Repository navigation
ci: add advanced CodeQL scanning - #51
Merged
Merged
Conversation
Retain Actions and JavaScript/TypeScript analysis with weekly coverage and fork-eligible pull request scanning. Document the separately coordinated default-to-advanced activation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No blocking issues remain; activation and live-upload verification are explicitly documented as separate maintainer responsibilities.
Review effort: Balanced
Findings: None
What changed in this PR
Adds advanced CodeQL scanning and documents the coordinated transition from default setup.
Changes:
- Scans Actions and JavaScript/TypeScript on
mainpushes, pull requests, and weekly. - Uses SHA-pinned actions, limited permissions, and checkout without persisted credentials.
- Documents activation prerequisites and live-upload verification.
| File | Description |
|---|---|
| AGENTS.md | Documents scanning safeguards and maintainer-led activation. |
| .github/workflows/codeql.yml | Adds the two-language CodeQL workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
actionsandjavascript-typescriptmatrix and default query suite.main, including fork PRs throughpull_requestrather thanpull_request_target. Normal fork-contributor workflow approvals still apply; there are no path filters or fork exclusions. Actions are SHA-pinned, checkout credentials are not persisted, and job permissions are limited tocontents: readandsecurity-events: write.AGENTS.md. This is an independent two-file change based on current upstreammain.Local validation
actionlint1.7.12 passed.git diff --checkpassed; only.github/workflows/codeql.ymlandAGENTS.mdchanged.These checks do not establish a successful live CodeQL scan.
Pending maintainer-coordinated activation
This PR does not disable default setup or change repository security settings, branch protections, rulesets, or fork Actions settings.
main, an authorized maintainer must coordinate disabling default setup in the upstream repository and rerunning the merge-triggered CodeQL workflow. Do not disable default setup prematurely./language:actionsand/language:javascript-typescriptonmainand an approved fork PR run, plus continued weekly scheduling.If existing required checks prevent merging the replacement, any tightly timed switch-before-merge requires a separate maintainer decision; this PR does not bypass or alter protections.