Skip to content

ci(codeql): analyse Rust and Python, not only the workflow files - #156

Merged
montge merged 2 commits into
developfrom
feature/codeql-rust-python
Sep 20, 2026
Merged

montge merged 2 commits into
developfrom
feature/codeql-rust-python

Conversation

@montge

@montge montge commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Why

CodeQL Advanced analyses one language: actions. Every analysis on develop is /language:actions with 0 results, and code scanning shows 0 open alerts (21 fixed, 20 of them actions/missing-workflow-permissions). The library itself, about 69k lines of Rust and 9k of Python, has never had a security analysis. GitHub lists the repository's analysable languages as actions, python, rust.

What

  • python and rust rows in the language matrix, both build-mode: none. That is the only mode Rust supports; the extractor needs rustup and cargo, which ubuntu-latest has, so there is no toolchain step.
  • The security-extended suite for those two rows, passed through a per-row matrix.queries. For Rust it adds 2 queries to the 16 defaults (use of a pointer after its lifetime ended, log injection); for Python 7 to 48 (tarfile extraction, partial SSRF, requests without certificate validation, unsafe shell commands and others). These fit what the repo has: a few unsafe blocks, credential handling, HTTP downloads, subprocess calls.
  • The actions row sets no queries, so the input is an empty string and that analysis is exactly as before (getOptionalInput in codeql-action treats empty as unset).
  • workflow_dispatch, so that a baseline scan can be started by hand instead of waiting for a merge or the Monday cron. ci.yml already has it.

Not enabled, on purpose: security-and-quality (for Python it would duplicate the GitHub-managed Code Quality analysis; for Rust it adds only unused-variable and ctor queries that clippy with -D warnings already covers), and security-extended for actions (it would flag every tag-pinned third-party action in all six workflows; a real supply-chain point, but a different change).

What to expect from the first run

No CodeQL analysis of Rust or Python has run yet; this PR is the first.

  • Three jobs instead of one. The Rust extractor loads the workspace with all features on and runs the dependencies' build scripts through rust-analyzer (608 packages in Cargo.lock, including ort, pyo3, eframe/wgpu), so expect minutes, where the whole workflow takes about 40 s today.
  • If the workspace fails to load, the extractor falls back to extracting files without type information and the job still goes green. So read the Rust job log and Security > Code scanning > Tool status after the first run: a green job with degraded extraction is the failure to look for. If it is degraded, the likely fixes are the GUI system libraries that ci.yml installs for thresh-viz, or narrowing features with CODEQL_EXTRACTOR_RUST_OPTION_CARGO_FEATURES. Neither is added speculatively.
  • develop has no Rust or Python baseline, so this PR may report findings in code it does not touch, and the CodeQL check goes red on any high-severity one. Those are what the change is for: triage them in follow-ups; do not add paths-ignore.

Checks

  • actionlint 1.7.12: 0 errors. Negative control: a misspelt matrix.querys is rejected, so the matrix key is really type-checked.
  • Apart from the two matrix rows, the queries input and the new trigger, the parsed workflow is identical to develop: permissions, runner, action versions and category untouched.

Found on the way, not changed here

  • .github/dependabot.yml still has the template placeholder package-ecosystem: "", so version updates are configured for nothing (security updates still arrive). Setting real ecosystems will open a batch of PRs, so that is your call.
  • All six workflows use actions/checkout@v4; current is v7.
  • proxmox_mcp.log is tracked at the root of this public repository. It holds a private LAN address and no credentials; it probably wants removing and ignoring.

OpenSpec Validate is expected to be red until #155 merges.

🤖 Generated with Claude Code

https://claude.ai/code/session_01C53cGKw2kFHBrY6cy4tRnP

CodeQL Advanced scanned a single language, `actions`. The 69k lines of Rust and
9k lines of Python have never had a security analysis: every analysis on
develop is `/language:actions` with 0 results.

- Add `python` and `rust` rows to the language matrix, both `build-mode: none`
  (the only mode Rust supports; rustup and cargo are preinstalled on
  ubuntu-latest).
- Run the `security-extended` suite for those two through a per-row
  `matrix.queries`; the `actions` row sets none, so the input is empty and that
  analysis is unchanged.
- Add `workflow_dispatch`, so a baseline scan can be started by hand.

Checked with actionlint 1.7.12 (0 errors; a misspelt `matrix.querys` is
rejected, so it does type-check the matrix). No CodeQL analysis of Rust or
Python has run yet: the first is this change's pull request.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C53cGKw2kFHBrY6cy4tRnP
Copilot AI lite review requested due to automatic review settings September 19, 2026 14:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: fab61fac-d155-4099-8a47-00535f69342b

📥 Commits

Reviewing files that changed from the base of the PR and between eb91f22 and 5f5d026.

📒 Files selected for processing (1)
  • .github/workflows/codeql.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@codecov

codecov Bot commented Sep 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@montge

montge commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Result of the first Rust and Python analyses (the checks the description asked for):

Category Rules run Findings
/language:rust 28 0
/language:python 50 0
/language:actions 17 0
  • Rust extraction was healthy, not degraded. 186 of 187 Rust files extracted without error, 1 with errors. The job log has no "unable to load manifest" warning and no fallback to extraction without semantics, so the workspace loaded with all features and the types and macros were available to the queries.
  • Rust job time: 5 m 19 s (Python 56 s, Actions 39 s). No system libraries or feature narrowing were needed.
  • Nothing to triage: the security-extended suites found no issue in the Rust or the Python code.

🤖 Generated with Claude Code

@sonarqubecloud

Copy link
Copy Markdown

@montge
montge merged commit 18f196a into develop Sep 20, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants