ci: wire Gemini code review + CodeQL security scanning#4
Merged
Conversation
Gemini Code Assist is the workhorse code reviewer; CodeQL runs the security-extended query suite only (no quality queries) so the two are non-overlapping. Both run on PRs and pushes to main so review is a standing pre-merge gate on the umbrella's generator scripts (aggregate-changelog.mjs, ecosystem-drift.py). - .gemini/config.yaml + .gemini/styleguide.md workhorse code-review gate - .github/workflows/codeql.yml CodeQL security-extended, build-mode none
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wires the standing two-reviewer gate on the IEP umbrella (the 7th IEP repo).
Gemini Code Assist — workhorse code reviewer; auto-reviews every PR once the app is installed on the
intent-solutions-ioorg (separate install from the personal account)..gemini/styleguide.mdcarries the same IEP review priorities as the six code repos.CodeQL — security scanning only (
security-extended, no quality queries) over the generator scripts (aggregate-changelog.mjs,ecosystem-drift.py).build-mode: none, PR + push + weekly. Free on this public repo.Docs/CI-only. Completes Gemini+CodeQL coverage across all 7 IEP repos.