From 98228b3bcfd45b5b7e512d2d492fac6c1b061ee8 Mon Sep 17 00:00:00 2001 From: Imani Manyara <19682005+imanimanyara@users.noreply.github.com> Date: Fri, 2 Oct 2026 06:06:50 -0400 Subject: [PATCH] Run CI on pull requests instead of pushes to main The org rule is that every change reaches main through a pull request, so CI belongs on pull_request, where it gates the change before it lands. A push trigger on main runs after the change has already landed and re-runs every check a second time when a pull request merges. Drop the push-to-main trigger and make sure workflow_dispatch is present so a maintainer can still re-run the workflow by hand. Existing pull_request filters and any schedule are unchanged; tag-driven release workflows are untouched. --- .github/workflows/codeql.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index d25150f..e63b11d 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,10 +1,9 @@ name: codeql on: - push: - branches: [main] pull_request: branches: [main] + workflow_dispatch: schedule: - cron: "30 6 * * 1" # weekly, Monday 06:30 UTC (≈ 02:30 ET)