Skip to content

codeql-scan: setup-android v4 with no default packages - #86

Merged
HereLiesAz merged 1 commit into
mainfrom
claude/codeql-setup-android-v4
Sep 27, 2026
Merged

HereLiesAz merged 1 commit into
mainfrom
claude/codeql-setup-android-v4

Conversation

@HereLiesAz

@HereLiesAz HereLiesAz commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

android-actions/setup-android@v3 installs the SDK tools package by default. sdkmanager no longer finds that package ("Failed to find package 'tools'"), so it exits 1 and every java-kotlin CodeQL job fails before analysis starts. The failure showed up on HereLiesAz/azphalt#232.

This switches to @v4 with packages: '', which is how ci-validation.yml already sets up Android. The analyzed build installs what it needs.

test_workflow_policy.py, audit_workflow_collection.py and every scripts/test_*.py pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv


Generated by Claude Code

Summary by Sourcery

Prevent Java/Kotlin CodeQL jobs from failing during Android SDK initialization.

Bug Fixes:

  • Fix Java/Kotlin CodeQL workflows failing during Android SDK setup by avoiding installation of the obsolete SDK tools package.

Enhancements:

  • Update the Android setup action to v4 and configure it to provide the SDK without default packages so analyzed builds can install their own requirements.

v3 installs the SDK "tools" package, which sdkmanager no longer finds,
so every java-kotlin CodeQL run fails before analysis. Mirrors
ci-validation.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
workflows 23e54bf Commit Preview URL

Branch Preview URL
Sep 27 2026, 04:49 PM

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The Java/Kotlin CodeQL workflow now uses android-actions/setup-android v4 with no default packages, preventing sdkmanager failures caused by the removed SDK tools package while allowing the analyzed build to install its required dependencies.

Sequence diagram for the corrected Android CodeQL setup

sequenceDiagram
    participant Workflow as CodeQLWorkflow
    participant AndroidAction as setup_android_v4
    participant SDKManager as sdkmanager
    participant Build as AnalyzedBuild
    participant CodeQL as CodeQLAnalysis

    Workflow->>AndroidAction: setup_android_v4
    AndroidAction->>SDKManager: install packages: ''
    SDKManager-->>AndroidAction: SDK available without tools package
    Workflow->>Build: run analyzed build
    Build->>SDKManager: install required dependencies
    SDKManager-->>Build: dependencies installed
    Workflow->>CodeQL: initialize and analyze
    CodeQL-->>Workflow: analysis completes
Loading

File-Level Changes

Change Details Files
Update Android SDK setup in the Java/Kotlin CodeQL workflow to avoid installing the obsolete default SDK tools package.
  • Upgrade the setup action from v3 to v4.
  • Pass an empty package list so the action only provisions the SDK and does not invoke sdkmanager for the unavailable tools package.
  • Keep Android dependency installation to the analyzed build.
.github/workflows/codeql-scan.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@HereLiesAz
HereLiesAz marked this pull request as ready for review September 27, 2026 18:02

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 4 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@HereLiesAz
HereLiesAz merged commit 0d8aac5 into main Sep 27, 2026
4 checks passed
@HereLiesAz
HereLiesAz deleted the claude/codeql-setup-android-v4 branch September 27, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants