ci: run CodeQL on pull requests from forks - #4248
Closed
aryanmehrotra wants to merge 2 commits into
Closed
aryanmehrotra wants to merge 2 commits into
aryanmehrotra wants to merge 2 commits into
Conversation
CodeQL default setup did not analyse pull requests from forks: #4139, #4201, #4203, #4205 and #4208 have no CodeQL check, while same-repo PRs such as #4195 and #4244 do. #4205 therefore merged unscanned, and its go/clear-text-logging alerts first failed a check on the v1.61.0 release PR (#4246). Add an advanced-setup workflow for go and actions that runs on pull_request, push and weekly. Uploads are rejected while default setup is enabled, so a repository admin must switch CodeQL to Advanced when this merges.
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description:
Why
CodeQL default setup has not been analysing PRs from forks:
Contributions from outside the org come from forks, so code scanning first saw that code after it merged. #4205 merged unscanned. Its six
go/clear-text-loggingalerts (#179–#184) appeared on the push todevelopment, and first failed a check on the v1.61.0 release PR, #4246. The code fix is in #4247.What
New
.github/workflows/codeql.yml:pull_requestandpushformainanddevelopment, plus a weeklyscheduleso new queries also run over code that hasn't changedgo(autobuild) andactions, the same two default setup analysedsetup-goand the existingsetup-go-toolchainaction, becausego.workpins a newer Gogithub/codeql-actionpinned by SHA (v4.38.0); concurrency and job timeout followgo.yml/typos.ymlpull_request, notpull_request_target, so code from a fork never runs with a write token;security-events: writeis granted on the job onlyBreaking Changes (if applicable):
None. CI only.
Additional Information:
actionlintandtypos: clean.