Skip to content

Add CodeQL analysis workflow configuration - #3

Merged
hashexplaindata merged 1 commit into
masterfrom
hashexplaindata-patch-1
Mar 12, 2026
Merged

hashexplaindata merged 1 commit into
masterfrom
hashexplaindata-patch-1

Conversation

@hashexplaindata

Copy link
Copy Markdown
Owner

This workflow file sets up CodeQL analysis for the repository, defining triggers for pushes and pull requests on the master branch, as well as a scheduled run. It includes a matrix for analyzing JavaScript and TypeScript with specified build modes.

This workflow file sets up CodeQL analysis for the repository, defining triggers for pushes and pull requests on the master branch, as well as a scheduled run. It includes a matrix for analyzing JavaScript and TypeScript with specified build modes.
Copilot AI review requested due to automatic review settings March 12, 2026 18:47
@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7a97466d2c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +16 to +18
branches: [ "master" ]
pull_request:
branches: [ "master" ]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use the repository’s main branch in CodeQL triggers

The workflow filters both push and pull_request events to master, but this repository’s active branch is main, so CodeQL will not run on normal commits/PRs and will only execute on the weekly schedule. That leaves new vulnerabilities or query regressions undetected during everyday development until the cron run; update the branch filters to main (or include both branch names if needed).

Useful? React with 👍 / 👎.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a GitHub Actions workflow to run GitHub CodeQL “Advanced” code scanning for the repository, intended to analyze JavaScript/TypeScript on pushes/PRs to master and on a weekly schedule.

Changes:

  • Introduces .github/workflows/codeql.yml to configure CodeQL analysis runs.
  • Defines a matrix to scan javascript-typescript with build-mode: none.
  • Adds CodeQL init/analyze steps with the required workflow permissions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

include:
- language: javascript-typescript
build-mode: none
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'

Copilot AI Mar 12, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor grammar in comment: "values keywords" reads incorrectly; consider changing to just "values" or "keywords".

Suggested change
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
# CodeQL supports the following values for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'

Copilot uses AI. Check for mistakes.
Comment on lines +46 to +47
- language: javascript-typescript
build-mode: none

Copilot AI Mar 12, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

YAML indentation for the matrix.include list is invalid: the - language: ... item needs to be indented under include: (e.g., include:\n - language: ...). As written, GitHub Actions will fail to parse this workflow.

Suggested change
- language: javascript-typescript
build-mode: none
- language: javascript-typescript
build-mode: none

Copilot uses AI. Check for mistakes.
Comment on lines +56 to +58
steps:
- name: Checkout repository
uses: actions/checkout@v4

Copilot AI Mar 12, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

steps: must contain a YAML sequence indented beneath it. The - name: ... entries are currently aligned with steps: which will break workflow parsing; indent the step items under steps:.

Copilot uses AI. Check for mistakes.
@hashexplaindata
hashexplaindata merged commit 50a2c6e into master Mar 12, 2026
6 checks passed
@hashexplaindata
hashexplaindata deleted the hashexplaindata-patch-1 branch March 12, 2026 23:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants