Skip to content

ci: add advanced CodeQL scanning - #51

Merged
mnriem merged 1 commit into
github:mainfrom
mnriem:mnriem-advanced-codeql-setup
Oct 5, 2026
Merged

mnriem merged 1 commit into
github:mainfrom
mnriem:mnriem-advanced-codeql-setup

Conversation

@mnriem

@mnriem mnriem commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add an advanced CodeQL workflow aligned with Spec Kit's workflow, retaining the actions and javascript-typescript matrix and default query suite.
  • Scan pushes and pull requests targeting main, including fork PRs through pull_request rather than pull_request_target. Normal fork-contributor workflow approvals still apply; there are no path filters or fork exclusions. Actions are SHA-pinned, checkout credentials are not persisted, and job permissions are limited to contents: read and security-events: write.
  • Preserve existing weekly coverage with Tuesday 04:23 UTC scans, deliberately beyond Spec Kit's unscheduled workflow. No build/dependency steps, custom query suites, or release behavior are added.
  • Document the separately coordinated activation prerequisites in AGENTS.md. This is an independent two-file change based on current upstream main.

Local validation

  • actionlint 1.7.12 passed.
  • PyYAML parsing and exact static checks passed for triggers, weekly cron, language matrix, permissions, immutable action pins, analysis categories, checkout credential handling, and absence of extra build/release/custom-query surfaces.
  • git diff --check passed; only .github/workflows/codeql.yml and AGENTS.md changed.

These checks do not establish a successful live CodeQL scan.

Pending maintainer-coordinated activation

This PR does not disable default setup or change repository security settings, branch protections, rulesets, or fork Actions settings.

  1. Review and merge the replacement workflow while default setup remains enabled. Advanced CodeQL SARIF uploads are rejected while default setup is enabled, so pre-switch upload failures are expected.
  2. Once the approved replacement exists on main, an authorized maintainer must coordinate disabling default setup in the upstream repository and rerunning the merge-triggered CodeQL workflow. Do not disable default setup prematurely.
  3. Verify successful live uploads for both /language:actions and /language:javascript-typescript on main and an approved fork PR run, plus continued weekly scheduling.

If existing required checks prevent merging the replacement, any tightly timed switch-before-merge requires a separate maintainer decision; this PR does not bypass or alter protections.

Retain Actions and JavaScript/TypeScript analysis with weekly coverage and fork-eligible pull request scanning. Document the separately coordinated default-to-advanced activation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 19:11

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No blocking issues remain; activation and live-upload verification are explicitly documented as separate maintainer responsibilities.

Review effort: Balanced
Findings: None

What changed in this PR

Adds advanced CodeQL scanning and documents the coordinated transition from default setup.

Changes:

  • Scans Actions and JavaScript/TypeScript on main pushes, pull requests, and weekly.
  • Uses SHA-pinned actions, limited permissions, and checkout without persisted credentials.
  • Documents activation prerequisites and live-upload verification.
File Description
AGENTS.md Documents scanning safeguards and maintainer-led activation.
.github/​workflows/​codeql.yml Adds the two-language CodeQL workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mnriem
mnriem merged commit e0816db into github:main Oct 5, 2026
6 of 8 checks passed
@mnriem
mnriem deleted the mnriem-advanced-codeql-setup branch October 5, 2026 19:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants