Restore PR CI; build the Kotlin for CodeQL; OpenCode security review - #228
Conversation
ci.yml is back as the source central CI Validation binds to (HereLiesAz/workflows semantic_catalog.py): workspace build + test on Node 24, conformance fixture drift, and the Compose storefront (Wasm, Android, desktopTest, :azp:test). CodeQL java-kotlin was autobuild, which finds no build at the root and fails on every run. It now builds storefront-cmp's desktop target and the azp verifier with Gradle under the tracer (Java 17, version frozen). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's GuideRestores hash-bound CI validation and expands it to cover workspace, fixture, and Compose storefront checks, while fixing CodeQL Kotlin analysis by using a Java 17 manual Gradle build from the storefront project instead of repository-root autobuild. Sequence diagram for manual Kotlin CodeQL buildsequenceDiagram
participant CodeQL as CodeQL workflow
participant Runner as GitHub runner
participant Gradle as storefront-cmp Gradle
participant Kotlin as Kotlin compiler
CodeQL->>Runner: setup-java Java 17
CodeQL->>Gradle: compileKotlinDesktop
CodeQL->>Gradle: :azp:compileKotlin
Gradle->>Kotlin: compile Kotlin sources under tracer
Kotlin-->>Gradle: compilation results
Gradle-->>CodeQL: build succeeds
CodeQL->>CodeQL: analyze
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
security-review.yml is the source HereLiesAz/workflows' opencode-security-review.yml binds to: a read-only OpenCode review of each pull request, posted as one comment. Advisory. Replaces the Copilot security review, which fails on every run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 16 hours by commenting @sourcery-ai review. Upgrade to get a review now.
CI.
.github/workflows/ci.ymlis back. It is the source that central CI Validation binds to by hash, so the controller swaps it for a tracker. It runs:assembleDebug,desktopTest,:azp:test.Needs HereLiesAz/workflows#83 (hash
37131af3…).CodeQL.
java-kotlinused autobuild, which finds no build at the repo root, so it failed on every run includingmain. It is now a manual build:./gradlew compileKotlinDesktop :azp:compileKotlininapps/storefront-cmp, run under the tracer;CodeQL 2.27.1 (the version the runner uses) supports Kotlin 2.4.20.
Security review.
.github/workflows/security-review.ymlbinds to the new centralopencode-security-review.yml. It is a read-only OpenCode review of each PR, posted as one comment and advisory only. It replaces the Copilot security review. Needs HereLiesAz/workflows#84 (hashf92c8098…).After it lands, turn off the Copilot review in Settings → Code security / Copilot → Code review so the failing
github-advanced-securitycheck stops appearing.Order: workflows#83 and #84 merge first, then this PR.
Validated locally:
pnpm fixturesshows no drift.desktopTestand:azp:testpass.assembleDebugand Wasm were not run here: this sandbox has no Android SDK, and yarn gets a 403 from codeload. Both run on the hosted runner.🤖 Generated with Claude Code
https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
Summary by Sourcery
Restore repository validation, make Kotlin CodeQL analysis build successfully, and replace the pull-request security review with an advisory OpenCode workflow.
New Features:
Bug Fixes:
Enhancements:
CI:
Tests: