Skip to content

Remove non-functional CodeQL workflow - #4

Merged
safenestdev merged 1 commit into
mainfrom
security/remove-dead-codeql
Aug 27, 2026
Merged

safenestdev merged 1 commit into
mainfrom
security/remove-dead-codeql

Conversation

@safenestdev

Copy link
Copy Markdown
Contributor

The existing codeql.yml (added 2026-03-09, language: csharp) has 0 recorded runs in the Actions history and can't realistically work: no .csproj/.sln exists, just Unity .asmdef source referencing UnityEngine APIs, which needs a licensed Unity Editor to compile — not something a plain CodeQL Autobuild step in CI can do.

Removing it rather than leaving a workflow file that looks like SAST coverage but has never once executed. No SCA addition either — this is a source-only package with no external dependency manifest to scan against.

If Unity CI ever gets a real build step (e.g. via a licensed Unity CI image), CodeQL could be revisited then.

Added 2026-03-09, targeting language: csharp, but has 0 recorded
runs ever (confirmed via the Actions API) and can't realistically
work: this package has no .csproj/.sln, just Unity .asmdef source
referencing UnityEngine APIs, which requires a licensed Unity
Editor to compile -- not available to a plain CodeQL Autobuild step
in CI. Removing a config that looks like coverage but has never
actually run, rather than leaving it as false assurance.

No SCA addition either: this is a source-only Unity package with
no external dependency manifest to scan.
@safenestdev
safenestdev merged commit 226b04c into main Aug 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant