Dargon789/forge-std
View on GitHub#### Flow diagram for CodeQL Advanced workflow execution
Open
#4 opened on Oct 3, 2025
documentationduplicateenhancementgood first issuehelp wantedinvalidquestion
Repository metrics
- Stars
- (1 star)
- PR merge metrics
- (PR metrics pending)
Description
Reviewer's Guide
Introduces a new CodeQL Advanced workflow for automated security scanning using GitHub Actions with a multi-language matrix and customizable build modes.
Flow diagram for CodeQL Advanced workflow execution
flowchart TD
Start(["Trigger: push, pull_request, schedule"]) --> AnalyzeJob["Job: Analyze (per language)"]
AnalyzeJob --> Checkout["Checkout repository"]
AnalyzeJob --> InitCodeQL["Initialize CodeQL"]
AnalyzeJob --> ManualBuild["Manual build (if required)"]
AnalyzeJob --> PerformAnalysis["Perform CodeQL Analysis"]
PerformAnalysis --> End(["Security scan results"])
File-Level Changes
| Change | Details | Files |
|---|---|---|
| Add CodeQL Advanced GitHub Actions workflow | Define triggers for push, pull_request on master and schedule a weekly cron runConfigure multi-language analysis matrix with runner selection and build modesSet up job permissions, checkout, initialization, manual build fallback, and analysis steps | .github/workflows/codeql.yml |
Interacting with Sourcery
- Trigger a new review: Comment
@sourcery-ai reviewon the pull request. - Continue discussions: Reply directly to Sourcery's review comments.
- Generate a GitHub issue from a review comment: Ask Sourcery to create an
issue from a review comment by replying to it. You can also reply to a
review comment with
@sourcery-ai issueto create an issue from it. - Generate a pull request title: Write
@sourcery-aianywhere in the pull request title to generate a title at any time. You can also comment@sourcery-ai titleon the pull request to (re-)generate the title at any time. - Generate a pull request summary: Write
@sourcery-ai summaryanywhere in the pull request body to generate a PR summary at any time exactly where you want it. You can also comment@sourcery-ai summaryon the pull request to (re-)generate the summary at any time. - Generate reviewer's guide: Comment
@sourcery-ai guideon the pull request to (re-)generate the reviewer's guide at any time. - Resolve all Sourcery comments: Comment
@sourcery-ai resolveon the pull request to resolve all Sourcery comments. Useful if you've already addressed all the comments and don't want to see them anymore. - Dismiss all Sourcery reviews: Comment
@sourcery-ai dismisson the pull request to dismiss all existing Sourcery reviews. Especially useful if you want to start fresh with a new review - don't forget to comment@sourcery-ai reviewto trigger a new review!
Customizing Your Experience
Access your dashboard to:
- Enable or disable review features such as the Sourcery-generated pull request summary, the reviewer's guide, and others.
- Change the review language.
- Add, remove or edit custom review instructions.
- Adjust other review settings.
Getting Help
- Contact our support team for questions or feedback.
- Visit our documentation for detailed guides and information.
- Keep in touch with the Sourcery team by following us on X/Twitter, LinkedIn or GitHub.
Originally posted by @sourcery-ai[bot] in https://github.com/Dargon789/forge-std/issues/3#issuecomment-3367192400