Skip to content

Commit 4f489a0

Browse files
hyperpolymathclaude
andcommitted
ci(codeql): converge to canonical language-autodetect workflow (Refs #8)
k9iser's codeql.yml was a stale hardcoded `javascript-typescript`-only matrix (left as a local security workflow by the b618a53 bundle migration). On this Rust-only repo CodeQL exits with a permanent false-red 'no source / configuration error' on the analyze job. Replace it verbatim with the canonical estate template shipped by rsr-template-repo / v3-templater / reposystem: a detect job reads the repo's actual language stats and only analyses CodeQL-supported, buildless-safe languages (here: rust), skipping entirely when none apply. Also brings the estate concurrency guardrail (cancel superseded runs). This is resolve-at-source + convergence to the central canonical template rather than a k9iser-local divergence. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 062fd75 commit 4f489a0

1 file changed

Lines changed: 39 additions & 4 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 39 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,22 +8,57 @@ on:
88
branches: [main, master]
99
schedule:
1010
- cron: '0 6 * * 1'
11+
# Estate guardrail: cancel superseded runs so re-pushes don't pile up
12+
# queued runs across the estate. Safe here because this workflow only
13+
# performs read-only checks/lint/test/scan with no publish or mutation.
14+
concurrency:
15+
group: ${{ github.workflow }}-${{ github.ref }}
16+
cancel-in-progress: true
1117

1218
permissions:
1319
contents: read
1420

1521
jobs:
22+
# The estate is heterogeneous (Rust, Idris2, Agda, Elixir, ReScript,
23+
# occasional JS/TS/Python). A hard-coded `javascript-typescript` matrix
24+
# made CodeQL exit with a "no source / configuration error" on every
25+
# non-JS/TS repo — a permanent false-red `analyze` on most repos' main.
26+
# Detect the languages the repo ACTUALLY contains and only analyse the
27+
# CodeQL-supported, buildless-safe ones; skip entirely when none apply.
28+
detect:
29+
runs-on: ubuntu-latest
30+
outputs:
31+
langs: ${{ steps.pick.outputs.langs }}
32+
steps:
33+
- name: Pick CodeQL languages from repo language stats
34+
id: pick
35+
env:
36+
GH_TOKEN: ${{ github.token }}
37+
run: |
38+
stats=$(gh api "repos/${{ github.repository }}/languages" --jq 'keys[]' 2>/dev/null || echo "")
39+
out=""
40+
add() { out="$out $1"; }
41+
echo "$stats" | grep -qix 'Rust' && add rust
42+
echo "$stats" | grep -qixE 'JavaScript|TypeScript' && add javascript-typescript
43+
echo "$stats" | grep -qix 'Python' && add python
44+
echo "$stats" | grep -qix 'Ruby' && add ruby
45+
echo "$stats" | grep -qix 'Go' && add go
46+
arr=$(printf '%s\n' $out | grep . | sort -u | jq -R . | jq -s -c .)
47+
[ -z "$arr" ] && arr='[]'
48+
echo "Detected CodeQL languages: $arr"
49+
echo "langs=$arr" >> "$GITHUB_OUTPUT"
50+
1651
analyze:
52+
needs: detect
53+
if: needs.detect.outputs.langs != '[]'
1754
runs-on: ubuntu-latest
1855
permissions:
1956
contents: read
2057
security-events: write
2158
strategy:
2259
fail-fast: false
2360
matrix:
24-
include:
25-
- language: javascript-typescript
26-
build-mode: none
61+
language: ${{ fromJSON(needs.detect.outputs.langs) }}
2762

2863
steps:
2964
- name: Checkout
@@ -33,7 +68,7 @@ jobs:
3368
uses: github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1
3469
with:
3570
languages: ${{ matrix.language }}
36-
build-mode: ${{ matrix.build-mode }}
71+
build-mode: none
3772

3873
- name: Perform CodeQL Analysis
3974
uses: github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1

0 commit comments

Comments
 (0)