Problem
CodeQL runs as default setup (actions, javascript-typescript, weekly), which analyzes only the default branch (main) and PRs into it. Every analysis on record is refs/heads/main or one of the four milestone-merge PRs (#2304, #2381, #2456, #2536). No v2/main work is scanned until the release PR.
That is how the v2.9.0 ReDoS (#2540) surfaced: CodeQL flagged a regression from this milestone's #2423 work only on the milestone-merge PR, and the release was held while it was fixed. The finding should have landed on the PR that introduced it.
Change
Switch to advanced setup: a committed .github/workflows/codeql.yml with
push to main and v2/main
pull_request against main and v2/main
- the existing weekly
schedule
- the same languages (
actions, javascript-typescript) and the default query suite
Disable default setup in the same change, or the two will double-report.
The workflow's analyze job holds security-events: write, which makes it a credentialed job, so every action it uses must be SHA-pinned (verify:action-pins, #2484) and it gets a timeout-minutes sized from observed runs (AGENTS.md).
This needs no new credential and does not depend on the GitHub App.
Acceptance
Part of tracker #2543. Needs no credential; can start now.
Problem
CodeQL runs as default setup (
actions,javascript-typescript, weekly), which analyzes only the default branch (main) and PRs into it. Every analysis on record isrefs/heads/mainor one of the four milestone-merge PRs (#2304, #2381, #2456, #2536). Nov2/mainwork is scanned until the release PR.That is how the v2.9.0 ReDoS (#2540) surfaced: CodeQL flagged a regression from this milestone's #2423 work only on the milestone-merge PR, and the release was held while it was fixed. The finding should have landed on the PR that introduced it.
Change
Switch to advanced setup: a committed
.github/workflows/codeql.ymlwithpushtomainandv2/mainpull_requestagainstmainandv2/mainscheduleactions,javascript-typescript) and the default query suiteDisable default setup in the same change, or the two will double-report.
The workflow's analyze job holds
security-events: write, which makes it a credentialed job, so every action it uses must be SHA-pinned (verify:action-pins, #2484) and it gets atimeout-minutessized from observed runs (AGENTS.md).This needs no new credential and does not depend on the GitHub App.
Acceptance
refs/heads/v2/main, and for a PR targetingv2/mainverify:action-pinspasses, and the job declarestimeout-minutesPart of tracker #2543. Needs no credential; can start now.