fix(ci): repoint codeql-action at a SHA that exists - #64
Conversation
github/codeql-action@29b1f65 is pinned here but exists in no repository -- the GitHub API returns 422 for it. CodeQL therefore could not start: the run graph fails to build and the job reports startup_failure, so this repository has had no CodeQL scanning at all. Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3 tag currently resolves to (v3.37.3), verified against the API. Found while auditing the estate: the same non-existent SHA is pinned in over 100 repositories, so CodeQL is dead across nearly all of them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. CI failed: 3 CI failures: a CodeQL analysis failure from missing JavaScript/TypeScript source files, a security policy check failure from potential hardcoded secrets in the codebase, and a Rust compilation error in the fslint-core benchmark due to a missing Clone implementation on PluginLoader.OverviewThree distinct job failures occurred across the CI pipeline: CodeQL analysis failed due to an empty or missing JavaScript/TypeScript codebase under the requested language matrix, a security compliance check failed due to potential hardcoded secrets detected by grep, and a Rust benchmark failed to compile because FailuresCodeQL Language Configuration Error (confidence: high)
Security Policy Check Failure (confidence: high)
Rust Benchmark Compilation Error (confidence: high)
Summary
Code Review ✅ Approved 2 resolved / 2 findingsUpdates CodeQL actions and Guix environment configurations for security compliance, but the guix.scm mislabels the repository and top-level workflow permissions fail to reach the analyze job. ✅ 2 resolved✅ Bug: guix.scm mislabels filesoup repo as squisher-corpus
✅ Bug: actions:read added at top level never reaches analyze job
Tip Comment OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
github/codeql-action@29b1f65c1f735799893313399435a59f54045865is pinned here but exists in no repository — the GitHub API returns 422 for it.CodeQL therefore could not start: the run graph fails to build and the job reports
startup_failure, so this repository has had no CodeQL scanning at all.Repointed at
4187e74d05793876e9989daffde9c3e66b4acd07, which is what thev3tag currently resolves to (v3.37.3), verified against the API.Found while auditing the estate: the same non-existent SHA was pinned in 104 repositories, so CodeQL was dead across nearly all of them.