From 4d7992c0b79fad7fa87fb2415e1c50e7a1d9a661 Mon Sep 17 00:00:00 2001 From: Azfaar Qureshi Date: Wed, 30 Dec 2020 09:00:45 -0500 Subject: [PATCH 1/4] adding codeql workfklow --- .github/workflows/codeql-analysis.yml | 40 +++++++++++++++++++++++++++ CHANGELOG.md | 1 + 2 files changed, 41 insertions(+) create mode 100644 .github/workflows/codeql-analysis.yml diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml new file mode 100644 index 00000000000..56652735c19 --- /dev/null +++ b/.github/workflows/codeql-analysis.yml @@ -0,0 +1,40 @@ +name: "CodeQL Analysis" + +on: + push: + branches: [master] + pull_request: + branches: [master] + workflow_dispatch: + schedule: + # ┌───────────── minute (0 - 59) + # │ ┌───────────── hour (0 - 23) + # │ │ ┌───────────── day of the month (1 - 31) + # │ │ │ ┌───────────── month (1 - 12 or JAN-DEC) + # │ │ │ │ ┌───────────── day of the week (0 - 6 or SUN-SAT) + # │ │ │ │ │ + # │ │ │ │ │ + # │ │ │ │ │ + # * * * * * + - cron: '30 1 * * *' + +jobs: + CodeQL-Build: + runs-on: ubuntu-latest + + steps: + - name: Checkout repository + uses: actions/checkout@v2 + + # Initializes the CodeQL tools for scanning. + - name: Initialize CodeQL + uses: github/codeql-action/init@v1 + with: + languages: go + + - name: Autobuild + uses: github/codeql-action/autobuild@v1 + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v1 + diff --git a/CHANGELOG.md b/CHANGELOG.md index 1ff9c42a0a7..57331809674 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,6 +14,7 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm - `NewGRPCDriver` function returns a `ProtocolDriver` that maintains a single gRPC connection to the collector. (#1369) - Documentation about the project's versioning policy. (#1388) - `NewSplitDriver` for OTLP exporter that allows sending traces and metrics to different endpoints. (#1418) +- Add codeql worfklow to GitHub Actions (#TBD) ### Changed From 8588e89b81685835f827d736d152364eab801077 Mon Sep 17 00:00:00 2001 From: Azfaar Qureshi Date: Wed, 30 Dec 2020 12:47:15 -0500 Subject: [PATCH 2/4] removing PR and commit triggers --- .github/workflows/codeql-analysis.yml | 3 --- 1 file changed, 3 deletions(-) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 56652735c19..a86c94301a3 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -2,9 +2,6 @@ name: "CodeQL Analysis" on: push: - branches: [master] - pull_request: - branches: [master] workflow_dispatch: schedule: # ┌───────────── minute (0 - 59) From a3c605cb8c4c91d76a5b2c2caa82f06e38cc484c Mon Sep 17 00:00:00 2001 From: Azfaar Qureshi Date: Wed, 30 Dec 2020 12:53:03 -0500 Subject: [PATCH 3/4] updating changelog --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 57331809674..38c33125772 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,7 +14,7 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm - `NewGRPCDriver` function returns a `ProtocolDriver` that maintains a single gRPC connection to the collector. (#1369) - Documentation about the project's versioning policy. (#1388) - `NewSplitDriver` for OTLP exporter that allows sending traces and metrics to different endpoints. (#1418) -- Add codeql worfklow to GitHub Actions (#TBD) +- Add codeql worfklow to GitHub Actions (#1428) ### Changed From 289257a3e7994a7619c39e8380597c4d4190631a Mon Sep 17 00:00:00 2001 From: Azfaar Qureshi Date: Wed, 30 Dec 2020 13:05:53 -0500 Subject: [PATCH 4/4] removing push trigger --- .github/workflows/codeql-analysis.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index a86c94301a3..780ad807831 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -1,7 +1,6 @@ name: "CodeQL Analysis" on: - push: workflow_dispatch: schedule: # ┌───────────── minute (0 - 59)