In .github/workflows/codeql.yml:
- Update all actions to the latest version.
- Add
workflow_dispatch for manual triggering.
- Change branch from
master to main to match current default branch.
- Add
pull-requests: read to add permission for PR analysis.
- Add enhanced query suites for better security coverage.
For testing:
- Push Python/JS changes and verify CodeQL analysis runs.
- Check security alerts.
In
.github/workflows/codeql.yml:workflow_dispatchfor manual triggering.mastertomainto match current default branch.pull-requests: readto add permission for PR analysis.For testing: