name: 'CodeQL Go' on: push: branches: - cluster - master paths: - '**.go' pull_request: branches: - cluster - master paths: - '**.go' concurrency: cancel-in-progress: true group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} jobs: analyze: name: Analyze runs-on: ubuntu-latest permissions: actions: read contents: read security-events: write steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Go id: go uses: actions/setup-go@v5 with: cache: false go-version: stable - name: Cache Go artifacts uses: actions/cache@v4 with: path: | ~/.cache/go-build ~/go/bin ~/go/pkg/mod key: go-artifacts-${{ runner.os }}-codeql-analyze-${{ steps.go.outputs.go-version }}-${{ hashFiles('go.sum', 'Makefile', 'app/**/Makefile') }} restore-keys: go-artifacts-${{ runner.os }}-codeql-analyze- - name: Initialize CodeQL uses: github/codeql-action/init@v3 with: languages: go - name: Autobuild uses: github/codeql-action/autobuild@v3 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v3 with: category: 'language:go'