diff --git a/.github/codeql/codeql-config-cpp.yml b/.github/codeql/codeql-config-cpp.yml new file mode 100644 index 00000000000..9ca8b845281 --- /dev/null +++ b/.github/codeql/codeql-config-cpp.yml @@ -0,0 +1,13 @@ +name: "WZ CodeQL C++ config" + +queries: + - uses: security-extended + - uses: security-and-quality + +query-filters: + - include: + precision: + - high + - very-high + tags contain: security + security-severity: /([5-9]|10)\.(\d)+/ diff --git a/.github/codeql/codeql-config.yml b/.github/codeql/codeql-config-javascript.yml similarity index 54% rename from .github/codeql/codeql-config.yml rename to .github/codeql/codeql-config-javascript.yml index 748d57b9e80..f65dce12591 100644 --- a/.github/codeql/codeql-config.yml +++ b/.github/codeql/codeql-config-javascript.yml @@ -1,4 +1,4 @@ -name: "WZ CodeQL config" +name: "WZ CodeQL JS config" # Interpreted languages scanning configuration (ex. JavaScript/TypeScript) paths: @@ -13,10 +13,3 @@ queries: - uses: security-extended - uses: security-and-quality -query-filters: - - include: - precision: - - high - - very-high - tags contain: security - security-severity: /([7-9]|10)\.(\d)+/ diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b0c88c6c5dc..1c74b6c2980 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -48,8 +48,7 @@ jobs: uses: github/codeql-action/init@v2 with: languages: ${{ matrix.language }} - config-file: ./.github/codeql/codeql-config.yml - queries: +security-extended,security-and-quality + config-file: ./.github/codeql/codeql-config-${{ matrix.language }}.yml # Override language selection by uncommenting this and choosing your languages # languages: go, javascript, csharp, python, cpp, java