mirror of
https://github.com/ckelsoe/obsidian-plaud-importer.git
synced 2026-07-22 07:49:02 +00:00
Add .github/workflows/codeql.yml for GitHub-native semantic security analysis of the TypeScript source (javascript-typescript extractor, build-mode none, no build step needed). Runs on push and PR to main plus a weekly cron, using the security-extended query suite. Complements the existing OSV-Scanner and Dependency Review jobs, which cover dependency vulnerabilities, by analyzing first-party code. This matters as the plugin moves toward write-back features that make authenticated network calls to a reverse-engineered API. Free for public repositories. |
||
|---|---|---|
| .. | ||
| ISSUE_TEMPLATE | ||
| workflows | ||