grafana / grafana/shared-workflows
Add Actions to CodeQL workflow
Open
- Dominant language
- Go
- Stars
- 26
- Forks
- 49
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 36
Description
The repository has CodeQL setup, but it doesn't run CodeQL analysis for [GitHub Actions workflows](https://github.blog/security/application-security/how-to-secure-your-github-actions-workflows-with-codeql/).
We should add it to the matrix for defence-in-depth given that Actions is a core function of the code in this repository:
https://github.com/grafana/shared-workflows/blob/439318050b71c6890f5fff812cd964cbc4ec5e5f/.github/workflows/codeql.yml#L39-L46
Contributor guide
Assessment
This issue has not been assessed yet.