name: CodeQL Go on: pull_request: types: [opened, synchronize, reopened, ready_for_review] paths: - "**/*.go" - "go.mod" - "go.sum" - "flake.*" - "Makefile" - ".github/workflows/codeql-go.yaml" push: branches: [main] paths: - "**/*.go" - "go.mod" - "go.sum" - "flake.*" - "Makefile" - ".github/workflows/codeql-go.yaml" schedule: - cron: "30 2 * * 1" workflow_dispatch: permissions: contents: read security-events: write packages: read concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: analyze-go: name: Analyze Go if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} runs-on: depot-ubuntu-latest-16 timeout-minutes: 60 steps: - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 with: go-version: "1.26.4" cache: true cache-dependency-path: | go.sum collector/go.sum - name: Initialize CodeQL uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: languages: go build-mode: manual dependency-caching: false - name: Build backend for CodeQL (PRs only) if: ${{ github.event_name == 'pull_request' }} run: | make build-server GO_BUILD_FLAGS= - name: Full build report for CodeQL (non-PRs only) if: ${{ github.event_name != 'pull_request' }} run: | make build GO_BUILD_FLAGS= - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: category: "/language:go"