name: CodeQL JavaScript/TypeScript on: push: # master plus fleet task branches: `pull_request`'s synchronize trigger # doesn't reliably fire when a revision lands on a PR head via the # merge API (see ci.yml for the live-proven receipts); `push` does, so # it's the redundant trigger for a required check that must not go # ABSENT on a fleet-authored PR revision. branches: [master, slave, 'feature/**', 'bug/**', 'chore/**', 'docs/**', 'hotfix/**'] paths: - 'panel/**' - '.github/workflows/codeql-js-ts.yml' pull_request: # Fleet PRs target the dev branch — see ci.yml's pull_request note. branches: [master, slave] paths: - 'panel/**' - '.github/workflows/codeql-js-ts.yml' schedule: - cron: '0 0 * * 1' workflow_dispatch: # A fleet branch that's also an open PR head can get both a `push` and a # `pull_request` run for the same commit; cancel the older one instead of # burning two runners on identical work. `head_ref` (set only for # pull_request) and `ref_name` (the short branch name, valid for push) both # resolve to the SAME branch name, so the two event shapes share one group — # plain `github.ref` would NOT (it's `refs/pull//merge` for pull_request # vs `refs/heads/` for push, so it'd never collapse them). concurrency: group: ${{ github.workflow }}-${{ github.head_ref || github.ref_name }} cancel-in-progress: true jobs: analyze: name: Analyze (${{ matrix.language }}) runs-on: ubuntu-latest permissions: actions: read contents: read security-events: write strategy: fail-fast: false matrix: include: - language: javascript-typescript build-mode: none steps: - name: Checkout code uses: actions/checkout@v7 - name: Initialize CodeQL uses: github/codeql-action/init@v4.37.3 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v4.37.3 with: category: "/language:${{ matrix.language }}"