codeql-analysis.yml
Update codeql v3
[signal-cli] / .github / workflows / codeql-analysis.yml
index 8e91e580387a0549a3386958e2e95694e76c6bc0..f778268a3b11b025037bf99172c630548827a36d 100644 (file)
@@ -9,6 +9,10 @@ on:
   schedule:
     - cron: '0 7 * * 4'
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+  security-events: write
+
 jobs:
   analyse:
     name: Analyse
@@ -17,25 +21,21 @@ jobs:
     steps:
 
       - name: Setup Java JDK
-        uses: actions/setup-java@v1
+        uses: actions/setup-java@v3
         with:
-          java-version: 11
+          distribution: 'zulu'
+          java-version: 21
 
       - name: Checkout repository
-        uses: actions/checkout@v2
+        uses: actions/checkout@v4
         with:
           # We must fetch at least the immediate parents so that if this is
           # a pull request then we can checkout the head.
           fetch-depth: 2
 
-      # If this run was triggered by a pull request event, then checkout
-      # the head of the pull request instead of the merge commit.
-      - run: git checkout HEAD^2
-        if: ${{ github.event_name == 'pull_request' }}
-
       # Initializes the CodeQL tools for scanning.
       - name: Initialize CodeQL
-        uses: github/codeql-action/init@v1
+        uses: github/codeql-action/init@v3
         # Override language selection by uncommenting this and choosing your languages
         # with:
         #   languages: go, javascript, csharp, python, cpp, java
@@ -43,7 +43,7 @@ jobs:
       # Autobuild attempts to build any compiled languages  (C/C++, C#, or Java).
       # If this step fails, then you should remove it and run the build manually (see below)
       - name: Autobuild
-        uses: github/codeql-action/autobuild@v1
+        uses: github/codeql-action/autobuild@v3
 
       # â„šī¸ Command-line programs to run using the OS shell.
       # đŸ“š https://git.io/JvXDl
@@ -57,4 +57,4 @@ jobs:
       #   make release
 
       - name: Perform CodeQL Analysis
-        uses: github/codeql-action/analyze@v1
+        uses: github/codeql-action/analyze@v3