ci(codeql): switch to advanced setup so fork pull requests are scanned - #911
Merged
Merged
Conversation
GitHub's managed default setup skips pull requests from forks, while the main ruleset requires a CodeQL result, so every external PR was blocked. This workflow mirrors the default-setup config (actions, csharp, javascript-typescript, python; build-mode none; security-extended; weekly) and keeps the /language:<lang> categories so existing alerts carry over.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Pull requests from forks can't be merged right now. The
mainruleset requires a CodeQL result before merge, but GitHub's managed CodeQL "default setup" never analyzes pull requests from forks. So an external PR waits for a check that never starts. Every PR opened from a branch in this repo (#890–#909) has a CodeQL run. All four fork PRs (#808, #893, #896, #898) have none, and #893 shows asBLOCKEDeven though all its other checks pass.What this changes
This adds
.github/workflows/codeql.yml, a CodeQL workflow we maintain ourselves ("advanced setup"), unlike default setup it runs on fork pull requests. It copies the current default-setup configuration:build-mode: none, so nothing has to be compiled, matching what default setup does todaysecurity-extendedqueriesmain, pull requests tomain, a weekly schedule, and manual dispatchResults are filed under the same
/language:<lang>categories default setup uses, so existing alerts carry over instead of being duplicated. A new push to a PR cancels that PR's earlier scan.Rollout (order matters)
GitHub rejects uploads from a hand-written CodeQL workflow while default setup is turned on. The jobs on this PR will fail at the upload step until step 1 below is done. Default setup keeps the PR mergeable until then.
Analyzejobs upload.Validation
The YAML parses, and the configuration was compared against the inputs of the latest default-setup run (
codeql-action@v4,build-mode: none,security-extended). The deciding test is #893 after step 4. Its analysis should upload, and the PR should stop showing asBLOCKED. Until that passes, the fork-PR case is unverified.🤖 Generated with Claude Code