Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
The repository has no static analysis for security defects. CodeQL is free for public repositories and reports findings into the Security tab. Use advanced setup (a workflow file) rather than the settings switch, so the configuration is versioned next to the rest of CI and can exclude generated files. The two committed generated files under web/src are ignored, because a fix applied there is lost on the next regeneration. Scans run on every push to main and every pull request, with no path filter. A filter would let some pull requests merge with no scan at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
peteski22
force-pushed
the
ci/add-codeql-code-scanning
branch
from
September 18, 2026 07:14
fca8958 to
b74c7c1
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This repository has no static analysis for security defects. This PR adds GitHub CodeQL, which is free for public repositories and reports its findings into the Security tab.
It uses advanced setup (a workflow file) rather than the settings switch, for two reasons. The configuration stays versioned next to the rest of CI, which is how every other check here is defined. And it can exclude generated files, which the settings switch cannot.
Three languages are scanned, matching what GitHub detects for this repo:
actions,javascript-typescript, andpython.javascript-typescriptis one language identifier covering both, so listing them separately would analyze the same files twice.The workflow has no path filter, unlike the others here. A filter would let some pull requests merge with no scan at all.
.github/codeql/codeql-config.ymlignoresweb/src/client/schema.tsandweb/src/routeTree.gen.ts. Both are generated and committed, so a fix applied there is lost on the next regeneration.Verification
actionlintzizmor --persona=regularact -ndry run, python legmake lintmake typecheckAction versions were resolved from the GitHub API at authoring time and pinned to full commit SHAs, matching the existing workflows.
Follow-ups, not in this PR
protect-mainruleset. Adding it there is a separate and deliberate step.developbranch that does not exist. This workflow does not copy that line.PR Type
Relevant issues
The originating request is tracked in a private mozilla-ai repository, so there is no public issue to close from here. Related: #967.
Checklist
tests/unit,tests/integration). Not applicable: a CI workflow has no unit or integration test surface. It was checked withactionlint,zizmor, and anactdry run instead.make lint,make typecheck,make test).make lintandmake typecheckboth passed.make testwas not run, because no Python changed.uv run python scripts/generate_openapi.py). The API contract did not change.AI Usage
AI Model/Tool used:
Claude Opus 5, through Claude Code.
Any additional AI details you'd like to share:
Every action version was verified against the GitHub API rather than recalled, then pinned to a full commit SHA. The workflow was validated with
actionlint, audited withzizmor, and dry run withactbefore this PR was opened.NOTE:
When responding to reviewer questions, please respond yourself rather than copy/pasting reviewer comments into an AI and pasting back its answer. We want to discuss with you, not your AI :)
🤖 Generated with Claude Code