Skip to content

Merge pull request #14 from neohiro/neohiro-doctor/add-doctor-sync #25

Merge pull request #14 from neohiro/neohiro-doctor/add-doctor-sync

Merge pull request #14 from neohiro/neohiro-doctor/add-doctor-sync #25

Workflow file for this run

name: CodeQL Security Analysis
on:
push:
branches: ['M3T4P0D.3XPL01T']
paths-ignore: ['**.md', '**.txt']
schedule:
- cron: '0 6 * * 1'
concurrency:
group: codeql-${{ github.ref }}
cancel-in-progress: true
permissions:
security-events: write
contents: read
jobs:
triage:
runs-on: ubuntu-latest
timeout-minutes: 2
outputs:
soft: ${{ steps.decide.outputs.soft }}
steps:
- name: Decide enforcement mode
id: decide
env:
EVENT: ${{ github.event_name }}
ACTOR: ${{ github.actor }}
MSG: ${{ github.event.head_commit.message }}
AUTHOR: ${{ github.event.head_commit.author.name }}
COMMITTER: ${{ github.event.head_commit.committer.name }}
AGENT_ACTORS: ${{ vars.AGENT_ACTORS }}
run: |
soft=false
if [ "$EVENT" = "push" ]; then
case "$MSG" in *"[oc]"*|*"[skip-email]"*) soft=true;; esac
if [ "$AUTHOR" = "OpenCode Agent" ]; then soft=true; fi
if [ "$COMMITTER" = "OpenCode Agent" ]; then soft=true; fi
if [ "$ACTOR" = "opencode-agent" ]; then soft=true; fi
if [ -n "$AGENT_ACTORS" ]; then
case ",$AGENT_ACTORS," in *",$ACTOR,"*) soft=true;; esac
fi
fi
echo "soft=$soft"
echo "soft=$soft" >> "$GITHUB_OUTPUT"
analyze:
name: Analyze (python)
needs: triage
continue-on-error: ${{ needs.triage.outputs.soft == 'true' }}
runs-on: windows-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: python
queries: security-extended
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4