Skip to content

fix(ci): repoint codeql-action at a SHA that exists - #59

Merged
hyperpolymath merged 6 commits into
mainfrom
fix/codeql-action-sha
Jul 28, 2026
Merged

fix(ci): repoint codeql-action at a SHA that exists#59
hyperpolymath merged 6 commits into
mainfrom
fix/codeql-action-sha

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Jul 28, 2026

Copy link
Copy Markdown
Owner

github/codeql-action@29b1f65c1f735799893313399435a59f54045865 is pinned here but exists in no repository — the GitHub API returns 422 for it.

CodeQL therefore could not start: the run graph fails to build and the job reports startup_failure, so this repository has had no CodeQL scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3 tag currently resolves to (v3.37.3), verified against the API.

Found while auditing the estate: the same non-existent SHA was pinned in 104 repositories, so CodeQL was dead across nearly all of them.


Summary by Gitar

  • CI enhancements:
    • Added actions: read permission across workflow files
    • Updated guix.scm package definition for squisher-corpus

This will update automatically on new commits.

hyperpolymath and others added 5 commits July 26, 2026 14:48
github/codeql-action@29b1f65 is pinned here but exists in no
repository -- the GitHub API returns 422 for it. CodeQL therefore could
not start: the run graph fails to build and the job reports
startup_failure, so this repository has had no CodeQL scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3
tag currently resolves to (v3.37.3), verified against the API.

Found while auditing the estate: the same non-existent SHA is pinned in
over 100 repositories, so CodeQL is dead across nearly all of them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown
CI failed: 4 CI check failures due to missing repository compliance files (STATE.a2ml), incorrect CodeQL language setup, and validation errors in K9 contracts and A2ML manifests.

Overview

Multiple CI workflow checks failed across different jobs due to missing configuration files, incorrect tool setup, and format validation errors in metadata and contract files.

Failures

Missing Machine Readable State File (confidence: high)

  • Type: configuration
  • Affected jobs: 90324181327
  • Related to change: yes
  • Root cause: The compliance check expects a .machine_readable/STATE.a2ml file to be present in the repository, but it does not exist.
  • Suggested fix: Create the required .machine_readable/STATE.a2ml file in the repository root and commit it.

CodeQL Configuration Error (confidence: high)

  • Type: configuration
  • Affected jobs: 90324181759
  • Related to change: yes
  • Root cause: The CodeQL workflow is configured to analyze JavaScript/TypeScript (languages: javascript-typescript), but the repository contains no valid source files for this language.
  • Suggested fix: Update the CodeQL workflow configuration in .github/workflows/codeql.yml to match the actual languages present in the repository, or add valid JS/TS source files.

K9 Validation Failures (confidence: high)

  • Type: build
  • Affected jobs: 90324180535
  • Related to change: yes
  • Root cause: The K9 validation script (.githooks/validate-k9.sh) failed with 6 errors due to missing magic numbers (K9!), missing pedigree blocks, and missing metadata fields.
  • Suggested fix: Fix all flagged K9 contract files by ensuring they start with the 'K9!' magic number and contain a valid pedigree block with required 'name' and version fields.

A2ML Manifest Validation Failure (confidence: high)

  • Type: build
  • Affected jobs: 90324180515
  • Related to change: yes
  • Root cause: The manifest file .github/0.1-AI-MANIFEST.a2ml is missing required identity fields (agent-id, name, or project).
  • Suggested fix: Add the required identity fields and an SPDX-License-Identifier to .github/0.1-AI-MANIFEST.a2ml within the first 10 lines.

Summary

  • Change-related failures: 4 failures involving repository compliance checks, CodeQL language configuration, K9 contract validation, and A2ML manifest validation.
  • Infrastructure/flaky failures: 0 failures.
  • Recommended action: Create the missing .machine_readable/STATE.a2ml file, correct the CodeQL language target in the workflow file, and fix the validation errors in the K9 contracts and A2ML manifests.
Code Review ✅ Approved

Repoints the CodeQL action at a valid SHA to resolve pipeline startup failures and adds read permissions across workflow files. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Tip

Comment Gitar fix CI or enable auto-apply: gitar auto-apply:on

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Jul 28, 2026
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit c388bc2 into main Jul 28, 2026
19 of 24 checks passed
@hyperpolymath
hyperpolymath deleted the fix/codeql-action-sha branch July 28, 2026 17:15
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant