feat(security): add CodeQL analysis and pre-release version gate #200
self-pr-validation.yml
on: pull_request
Detect Changed Files
7s
validation
/
Blocking Checks
10s
YAML Lint
6s
Action Lint
13s
Pinned Actions Check
6s
Markdown Link Check
15s
Spelling Check
7s
Shell Check
5s
README Check
5s
Composite Schema Lint
6s
CodeQL Analysis
38s
Lint Report
9s
validation
/
...
/
Send Notification
9s
Annotations
8 warnings and 1 notice
|
Pinned Actions Check
Found 5 internal action(s) not pinned to a version. Consider pinning to vX.Y.Z.
|
|
Pinned Actions Check:
.github/workflows/pr-security-scan.yml#L283
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-reporter@feat/pr-security-scan-codeql-prerelease
|
|
Pinned Actions Check:
.github/workflows/pr-security-scan.yml#L276
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-analyze@feat/pr-security-scan-codeql-prerelease
|
|
Pinned Actions Check:
.github/workflows/pr-security-scan.yml#L265
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-init@feat/pr-security-scan-codeql-prerelease
|
|
Pinned Actions Check:
.github/workflows/pr-security-scan.yml#L258
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-config@feat/pr-security-scan-codeql-prerelease
|
|
Pinned Actions Check:
.github/workflows/pr-security-scan.yml#L213
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/prerelease-check@feat/pr-security-scan-codeql-prerelease
|
|
CodeQL Analysis
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.
To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
|
|
CodeQL Analysis
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
|
|
validation / Advisory Checks
PR size: M (367 lines changed)
|