Skip to content

ci: add explicit CodeQL workflow, replace Default setup - #87

Merged
tonibergholm merged 3 commits into
mainfrom
fix-codeql-config
May 22, 2026
Merged

tonibergholm merged 3 commits into
mainfrom
fix-codeql-config

Conversation

@tonibergholm

Copy link
Copy Markdown
Member

Summary

  • Adds .github/workflows/codeql.yml with a file-tracked CodeQL configuration for rust and python
  • Runs on push to main, all PRs, and weekly (Monday 07:30 UTC)
  • Category tags (/language:rust, /language:python) match what the Default setup was reporting, so existing alert history is preserved

Why

GitHub's Default setup (configured in repo Settings) couldn't locate refs/heads/main to diff against on PRs, producing the warning: "1 configuration not found". A file-tracked workflow gives CodeQL a stable base ref on every branch and eliminates the warning.

After merging

Disable the Default setup to avoid duplicate alerts:

Settings → Security → Code scanning → Default setup → Disable

If Default setup is left on, both configurations will run and the same findings will appear twice.

GitHub's Default setup couldn't find refs/heads/main to diff against,
producing a spurious "1 configuration not found" warning on every PR.
A file-tracked workflow gives CodeQL a stable base to compare from.

Analyzes rust and python on push/PR and weekly; category tags match
what the Default setup was reporting (/language:rust, /language:python).
Copilot AI review requested due to automatic review settings May 22, 2026 13:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds an explicit, file-tracked GitHub Actions CodeQL workflow to replace reliance on GitHub “Default setup”, aiming to eliminate the “configuration not found” warning and preserve alert history via consistent category tags.

Changes:

  • Introduces .github/workflows/codeql.yml running CodeQL for Rust and Python on push to main, on all PRs, and on a weekly cron.
  • Uses a language matrix and sets SARIF category tags (/language:rust, /language:python) to match prior Default setup behavior.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/codeql.yml
Comment thread .github/workflows/codeql.yml
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings May 22, 2026 13:45
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@tonibergholm
tonibergholm merged commit e1e8626 into main May 22, 2026
14 of 16 checks passed
@tonibergholm
tonibergholm deleted the fix-codeql-config branch May 22, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants