Skip to content

ci: run CodeQL on pull requests from forks - #4248

Closed
aryanmehrotra wants to merge 2 commits into
developmentfrom
ci/codeql-advanced-setup
Closed

aryanmehrotra wants to merge 2 commits into
developmentfrom
ci/codeql-advanced-setup

Conversation

@aryanmehrotra

Copy link
Copy Markdown
Member

Description:

⚠️ Merge only together with an admin settings change. GitHub rejects uploads from an advanced-setup workflow while CodeQL default setup is enabled (CodeQL analyses from advanced configurations cannot be processed when the default setup is enabled). Switch CodeQL to Advanced under Settings → Code security → Code scanning, then re-run this PR's failed Analyze jobs. Until then, both Analyze jobs from this workflow will fail. That is expected.

Why

CodeQL default setup has not been analysing PRs from forks:

PR from a fork CodeQL check
#4205, #4139, #4208, #4203, #4201 yes none
#4244, #4195, #4050 no ran

Contributions from outside the org come from forks, so code scanning first saw that code after it merged. #4205 merged unscanned. Its six go/clear-text-logging alerts (#179–#184) appeared on the push to development, and first failed a check on the v1.61.0 release PR, #4246. The code fix is in #4247.

What

New .github/workflows/codeql.yml:

  • runs on pull_request and push for main and development, plus a weekly schedule so new queries also run over code that hasn't changed
  • languages go (autobuild) and actions, the same two default setup analysed
  • Go toolchain set up with setup-go and the existing setup-go-toolchain action, because go.work pins a newer Go
  • github/codeql-action pinned by SHA (v4.38.0); concurrency and job timeout follow go.yml / typos.yml
  • uses pull_request, not pull_request_target, so code from a fork never runs with a write token; security-events: write is granted on the job only

Breaking Changes (if applicable):

None. CI only.

Additional Information:

  • Verified on fix(tracing): redact tracer config in logs #4247 (before it was split out): the analysis ran, and only the upload was refused, with the error quoted above.
  • actionlint and typos: clean.
  • Rollback: revert this PR and switch the repository back to default setup.

CodeQL default setup did not analyse pull requests from forks: #4139,
#4201, #4203, #4205 and #4208 have no CodeQL check, while same-repo PRs
such as #4195 and #4244 do. #4205 therefore merged unscanned, and its
go/clear-text-logging alerts first failed a check on the v1.61.0 release
PR (#4246).

Add an advanced-setup workflow for go and actions that runs on
pull_request, push and weekly. Uploads are rejected while default setup is
enabled, so a repository admin must switch CodeQL to Advanced when this
merges.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant