Skip to content

ci(codeql): switch to advanced setup so fork pull requests are scanned - #911

Merged
JSv4 merged 1 commit into
mainfrom
ci/codeql-advanced-setup
Oct 3, 2026
Merged

JSv4 merged 1 commit into
mainfrom
ci/codeql-advanced-setup

Conversation

@JSv4

@JSv4 JSv4 commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Why

Pull requests from forks can't be merged right now. The main ruleset requires a CodeQL result before merge, but GitHub's managed CodeQL "default setup" never analyzes pull requests from forks. So an external PR waits for a check that never starts. Every PR opened from a branch in this repo (#890–#909) has a CodeQL run. All four fork PRs (#808, #893, #896, #898) have none, and #893 shows as BLOCKED even though all its other checks pass.

What this changes

This adds .github/workflows/codeql.yml, a CodeQL workflow we maintain ourselves ("advanced setup"), unlike default setup it runs on fork pull requests. It copies the current default-setup configuration:

  • languages: actions, csharp, javascript-typescript, python (one job each)
  • build-mode: none, so nothing has to be compiled, matching what default setup does today
  • security-extended queries
  • runs on pushes to main, pull requests to main, a weekly schedule, and manual dispatch

Results are filed under the same /language:<lang> categories default setup uses, so existing alerts carry over instead of being duplicated. A new push to a PR cancels that PR's earlier scan.

Rollout (order matters)

GitHub rejects uploads from a hand-written CodeQL workflow while default setup is turned on. The jobs on this PR will fail at the upload step until step 1 below is done. Default setup keeps the PR mergeable until then.

  1. Turn off default setup: Settings → Code security → CodeQL → Disable.
  2. Re-run this PR's CodeQL workflow and confirm all four Analyze jobs upload.
  3. Merge.
  4. Re-trigger the open fork PRs (fix(core): wrap tr-TR letter numbering like the default formatter #893, fix(html): read w:start/w:end paragraph indents (#894) #896, feat(html): emit Word lists as ol/ul/li behind semanticLists (#895) #898) by closing and reopening them, or with "Update branch". A pull request only picks up a new workflow on a fresh event.

Validation

The YAML parses, and the configuration was compared against the inputs of the latest default-setup run (codeql-action@v4, build-mode: none, security-extended). The deciding test is #893 after step 4. Its analysis should upload, and the PR should stop showing as BLOCKED. Until that passes, the fork-PR case is unverified.

🤖 Generated with Claude Code

GitHub's managed default setup skips pull requests from forks, while the
main ruleset requires a CodeQL result, so every external PR was blocked.
This workflow mirrors the default-setup config (actions, csharp,
javascript-typescript, python; build-mode none; security-extended; weekly)
and keeps the /language:<lang> categories so existing alerts carry over.
@JSv4
JSv4 merged commit f67fd69 into main Oct 3, 2026
19 of 23 checks passed
@JSv4
JSv4 deleted the ci/codeql-advanced-setup branch October 3, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant