Repository navigation
Replace CodeQL default setup with a cached, path-filtered Advanced Setup workflow - #151
Merged
Merged
Conversation
Default setup autobuilt the Rust crate from scratch every run (~8.5 min, no cache), had no concurrency group so superseded PR pushes queued another full scan instead of cancelling it, and scanned every merged change twice (once as the PR head, again as the resulting main push) — none of which is configurable since it isn't a workflow file in the repo. .github/workflows/codeql.yml reuses setup-tauri-env's cached Rust build (same cache coverage.yml's rust job warms), adds a concurrency group that cancels superseded PR runs, and skips the Rust/JS/Actions analyze jobs whose paths a PR didn't touch. Requires disabling CodeQL "default setup" in Settings -> Code security and analysis before this workflow's SARIF uploads will be accepted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2
|
This run was cancelled 🛑 The workflow was cancelled before completion. Please check the link below for details. |
DianaSensei
enabled auto-merge (squash)
September 17, 2026 17:40
|
|
||
| - name: Build (rust) | ||
| if: matrix.language == 'rust' | ||
| run: cargo build --manifest-path src-tauri/Cargo.toml |
GitHub rejected the file outright ("Unrecognized named-value: 'matrix'")
because the analyze job's own if: condition referenced matrix.language to
decide whether to run — matrix values only exist inside a job's
strategy/steps/outputs, not in the job-level if that gates the job itself.
Split the single matrixed job into three explicit jobs (analyze-actions,
analyze-js, analyze-rust), each gated on its own needs.changes.outputs.*.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #151 +/- ##
==========================================
+ Coverage 42.02% 42.04% +0.01%
==========================================
Files 299 299
Lines 19848 19848
Branches 4904 4904
==========================================
+ Hits 8342 8345 +3
+ Misses 10508 10506 -2
+ Partials 998 997 -1
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
1 of 2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.





Summary
Analyze (rust)job autobuilt the crate from scratch every run (~8.5 min, no cache), there was no concurrency group so a new PR push queued another full scan instead of cancelling the in-flight one, and every merged change was scanned twice — once as the PR head, again as the resulting push tomain..github/workflows/codeql.yml(Advanced Setup): reusessetup-tauri-env's cached Rust build (same cachecoverage.yml'srustjob warms), aconcurrencygroup that cancels superseded PR runs, and a cheapgit diff-based check that skips the Rust/JS-TS/Actions analyze job(s) whose paths a given PR didn't touch (schedule/workflow_dispatch/push-to-mainstill always run all three).security.ymlthat explained why CodeQL wasn't run from that workflow, pointing at the new file instead.GitHub refuses SARIF uploads from an Advanced Setup workflow while CodeQL "default setup" is still enabled — this PR's own
CodeQLcheck will show red until it's turned off. Please go to Settings → Code security and analysis → CodeQL analysis and switch it from Default to Advanced (or Disable, since this workflow now covers it) before or immediately after merging.Test plan
python3 -c "import yaml; yaml.safe_load(open('.github/workflows/codeql.yml'))"— valid YAMLCodeQLcheck runs green on this PR🤖 Generated with Claude Code
https://claude.ai/code/session_01BCypCuViyQDKGWxWspXKs2
Generated by Claude Code