operator icon indicating copy to clipboard operation
operator copied to clipboard

Add CodeQL analysis to the operator

Open afrittoli opened this issue 2 years ago • 6 comments

Changes

CodeQL performs static code analysis on every PR and may help identify security issues in the code.

It also helps to meet the OpenSSF badge requirements about security static checks.

Signed-off-by: Andrea Frittoli [email protected]

Submitter Checklist

These are the criteria that every PR should meet, please check them off as you review them:

  • [x] Run make test lint before submitting a PR
  • [x] Includes tests (if functionality changed/added)
  • [x] Includes docs (if user facing)
  • [x] Commit messages follow commit message best practices

See the contribution guide for more details.

Release Notes

NONE

afrittoli avatar Oct 10 '22 14:10 afrittoli

/approve /lgtm

vdemeester avatar Oct 10 '22 14:10 vdemeester

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: vdemeester

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

tekton-robot avatar Oct 10 '22 14:10 tekton-robot

/test pull-tekton-operator-integration-tests

vdemeester avatar Oct 10 '22 14:10 vdemeester

/retest

piyush-garg avatar Oct 11 '22 10:10 piyush-garg

I rebased the PR

afrittoli avatar Oct 11 '22 10:10 afrittoli

/lgtm

piyush-garg avatar Oct 12 '22 04:10 piyush-garg

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale with a justification. Stale issues rot after an additional 30d of inactivity and eventually close. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle stale

Send feedback to tektoncd/plumbing.

tekton-robot avatar Jan 10 '23 05:01 tekton-robot

Stale issues rot after 30d of inactivity. Mark the issue as fresh with /remove-lifecycle rotten with a justification. Rotten issues close after an additional 30d of inactivity. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle rotten

Send feedback to tektoncd/plumbing.

tekton-robot avatar Feb 09 '23 05:02 tekton-robot

/remove-lifecycle rotten

piyush-garg avatar Feb 23 '23 16:02 piyush-garg

/retest

piyush-garg avatar Feb 23 '23 16:02 piyush-garg

We need to fix those (or ignore).. 😅

vdemeester avatar Mar 22 '23 15:03 vdemeester

/retest

piyush-garg avatar May 09 '23 04:05 piyush-garg

/test all

piyush-garg avatar May 09 '23 04:05 piyush-garg