Skip to content

ci(PRODSEC-343): consolidate CodeQL workflows into single unified scan - #2

Closed
anguprasad07 wants to merge 3 commits into
mainfrom
PRODSEC-343/consolidate-codeql
Closed

ci(PRODSEC-343): consolidate CodeQL workflows into single unified scan#2
anguprasad07 wants to merge 3 commits into
mainfrom
PRODSEC-343/consolidate-codeql

Conversation

@anguprasad07

Copy link
Copy Markdown

Replaces separate codeql-full-scan.yml and codeql-pr-scan.yml with a single unified codeql.yml workflow.

Copilot AI review requested due to automatic review settings May 13, 2026 13:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR intends to consolidate CodeQL scanning by introducing a unified .github/workflows/codeql.yml workflow that covers scheduled, manual, and PR-triggered scans via a reusable workflow.

Findings (ordered by severity)

  • Blocker
    • Duplicate CodeQL executions: the PR adds a unified workflow and also adds/keeps separate PR/full scan workflows, which will cause overlapping scheduled and PR runs. (See: .github/workflows/codeql.yml, .github/workflows/codeql-pr-scan.yml, .github/workflows/codeql-full-scan.yml)
  • Medium
    • Repo convention mismatch: pull_request branch filtering is commented out in codeql.yml, while other workflows in this repo restrict PR triggers to branches: [main]. (See: .github/workflows/codeql.yml:12-14)
    • Supply-chain/reproducibility risk: reusable workflow is referenced via a moving ref @master instead of an immutable tag/SHA. (See: .github/workflows/codeql.yml:26)

Changes:

  • Add unified CodeQL workflow (codeql.yml) combining schedule, workflow_dispatch, and PR scanning with PR-only concurrency cancellation.
  • Add PR-only CodeQL workflow (codeql-pr-scan.yml) using a separate reusable workflow.
  • Add scheduled/dispatch full CodeQL workflow (codeql-full-scan.yml) using a separate reusable workflow.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 5 comments.

File Description
.github/workflows/codeql.yml Introduces unified CodeQL workflow with schedule/dispatch/PR triggers and caching/concurrency controls.
.github/workflows/codeql-pr-scan.yml Adds a separate PR-only CodeQL workflow (overlaps with unified workflow).
.github/workflows/codeql-full-scan.yml Adds a separate scheduled/dispatch CodeQL workflow (overlaps with unified workflow).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1 to +5
name: "CodeQL"

on:
schedule:
- cron: '0 1 * * *' # Daily at 01:00 UTC
default: ''
pull_request:
types: [opened, reopened, ready_for_review, synchronize]
# branches: [master, main]
# Skip draft PRs. Non-PR events are never drafts so this guard is a no-op
# for schedule/workflow_dispatch.
if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}
uses: KeepTruckin/security-scanners/.github/workflows/codeql-scan.yml@master
Comment on lines +1 to +6
name: "CodeQL PR Scan"

on:
pull_request:
types: [opened, reopened, ready_for_review, synchronize]
# branches: [master, main]
Comment on lines +1 to +6
name: "CodeQL Full Scan"

on:
schedule:
- cron: '0 1 * * *' # Daily at 01:00 UTC — adjust as needed
workflow_dispatch:
@anguprasad07
anguprasad07 deleted the PRODSEC-343/consolidate-codeql branch May 14, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants