Skip to content

ci: add CodeQL or equivalent security scanning workflow #665

@ericksoa

Description

@ericksoa

Summary

Add automated security scanning to the CI pipeline. CodeQL (or equivalent) should run on PRs and on a weekly schedule to catch common vulnerability patterns in JavaScript and Python.

Identified during review of #390.

Metadata

Metadata

Assignees

Labels

securitySomething isn't secure

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions