Automatically download latest version of CodeQL#66
Merged
kevinbackhouse merged 1 commit intoNov 10, 2025
Conversation
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR updates the CodeQL CLI installation in the Docker image to automatically use the latest version instead of a pinned version (2.23.0).
- Removes the
CODEQL_VERSIONenvironment variable that pinned the version to 2.23.0 - Changes the download URL to use
/releases/latest/download/instead of a specific version tag
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| # Install CodeQL CLI | ||
| ENV CODEQL_VERSION=2.23.0 | ||
| RUN curl -Ls -o /tmp/codeql.zip https://github.com/github/codeql-cli-binaries/releases/download/v$CODEQL_VERSION/codeql-linux64.zip \\ | ||
| RUN curl -Ls -o /tmp/codeql.zip https://github.com/github/codeql-cli-binaries/releases/latest/download/codeql-linux64.zip \\ |
There was a problem hiding this comment.
Using /releases/latest/download/ instead of a pinned version can lead to reproducibility and stability issues. Docker images built at different times may use different CodeQL CLI versions, potentially causing:
- Inconsistent behavior across deployments
- Unexpected breaking changes
- Difficulty troubleshooting issues
Consider either:
- Keeping a pinned version (e.g.,
v2.23.0) for reproducible builds - Adding a mechanism to explicitly update the version through configuration rather than automatically pulling the latest
- Documenting why automatic updates are preferred over version pinning
p-
approved these changes
Nov 10, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
It's going to be a nuisance if we have to keep updating the CodeQL version number in this file.