Skip to content

Add CodeQL advanced setup workflow - #23

Merged
InboundFrog merged 1 commit into
mainfrom
claude/ecstatic-lalande-471879
Jul 1, 2026
Merged

InboundFrog merged 1 commit into
mainfrom
claude/ecstatic-lalande-471879

Conversation

@InboundFrog

Copy link
Copy Markdown
Owner

Replaces CodeQL default setup with a committed workflow.

Why

Default setup didn't analyze PR head commits, producing the diff-informed "2 configurations not found" warning on PRs (e.g. #22). It also kept the CodeQL config out of version control.

What

  • Adds .github/workflows/codeql.yml analyzing actions + rust.
  • Both use build-mode: none (no compile needed — Rust extracts from source, so no libudev-dev/pkg-config required in the CodeQL job).
  • Categories /language:actions + /language:rust match the previous default-setup categories, preserving alert history continuity.
  • Triggers: push to main, PRs to main, weekly schedule. Actions SHA-pinned, persist-credentials: false — consistent with ci.yml.

Required companion step (already done)

Default setup disabled via API (code-scanning/default-setup → not-configured) so advanced-setup uploads aren't rejected.

🤖 Generated with Claude Code

Replaces CodeQL default setup with a committed workflow so analysis
runs on PR head commits (clearing the diff-informed "configurations
not found" warning) and the analysis config is version-controlled.

Both actions and rust use build-mode none (no compile required).
Categories match the previous default-setup categories for history
continuity.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@InboundFrog
InboundFrog merged commit aac9a04 into main Jul 1, 2026
5 checks passed
@InboundFrog
InboundFrog deleted the claude/ecstatic-lalande-471879 branch July 1, 2026 05:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant