Skip to content

ci: add CodeQL code scanning for Python, TypeScript, and Actions - #974

Draft
peteski22 wants to merge 1 commit into
mainfrom
ci/add-codeql-code-scanning
Draft

peteski22 wants to merge 1 commit into
mainfrom
ci/add-codeql-code-scanning

Conversation

@peteski22

Copy link
Copy Markdown
Contributor

Description

This repository has no static analysis for security defects. This PR adds GitHub CodeQL, which is free for public repositories and reports its findings into the Security tab.

It uses advanced setup (a workflow file) rather than the settings switch, for two reasons. The configuration stays versioned next to the rest of CI, which is how every other check here is defined. And it can exclude generated files, which the settings switch cannot.

Three languages are scanned, matching what GitHub detects for this repo: actions, javascript-typescript, and python. javascript-typescript is one language identifier covering both, so listing them separately would analyze the same files twice.

The workflow has no path filter, unlike the others here. A filter would let some pull requests merge with no scan at all.

.github/codeql/codeql-config.yml ignores web/src/client/schema.ts and web/src/routeTree.gen.ts. Both are generated and committed, so a fix applied there is lost on the next regeneration.

Verification

Check Result
actionlint Clean
zizmor --persona=regular Clean
act -n dry run, python leg Job succeeded, exit 0
make lint Passed
make typecheck Passed, 567 source files

Action versions were resolved from the GitHub API at authoring time and pinned to full commit SHAs, matching the existing workflows.

Follow-ups, not in this PR

PR Type

  • New Feature
  • Bug Fix
  • Refactor
  • Documentation
  • Infrastructure / CI

Relevant issues

The originating request is tracked in a private mozilla-ai repository, so there is no public issue to close from here. Related: #967.

Checklist

  • I understand the code I am submitting.
  • I have added or updated tests that cover my change (tests/unit, tests/integration). Not applicable: a CI workflow has no unit or integration test surface. It was checked with actionlint, zizmor, and an act dry run instead.
  • I ran the Definition of Done checks locally (make lint, make typecheck, make test). make lint and make typecheck both passed. make test was not run, because no Python changed.
  • Documentation was updated where necessary. No documentation change was needed.
  • If the API contract changed, I regenerated the OpenAPI spec (uv run python scripts/generate_openapi.py). The API contract did not change.

AI Usage

  • No AI was used.
  • AI was used for drafting/refactoring.
  • This is fully AI-generated.

AI Model/Tool used:

Claude Opus 5, through Claude Code.

Any additional AI details you'd like to share:

Every action version was verified against the GitHub API rather than recalled, then pinned to a full commit SHA. The workflow was validated with actionlint, audited with zizmor, and dry run with act before this PR was opened.

NOTE:
When responding to reviewer questions, please respond yourself rather than copy/pasting reviewer comments into an AI and pasting back its answer. We want to discuss with you, not your AI :)

  • I am an AI Agent filling out this form (check box if true)

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

The repository has no static analysis for security defects. CodeQL is free
for public repositories and reports findings into the Security tab.

Use advanced setup (a workflow file) rather than the settings switch, so the
configuration is versioned next to the rest of CI and can exclude generated
files. The two committed generated files under web/src are ignored, because a
fix applied there is lost on the next regeneration.

Scans run on every push to main and every pull request, with no path filter.
A filter would let some pull requests merge with no scan at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@peteski22
peteski22 force-pushed the ci/add-codeql-code-scanning branch from fca8958 to b74c7c1 Compare September 18, 2026 07:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants