2020 language : ["cpp", "csharp", "go", "java", "javascript", "python", "ruby"]
2121
2222 steps :
23- - uses : actions/checkout@v3
23+ - uses : actions/checkout@v4
2424
2525 - name : Initialize CodeQL
2626 run : |
3232
3333 - name : " Check and publish codeql-LANG-queries (src) pack"
3434 env :
35- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
35+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
3636 run : |
3737 PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-queries/versions --jq '.[0].metadata.container.tags[0]')
3838 CURRENT_VERSION=$(grep version ${{ matrix.language }}/src/qlpack.yml | awk '{print $2}')
5757 language : ["cpp", "csharp", "go", "java", "javascript", "python", "ruby"]
5858
5959 steps :
60- - uses : actions/checkout@v3
60+ - uses : actions/checkout@v4
6161
6262 - name : Initialize CodeQL
6363 run : |
6969
7070 - name : " Check and publish codeql-LANG-libs (lib) pack"
7171 env :
72- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
72+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
7373 run : |
7474 PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-libs/versions --jq '.[0].metadata.container.tags[0]')
7575 CURRENT_VERSION=$(grep version ${{ matrix.language }}/lib/qlpack.yml | awk '{print $2}')
@@ -84,13 +84,17 @@ jobs:
8484 extensions :
8585 runs-on : ubuntu-latest
8686
87+ permissions :
88+ contents : read
89+ packages : write
90+
8791 strategy :
8892 fail-fast : false
8993 matrix :
9094 language : ["csharp", "java"]
9195
9296 steps :
93- - uses : actions/checkout@v3
97+ - uses : actions/checkout@v4
9498
9599 - name : Initialize CodeQL
96100 run : |
@@ -102,7 +106,7 @@ jobs:
102106
103107 - name : Check and publish codeql-LANG-extensions (ext) pack
104108 env :
105- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
109+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
106110 run : |
107111 PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-extensions/versions --jq '.[0].metadata.container.tags[0]')
108112 CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext/qlpack.yml | awk '{print $2}')
@@ -117,13 +121,17 @@ jobs:
117121 library_sources_extensions :
118122 runs-on : ubuntu-latest
119123
124+ permissions :
125+ contents : read
126+ packages : write
127+
120128 strategy :
121129 fail-fast : false
122130 matrix :
123131 language : ["csharp", "java"]
124132
125133 steps :
126- - uses : actions/checkout@v3
134+ - uses : actions/checkout@v4
127135
128136 - name : Initialize CodeQL
129137 run : |
@@ -135,7 +143,7 @@ jobs:
135143
136144 - name : Check and publish codeql-LANG-library-sources (ext-library-sources) pack
137145 env :
138- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
146+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
139147 run : |
140148 PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-library-sources/versions --jq '.[0].metadata.container.tags[0]')
141149 CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext-library-sources/qlpack.yml | awk '{print $2}')
0 commit comments