Add CodeQL analysis workflow configuration - #3
Conversation
This workflow file sets up CodeQL analysis for the repository, defining triggers for pushes and pull requests on the master branch, as well as a scheduled run. It includes a matrix for analyzing JavaScript and TypeScript with specified build modes.
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7a97466d2c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| branches: [ "master" ] | ||
| pull_request: | ||
| branches: [ "master" ] |
There was a problem hiding this comment.
Use the repository’s main branch in CodeQL triggers
The workflow filters both push and pull_request events to master, but this repository’s active branch is main, so CodeQL will not run on normal commits/PRs and will only execute on the weekly schedule. That leaves new vulnerabilities or query regressions undetected during everyday development until the cron run; update the branch filters to main (or include both branch names if needed).
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Pull request overview
Adds a GitHub Actions workflow to run GitHub CodeQL “Advanced” code scanning for the repository, intended to analyze JavaScript/TypeScript on pushes/PRs to master and on a weekly schedule.
Changes:
- Introduces
.github/workflows/codeql.ymlto configure CodeQL analysis runs. - Defines a matrix to scan
javascript-typescriptwithbuild-mode: none. - Adds CodeQL init/analyze steps with the required workflow permissions.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
You can also share your feedback on Copilot code review. Take the survey.
| include: | ||
| - language: javascript-typescript | ||
| build-mode: none | ||
| # CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift' |
There was a problem hiding this comment.
Minor grammar in comment: "values keywords" reads incorrectly; consider changing to just "values" or "keywords".
| # CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift' | |
| # CodeQL supports the following values for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift' |
| - language: javascript-typescript | ||
| build-mode: none |
There was a problem hiding this comment.
YAML indentation for the matrix.include list is invalid: the - language: ... item needs to be indented under include: (e.g., include:\n - language: ...). As written, GitHub Actions will fail to parse this workflow.
| - language: javascript-typescript | |
| build-mode: none | |
| - language: javascript-typescript | |
| build-mode: none |
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 |
There was a problem hiding this comment.
steps: must contain a YAML sequence indented beneath it. The - name: ... entries are currently aligned with steps: which will break workflow parsing; indent the step items under steps:.
This workflow file sets up CodeQL analysis for the repository, defining triggers for pushes and pull requests on the master branch, as well as a scheduled run. It includes a matrix for analyzing JavaScript and TypeScript with specified build modes.