fix(ci): repoint codeql-action at a SHA that exists - #121
Conversation
github/codeql-action@29b1f65 is pinned here but exists in no repository -- the GitHub API returns 422 for it. CodeQL therefore could not start: the run graph fails to build and the job reports startup_failure, so this repository has had no CodeQL scanning at all. Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3 tag currently resolves to (v3.37.3), verified against the API. Found while auditing the estate: the same non-existent SHA is pinned in over 100 repositories, so CodeQL is dead across nearly all of them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
| @@ -1,18 +1,18 @@ | |||
| ; SPDX-License-Identifier: MPL-2.0 | |||
There was a problem hiding this comment.
💡 Quality: License mismatch: SPDX header MPL-2.0 vs field PMPL-1.0-or-later
The SPDX header on line 1 still declares MPL-2.0, while the package license field was changed to PMPL-1.0-or-later. These now disagree, which confuses license tooling and downstream consumers. Make the SPDX identifier and the license field consistent (and confirm which license actually applies to this repo).
Was this helpful? React with 👍 / 👎
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. CI failed: 3 CI failures due to configuration issues: a CodeQL analysis failure from missing JavaScript/TypeScript source files, an unpinned action reference in workflow validation, and a duplicate CLI flag passed to TruffleHog.OverviewThree distinct configuration and setup issues caused CI jobs to fail across the workflow suite, including a CodeQL language mismatch, an unpinned GitHub action reference violating repository security policy, and a duplicate argument error in the TruffleHog security scanner. FailuresCodeQL Database Finalization Failure (confidence: high)
Unpinned Action in Workflow Validation (confidence: high)
TruffleHog Duplicate Flag Error (confidence: high)
Summary
Code Review 👍 Approved with suggestions 1 resolved / 2 findingsPins the CodeQL action to a valid SHA and updates estate-wide security compliance, but renames the guix.scm package to squisher-corpus and introduces an SPDX license mismatch. 💡 Quality: License mismatch: SPDX header MPL-2.0 vs field PMPL-1.0-or-laterThe SPDX header on line 1 still declares ✅ 1 resolved✅ Bug: guix.scm renamed to wrong project 'squisher-corpus'
🤖 Prompt for agentsTip Comment OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
github/codeql-action@29b1f65c1f735799893313399435a59f54045865is pinned here but exists in no repository — the GitHub API returns 422 for it.CodeQL therefore could not start: the run graph fails to build and the job reports
startup_failure, so this repository has had no CodeQL scanning at all.Repointed at
4187e74d05793876e9989daffde9c3e66b4acd07, which is what thev3tag currently resolves to (v3.37.3), verified against the API.Found while auditing the estate: the same non-existent SHA was pinned in 104 repositories, so CodeQL was dead across nearly all of them.
Summary by Gitar
guix.scmpackage definition forsquisher-corpusand changed licenseactions: readpermissions across workflow filesGOVERNANCE.adocdocumentation fileThis will update automatically on new commits.