test(ci): re-register CodeQL workflow under fresh path codeql-security.yml - #93
hyperpolymath wants to merge 1 commit into
Conversation
vexometer's codeql.yml startup_fails at EVERY content state tested: v4.38.1 (#90 base), v4.38.0 SHA (#90 merge), top-level grant removed (#92) - while byte-identical content passes on hypatia. Nexia-list probes proved a byte-identical workflow under a NEW path starts and runs, implicating a wedged workflow registration rather than content. This rename tests re-registration without losing the git history of the file itself.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (15)
🔇 Additional comments (1)
📝 SummarySummary by CodeRabbit
WalkthroughThe GitHub Actions workflow name changes from ChangesCodeQL workflow
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Other Merge Risk: ⚪ Minimal · up to The workflow’s displayed name changes, but its execution behavior is unchanged, so no merge-blocking impact is evident. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit sees the workflow name Comment |
|
Result: negative — and decisive. Renamed to a brand-new workflow path + name → still
⇒ The residue is repo-side state (code scanning / CodeQL registration), not controllable from repo files. Recommended owner actions: Settings → Code security and analysis → CodeQL — toggle code scanning/default setup off and on (clears wedged registrations); if |
Second diagnostic arm (alongside #92). vexometer's
codeql.ymlstartup_fails regardless of content state while identical content passes elsewhere — same signature that in nexia-list resolved to a wedged workflow registration (fresh path started fine). Renaming re-registers the workflow under a new path. If this PR'sCodeQL (migrated)run starts while the old-name runs never did, the fix is this rename; the mystery then rests with GitHub's workflow registry rather than repo content.