Skip to content

ci: add fork-aware CodeQL analysis (#857) - #858

Merged
haofeif merged 3 commits into
mainfrom
fix/857-codeql-fork-pr-ci
Oct 2, 2026
Merged

haofeif merged 3 commits into
mainfrom
fix/857-codeql-fork-pr-ci

Conversation

@haofeif

@haofeif haofeif commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Refs #857. This is the CI-only PR; application parser/path findings are a separate workstream.

Merged on 2026-10-02 at 14:10 UTC as bcd714c1d1679225aae4d65fb063f6212307870e. The post-merge CodeQL baseline also completed successfully.

  • Add an advanced CodeQL workflow for fork and same-repository PRs, pushes to main, weekly scans, and manual dispatch.
  • Preserve Python, JavaScript/TypeScript, GitHub Actions, and Rust coverage using SHA-pinned actions, no project build/dependency installation, and no retained checkout credentials.
  • Correct the default-setup coverage comments and document the administrator cutover, required scan/status rules, acceptance checks, and rollback in SECURITY.md. Update the contributor skill's workflow map and generated package mirror.
  • Add workflow-contract regressions, maintainer ownership for CI definitions, and the missing CHANGELOG.md entry. Existing Trivy, dependency-review, and secret-scanning jobs are unchanged.

Review follow-ups

Commit ac0631a911e31da806bf4b436806e166eb8b2cb7 addresses both reported P3 findings:

  • .github/CODEOWNERS assigns all .github/workflows/ definitions and the ownership file itself to the existing @awslabs/multiq repository-maintainer team. Directory-wide ownership also covers adding a different workflow that emits the same required check names.
  • The active protect-main ruleset (8799753) now requires code-owner review and dismisses stale approvals after changes to the reviewed diff. These are actual hosted settings, not just instructions in a document. All other rule parameters, CodeQL gates, and existing bypasses were preserved.
  • CHANGELOG.md records the advanced CodeQL workflow and ownership/review requirements under Unreleased.
  • The stale draft wording was corrected before merge to match the PR's ready-for-review state.

GitHub's native CODEOWNERS validation reports zero errors; the team is visible and has explicit repository admin permission. GitHub reads ownership from the base branch, so the new file could not enforce its own initial introduction. Review was explicitly requested from @awslabs/multiq for this PR. The ownership file is now on main, and required code-owner review plus stale-approval dismissal were reverified after merge. The bootstrap and approval-invalidation acceptance checks are documented in SECURITY.md.

Validation

For the follow-up commit:

  • Focused CodeQL, workflow-pin, and contributor-accuracy contracts: 109 passed, 7 skipped. Both new ownership cases failed before CODEOWNERS was added and passed afterward.
  • Black and isort checks passed for the changed test file.
  • The repository Markdown-link validator passed.
  • GitHub accepted the CODEOWNERS syntax and owner team, and the effective main rules confirm required code-owner review plus stale-approval dismissal.

All 25 reported checks passed at ac0631a911e31da806bf4b436806e166eb8b2cb7, including the fresh CI and all four CodeQL jobs.

The four processed CodeQL analyses (1881159716, 1881161947, 1881171012, and 1881177244) all match this run's PR merge revision ac46c961f4747862a05cadaf53cf615756127c63, ref refs/pull/858/merge, and analysis key .github/workflows/codeql.yml:analyze. Each reports zero results and empty error/warning fields. These are fresh results, not the previous head's scans.

The Copilot review at this head reports nil findings.

Hosted CodeQL cutover

The earlier default/advanced conflict was resolved by actually disabling hosted default setup and verifying state: not-configured. The four advanced jobs at the previous head, 65ce6776c353f66d755afc2ce4e1713a0ffaed36, then completed successfully on 2026-10-02 at 11:57 UTC, with all four analyses processed at that run's PR merge revision. No helper script or helper PR was needed.

The existing active protect-main ruleset also requires:

  • CodeQL scanning results, with security alerts High or higher and general alerts Errors.
  • All four CodeQL (actions), CodeQL (javascript-typescript), CodeQL (python), and CodeQL (rust) status contexts, restricted to GitHub Actions (integration 15368), with the branch required to be up to date.

Existing bypasses remain DeployKey / always and RepositoryRole 5 (administrator) / pull_request; no bypass was added, and the assistant did not use one. Other rulesets were not modified.

Post-merge baseline

All four jobs in the advanced CodeQL push run passed at merge commit bcd714c1d1679225aae4d65fb063f6212307870e. Processed analyses 1881320870, 1881325035, 1881327565, and 1881337816 all match that commit and refs/heads/main, with no analysis errors or warnings.

The Python default-branch analysis reports 11 results; the other three languages report zero. The five open CodeQL alerts associated with this commit (253, 254, 289, 301, 303) all predate this merge. These remain separate triage work: successful scanning does not mean all baseline alerts are resolved.

Remaining migration acceptance

The merge, default-branch baseline, and ownership/review configuration are complete. Keep other main merges paused until the remaining controlled acceptance checks are complete, including through the existing bypasses.

Still verify owner-review enforcement and dismissal after a new push, a disposable fork PR, a harmless controlled finding above the threshold, missing/pending/failed analysis, and rejection of stale scan results. Keep #857 open until those operational acceptance checks are complete. The rollback procedure remains in SECURITY.md.

No provider code, regexes, filesystem handling, or alert dismissals are part of this PR. Hosted settings were applied separately as administrator operations; the PR was merged by the maintainer, not by the assistant.

haofeif and others added 2 commits October 2, 2026 17:53
Add the advanced CodeQL workflow for the existing language coverage and document the required administrator cutover and merge protection. Keep application security fixes separate. Refs #857.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the canonical contributor skill and generated mirror aligned with the new PR workflow. Refs #857.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@haofeif
haofeif force-pushed the fix/857-codeql-fork-pr-ci branch from 4fd011f to 65ce677 Compare October 2, 2026 07:55
@haofeif
haofeif marked this pull request as ready for review October 2, 2026 12:17
Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Final confidence depends on post-merge fork, baseline, and branch-protection acceptance checks that cannot be established through static review.

Review effort: Balanced
Findings: None

What changed in this PR

Adds fork-aware advanced CodeQL scanning and documents the administrator-managed migration and enforcement process.

Changes:

  • Scans four languages across PR, push, scheduled, and manual events.
  • Adds workflow security and regression contracts.
  • Updates security guidance and contributor workflow maps.
File Description
.github/​workflows/​codeql.yml Defines the advanced CodeQL matrix.
.github/​workflows/​ci.yml Replaces obsolete CodeQL commentary.
SECURITY.md Documents migration, enforcement, validation, and rollback.
test/​test_codeql_workflow.py Tests workflow coverage and least privilege.
skills/​cao-contributing/​SKILL.md Adds CodeQL to the workflow map.
src/​cli_agent_orchestrator/​skills/​cao-contributing/​SKILL.md Updates the packaged skill mirror.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Protect workflow definitions and CODEOWNERS, document fresh owner approval and bootstrap review, and record the CodeQL migration in the changelog.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 13:42
@haofeif
haofeif requested a review from a team October 2, 2026 13:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Final readiness depends on administrator-managed protections and post-merge fork and merge-gate acceptance checks.

Review effort: Balanced
Findings: None

@haofeif
haofeif merged commit bcd714c into main Oct 2, 2026
26 checks passed
@haofeif
haofeif deleted the fix/857-codeql-fork-pr-ci branch October 2, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants