Repository navigation
ci: add fork-aware CodeQL analysis (#857) - #858
Merged
Merged
Conversation
Add the advanced CodeQL workflow for the existing language coverage and document the required administrator cutover and merge protection. Keep application security fixes separate. Refs #857. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the canonical contributor skill and generated mirror aligned with the new PR workflow. Refs #857. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
haofeif
force-pushed
the
fix/857-codeql-fork-pr-ci
branch
from
October 2, 2026 07:55
4fd011f to
65ce677
Compare
This was referenced Oct 2, 2026
haofeif
marked this pull request as ready for review
October 2, 2026 12:17
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Final confidence depends on post-merge fork, baseline, and branch-protection acceptance checks that cannot be established through static review.
Review effort: Balanced
Findings: None
What changed in this PR
Adds fork-aware advanced CodeQL scanning and documents the administrator-managed migration and enforcement process.
Changes:
- Scans four languages across PR, push, scheduled, and manual events.
- Adds workflow security and regression contracts.
- Updates security guidance and contributor workflow maps.
| File | Description |
|---|---|
.github/workflows/codeql.yml |
Defines the advanced CodeQL matrix. |
.github/workflows/ci.yml |
Replaces obsolete CodeQL commentary. |
SECURITY.md |
Documents migration, enforcement, validation, and rollback. |
test/test_codeql_workflow.py |
Tests workflow coverage and least privilege. |
skills/cao-contributing/SKILL.md |
Adds CodeQL to the workflow map. |
src/cli_agent_orchestrator/skills/cao-contributing/SKILL.md |
Updates the packaged skill mirror. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Protect workflow definitions and CODEOWNERS, document fresh owner approval and bootstrap review, and record the CodeQL migration in the changelog. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Refs #857. This is the CI-only PR; application parser/path findings are a separate workstream.
Merged on 2026-10-02 at 14:10 UTC as
bcd714c1d1679225aae4d65fb063f6212307870e. The post-merge CodeQL baseline also completed successfully.main, weekly scans, and manual dispatch.SECURITY.md. Update the contributor skill's workflow map and generated package mirror.CHANGELOG.mdentry. Existing Trivy, dependency-review, and secret-scanning jobs are unchanged.Review follow-ups
Commit
ac0631a911e31da806bf4b436806e166eb8b2cb7addresses both reported P3 findings:.github/CODEOWNERSassigns all.github/workflows/definitions and the ownership file itself to the existing@awslabs/multiqrepository-maintainer team. Directory-wide ownership also covers adding a different workflow that emits the same required check names.protect-mainruleset (8799753) now requires code-owner review and dismisses stale approvals after changes to the reviewed diff. These are actual hosted settings, not just instructions in a document. All other rule parameters, CodeQL gates, and existing bypasses were preserved.CHANGELOG.mdrecords the advanced CodeQL workflow and ownership/review requirements under Unreleased.GitHub's native CODEOWNERS validation reports zero errors; the team is visible and has explicit repository admin permission. GitHub reads ownership from the base branch, so the new file could not enforce its own initial introduction. Review was explicitly requested from
@awslabs/multiqfor this PR. The ownership file is now onmain, and required code-owner review plus stale-approval dismissal were reverified after merge. The bootstrap and approval-invalidation acceptance checks are documented inSECURITY.md.Validation
For the follow-up commit:
mainrules confirm required code-owner review plus stale-approval dismissal.All 25 reported checks passed at
ac0631a911e31da806bf4b436806e166eb8b2cb7, including the fresh CI and all four CodeQL jobs.The four processed CodeQL analyses (
1881159716,1881161947,1881171012, and1881177244) all match this run's PR merge revisionac46c961f4747862a05cadaf53cf615756127c63, refrefs/pull/858/merge, and analysis key.github/workflows/codeql.yml:analyze. Each reports zero results and empty error/warning fields. These are fresh results, not the previous head's scans.The Copilot review at this head reports nil findings.
Hosted CodeQL cutover
The earlier default/advanced conflict was resolved by actually disabling hosted default setup and verifying
state: not-configured. The four advanced jobs at the previous head,65ce6776c353f66d755afc2ce4e1713a0ffaed36, then completed successfully on 2026-10-02 at 11:57 UTC, with all four analyses processed at that run's PR merge revision. No helper script or helper PR was needed.The existing active
protect-mainruleset also requires:CodeQL (actions),CodeQL (javascript-typescript),CodeQL (python), andCodeQL (rust)status contexts, restricted to GitHub Actions (integration15368), with the branch required to be up to date.Existing bypasses remain
DeployKey/alwaysandRepositoryRole5 (administrator) /pull_request; no bypass was added, and the assistant did not use one. Other rulesets were not modified.Post-merge baseline
All four jobs in the advanced CodeQL push run passed at merge commit
bcd714c1d1679225aae4d65fb063f6212307870e. Processed analyses1881320870,1881325035,1881327565, and1881337816all match that commit andrefs/heads/main, with no analysis errors or warnings.The Python default-branch analysis reports 11 results; the other three languages report zero. The five open CodeQL alerts associated with this commit (
253,254,289,301,303) all predate this merge. These remain separate triage work: successful scanning does not mean all baseline alerts are resolved.Remaining migration acceptance
The merge, default-branch baseline, and ownership/review configuration are complete. Keep other
mainmerges paused until the remaining controlled acceptance checks are complete, including through the existing bypasses.Still verify owner-review enforcement and dismissal after a new push, a disposable fork PR, a harmless controlled finding above the threshold, missing/pending/failed analysis, and rejection of stale scan results. Keep #857 open until those operational acceptance checks are complete. The rollback procedure remains in
SECURITY.md.No provider code, regexes, filesystem handling, or alert dismissals are part of this PR. Hosted settings were applied separately as administrator operations; the PR was merged by the maintainer, not by the assistant.