[CodeQL] Enable GitHub Actions Workflows security analysis
Open
needs-triage
- Dominant language
- Go
- Stars
- 46.3k
- Forks
- 9k
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 89
Description
Reference:
https://github.blog/changelog/2025-04-22-github-actions-workflow-security-analysis-with-codeql-is-now-generally-available/
May need to update https://github.com/cli/cli/blob/trunk/.github/workflows/codeql.yml for the matrix stragety with `actions` and `go` as suggested here:
https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#changing-the-languages-that-are-analyzed
Contributor guide
Assessment
This issue has not been assessed yet.