ci: add CodeQL static analysis workflow#1022
ci: add CodeQL static analysis workflow#1022mergify[bot] merged 1 commit intopython-wheel-build:mainfrom
Conversation
Add CodeQL SAST for Python to run on pushes to main, PRs, and weekly. Results are uploaded to GitHub's Security tab as code scanning alerts. See also python-wheel-build#1008 Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Martin Prpič <mprpic@redhat.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis pull request introduces a new GitHub Actions workflow file ( Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes 🚥 Pre-merge checks | ✅ 2✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
@mergify rebase |
|
@Mergifyio queue |
|
@Mergifyio refresh |
☑️ Nothing to do, the required conditions are not metDetails
|
|
✅ Pull request refreshed |
Pull Request Description
What
Add CodeQL SAST for Python to run on pushes to main, PRs, and weekly. Results are uploaded to GitHub's Security tab as code scanning alerts.
See also #1008
Why
https://github.blog/security/supply-chain-security/securing-the-open-source-supply-chain-across-github/#h-what-you-can-do-today