ci(codeql): switch to advanced workflow + drop default setup#159
Conversation
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Warning Rate limit exceeded
To continue reviewing without waiting, purchase usage credits in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
This PR adds a well-structured CodeQL advanced workflow that properly addresses the Enterprise PRs ruleset requirements. The workflow is correctly configured with:
- Appropriate triggers (push to all branches except noisy ones, PRs to main, weekly schedule, manual dispatch)
- Proper concurrency control to prevent queue congestion
- Correctly scoped permissions (actions: read, contents: read, security-events: write)
- Secure use of pinned official GitHub actions (@V3, @v4)
- Appropriate language matrix (javascript-typescript, actions) with correct build-mode settings
- Security-and-quality query suite maintaining coverage parity with default setup
No blocking issues identified. The implementation correctly solves the chicken-and-egg problem where default-setup CodeQL never runs on feature branches, preventing pushes when the code_scanning rule is active.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
Disables default-setup CodeQL (which only runs on push to default branch and weekly) and replaces it with a custom workflow that runs on push to all branches.
This unblocks pushes to feature branches when the Enterprise "PRs" ruleset's
code_scanningrule is active — default-setup never runs against feature-branch pushes, so the rule rejects them indefinitely with "Waiting for Code Scanning results".Maintained centrally at github.com/jbdevprimary/gh-fleet-sync. Do not edit the workflow in place — drift detection runs on every fan-out and will flag it.