fix(ci): repoint codeql-action at a SHA that exists - #56
Conversation
github/codeql-action@29b1f65 is pinned here but exists in no repository -- the GitHub API returns 422 for it. CodeQL therefore could not start: the run graph fails to build and the job reports startup_failure, so this repository has had no CodeQL scanning at all. Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3 tag currently resolves to (v3.37.3), verified against the API. Found while auditing the estate: the same non-existent SHA is pinned in over 100 repositories, so CodeQL is dead across nearly all of them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
CI failed: Multiple CI workflow failures across jobs due to missing target files for Deno lint, CodeQL configuration mismatch for non-JavaScript codebases, policy violations for ReScript files, and missing Node.js dependency lock files.OverviewAnalysis of 5 CI logs revealed 4 distinct failure patterns causing build and workflow failures: a Deno lint target path error, a CodeQL analysis failure due to missing JavaScript/TypeScript files, an estate policy violation regarding ReScript files, and a missing Node.js dependency lock file. FailuresDeno Lint No Target Files (confidence: high)
CodeQL Analysis Configuration Error (confidence: high)
Estate Policy Violation: ReScript Files Found (confidence: high)
Missing Node.js Dependency Lock File (confidence: high)
Summary
Code Review ✅ ApprovedUpdates CodeQL action references to point to a valid SHA, adds missing read permissions to GitHub workflows, and cleans up duplicate governance and project configuration files. No issues found.
Tip Comment OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|
|
|




github/codeql-action@29b1f65c1f735799893313399435a59f54045865is pinned here but exists in no repository — the GitHub API returns 422 for it.CodeQL therefore could not start: the run graph fails to build and the job reports
startup_failure, so this repository has had no CodeQL scanning at all.Repointed at
4187e74d05793876e9989daffde9c3e66b4acd07, which is what thev3tag currently resolves to (v3.37.3), verified against the API.Found while auditing the estate: the same non-existent SHA was pinned in 104 repositories, so CodeQL was dead across nearly all of them.
Summary by Gitar
codeql-actionreferences in workflows to a valid SHAactions: readpermission across multiple GitHub workflow configurationsguix.scmmetadata package definition frompreference-injectortosquisher-corpusGOVERNANCE.adocin favor ofGOVERNANCE.mdThis will update automatically on new commits.