ci: run CodeQL on our runners except for fork pull requests - #45
Merged
Conversation
CodeQL was the one workflow still pinned to ubuntu-latest after the rest of CI moved to self-hosted. It now uses the same expression every job in ci.yml carries, so the analysis runs on our hardware for pushes, the weekly cron and branch pull requests, and falls back to GitHub's for fork pull requests. build-mode: none parses the tree rather than executing it, so this job never had ci.yml's arbitrary-code exposure. The guard is here so the trust boundary is stated in one form across both workflows rather than inferred per file.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CodeQL was the one workflow still pinned to
ubuntu-latestafter the rest of CI moved to self-hosted. It now carries the same expression every job inci.ymluses:So the analysis runs on our hardware for pushes to main, the weekly cron and branch pull requests, and falls back to GitHub's hardware for fork pull requests.
build-mode: noneparses the tree rather than executing it, so this job never carriedci.yml's arbitrary-code exposure. The guard is here so the trust boundary is stated the same way in both workflows rather than inferred per file.Worth watching on the first run
The self-hosted runner needs outbound access to github.com to pull the CodeQL bundle, and enough disk for the database. Nothing else —
build-mode: noneneeds no toolchain.