Skip to content

ci: T9082: onboard CodeQL scanning - #156

Merged
andamasov merged 1 commit into
productionfrom
feature/T9082-codeql-onboard
Jul 14, 2026
Merged

andamasov merged 1 commit into
productionfrom
feature/T9082-codeql-onboard

Conversation

@andamasov

@andamasov andamasov commented Jul 14, 2026 •

Copy link
Copy Markdown
Member

Adds a thin caller of the central CodeQL reusable workflow (vyos/.github codeql-analysis.yml) — push/PR on production + weekly cron. Advisory only; not a required check.

Part of the vyos-org CodeQL rollout (T9082, IS-610). Reusable + caller shape pre-validated on the T9082 canaries (ipaddrcheck: legacy autobuild on v4, validation fail-fast, build-mode none + coverage parity; rest.vyos: legacy interpreted row).

Advances: IS-610

🤖 Generated by robots

@andamasov
andamasov marked this pull request as ready for review July 14, 2026 16:46
@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a GitHub Actions workflow that runs the shared CodeQL analysis workflow for Python on production changes and a weekly schedule, with path exclusions and restricted permissions.

Changes

CodeQL Analysis

Layer / File(s) Summary
Configure CodeQL workflow
.github/workflows/codeql.yml
Adds push and pull-request triggers for production, excludes .github/** and Markdown changes, schedules weekly analysis, sets read-only permissions with security-events: write, and invokes the shared Python CodeQL workflow (lines 1–30).
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title accurately summarizes the main change: onboarding CodeQL scanning via CI.
Description check ✅ Passed The description is clearly related and matches the workflow change and rollout context.
✨ Finishing Touches
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feature/T9082-codeql-onboard

Comment @coderabbitai help to get the list of available commands.

@andamasov

Copy link
Copy Markdown
Member Author

Adversarial review — a6030d719f2b44d880df4c33e2e3d05bf6ab1474 — Codex + agy parallel

Providers disagree — dispositions below.

  1. [single-source, agy — high] Self-reference @production ref-resolution failure during PR — rejected, factually wrong: reusable-workflow refs resolve at run time against the existing production branch (which already carries the reusable); every T9082 canary run today resolved cross-repo the same way. Codex explicitly verified no recursion. The real (known) limitation — a PR editing the reusable itself doesn't self-test — is handled by the canary-pin pattern in the T9082 spec §5.4.
  2. [single-source, agy — medium] .github/** paths filter dead PR triggers in this repo — acknowledged, accepted: this repo's Python lives at root scripts/, which the filter does cover; workflow-file PRs intentionally don't re-scan (fleet parity); the weekly cron is the backstop.
  3. [single-source, agy — medium] SARIF category collision with codeql-analysis.yml — rejected, factually wrong: the reusable is workflow_call-only and never uploads on its own; this caller is the single upload source for the repo. Codex explicitly verified no collision.

Codex verdict: NO FINDINGS.


Each finding must receive a fix commit OR a pushback reply in a reply to this comment before merge. Dispositions above serve as the pushback record.

@andamasov
andamasov merged commit 1b83aa1 into production Jul 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant