ci(codeql): analyse Rust and Python, not only the workflow files - #156
Conversation
CodeQL Advanced scanned a single language, `actions`. The 69k lines of Rust and 9k lines of Python have never had a security analysis: every analysis on develop is `/language:actions` with 0 results. - Add `python` and `rust` rows to the language matrix, both `build-mode: none` (the only mode Rust supports; rustup and cargo are preinstalled on ubuntu-latest). - Run the `security-extended` suite for those two through a per-row `matrix.queries`; the `actions` row sets none, so the input is empty and that analysis is unchanged. - Add `workflow_dispatch`, so a baseline scan can be started by hand. Checked with actionlint 1.7.12 (0 errors; a misspelt `matrix.querys` is rejected, so it does type-check the matrix). No CodeQL analysis of Rust or Python has run yet: the first is this change's pull request. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01C53cGKw2kFHBrY6cy4tRnP
|
Warning Review limit reachedNext included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Result of the first Rust and Python analyses (the checks the description asked for):
🤖 Generated with Claude Code |
|



Why
CodeQL Advancedanalyses one language:actions. Every analysis ondevelopis/language:actionswith 0 results, and code scanning shows 0 open alerts (21 fixed, 20 of themactions/missing-workflow-permissions). The library itself, about 69k lines of Rust and 9k of Python, has never had a security analysis. GitHub lists the repository's analysable languages asactions,python,rust.What
pythonandrustrows in the language matrix, bothbuild-mode: none. That is the only mode Rust supports; the extractor needsrustupandcargo, whichubuntu-latesthas, so there is no toolchain step.security-extendedsuite for those two rows, passed through a per-rowmatrix.queries. For Rust it adds 2 queries to the 16 defaults (use of a pointer after its lifetime ended, log injection); for Python 7 to 48 (tarfile extraction, partial SSRF, requests without certificate validation, unsafe shell commands and others). These fit what the repo has: a fewunsafeblocks, credential handling, HTTP downloads, subprocess calls.actionsrow sets noqueries, so the input is an empty string and that analysis is exactly as before (getOptionalInputin codeql-action treats empty as unset).workflow_dispatch, so that a baseline scan can be started by hand instead of waiting for a merge or the Monday cron.ci.ymlalready has it.Not enabled, on purpose:
security-and-quality(for Python it would duplicate the GitHub-managed Code Quality analysis; for Rust it adds only unused-variable and ctor queries that clippy with-D warningsalready covers), andsecurity-extendedforactions(it would flag every tag-pinned third-party action in all six workflows; a real supply-chain point, but a different change).What to expect from the first run
No CodeQL analysis of Rust or Python has run yet; this PR is the first.
Cargo.lock, includingort,pyo3,eframe/wgpu), so expect minutes, where the whole workflow takes about 40 s today.ci.ymlinstalls forthresh-viz, or narrowing features withCODEQL_EXTRACTOR_RUST_OPTION_CARGO_FEATURES. Neither is added speculatively.develophas no Rust or Python baseline, so this PR may report findings in code it does not touch, and theCodeQLcheck goes red on any high-severity one. Those are what the change is for: triage them in follow-ups; do not addpaths-ignore.Checks
matrix.querysis rejected, so the matrix key is really type-checked.queriesinput and the new trigger, the parsed workflow is identical todevelop: permissions, runner, action versions and category untouched.Found on the way, not changed here
.github/dependabot.ymlstill has the template placeholderpackage-ecosystem: "", so version updates are configured for nothing (security updates still arrive). Setting real ecosystems will open a batch of PRs, so that is your call.actions/checkout@v4; current is v7.proxmox_mcp.logis tracked at the root of this public repository. It holds a private LAN address and no credentials; it probably wants removing and ignoring.OpenSpec Validateis expected to be red until #155 merges.🤖 Generated with Claude Code
https://claude.ai/code/session_01C53cGKw2kFHBrY6cy4tRnP