Skip to content

Replace CodeQL default setup with a cached, path-filtered Advanced Setup workflow - #151

Merged
DianaSensei merged 2 commits into
mainfrom
codeql-advanced-setup
Sep 17, 2026
Merged

DianaSensei merged 2 commits into
mainfrom
codeql-advanced-setup

Conversation

@DianaSensei

Copy link
Copy Markdown
Owner

Summary

  • CodeQL "default setup" isn't a file in this repo, so it can't be tuned: the Analyze (rust) job autobuilt the crate from scratch every run (~8.5 min, no cache), there was no concurrency group so a new PR push queued another full scan instead of cancelling the in-flight one, and every merged change was scanned twice — once as the PR head, again as the resulting push to main.
  • Adds .github/workflows/codeql.yml (Advanced Setup): reuses setup-tauri-env's cached Rust build (same cache coverage.yml's rust job warms), a concurrency group that cancels superseded PR runs, and a cheap git diff-based check that skips the Rust/JS-TS/Actions analyze job(s) whose paths a given PR didn't touch (schedule/workflow_dispatch/push-to-main still always run all three).
  • Updates the now-stale comment in security.yml that explained why CodeQL wasn't run from that workflow, pointing at the new file instead.

⚠️ Action required before/at merge

GitHub refuses SARIF uploads from an Advanced Setup workflow while CodeQL "default setup" is still enabled — this PR's own CodeQL check will show red until it's turned off. Please go to Settings → Code security and analysis → CodeQL analysis and switch it from Default to Advanced (or Disable, since this workflow now covers it) before or immediately after merging.

Test plan

  • python3 -c "import yaml; yaml.safe_load(open('.github/workflows/codeql.yml'))" — valid YAML
  • After default setup is disabled, confirm the CodeQL check runs green on this PR
  • Confirm a docs-only PR skips all analyze jobs (paths-ignore) and a Rust-only change skips the JS-TS/Actions analyze jobs

🤖 Generated with Claude Code

https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2


Generated by Claude Code

Default setup autobuilt the Rust crate from scratch every run (~8.5 min,
no cache), had no concurrency group so superseded PR pushes queued
another full scan instead of cancelling it, and scanned every merged
change twice (once as the PR head, again as the resulting main push) —
none of which is configurable since it isn't a workflow file in the repo.

.github/workflows/codeql.yml reuses setup-tauri-env's cached Rust build
(same cache coverage.yml's rust job warms), adds a concurrency group that
cancels superseded PR runs, and skips the Rust/JS/Actions analyze jobs
whose paths a PR didn't touch.

Requires disabling CodeQL "default setup" in Settings -> Code security
and analysis before this workflow's SARIF uploads will be accepted.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2
@pullfrog

pullfrog Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

This run was cancelled 🛑

The workflow was cancelled before completion. Please check the link below for details.

Pullfrog  | View workflow run | via Pullfrog | 𝕏

@DianaSensei
DianaSensei enabled auto-merge (squash) September 17, 2026 17:40

- name: Build (rust)
if: matrix.language == 'rust'
run: cargo build --manifest-path src-tauri/Cargo.toml
GitHub rejected the file outright ("Unrecognized named-value: 'matrix'")
because the analyze job's own if: condition referenced matrix.language to
decide whether to run — matrix values only exist inside a job's
strategy/steps/outputs, not in the job-level if that gates the job itself.
Split the single matrixed job into three explicit jobs (analyze-actions,
analyze-js, analyze-rust), each gated on its own needs.changes.outputs.*.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@DianaSensei
DianaSensei merged commit 9441835 into main Sep 17, 2026
17 of 18 checks passed
@DianaSensei
DianaSensei deleted the codeql-advanced-setup branch September 17, 2026 17:43
@codecov

codecov Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 42.04%. Comparing base (0ec4be4) to head (c642ba9).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #151      +/-   ##
==========================================
+ Coverage   42.02%   42.04%   +0.01%     
==========================================
  Files         299      299              
  Lines       19848    19848              
  Branches     4904     4904              
==========================================
+ Hits         8342     8345       +3     
+ Misses      10508    10506       -2     
+ Partials      998      997       -1     
Flag Coverage Δ
frontend 37.14% <ø> (+<0.01%) ⬆️
rust 65.49% <ø> (+0.05%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 2 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants