https://github.blog/changelog/2025-07-21-code-scanning-will-stop-combining-multiple-sarif-runs-uploaded-in-the-same-sarif-file/ broke all scan tools
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 25/100
Hướng nghiên cứu
Bắt đầu với changelog GitHub được liên kết, sau đó so sánh .github/codeql/codeql-config.yml và .github/workflows/codeql-analysis.yml với hành vi của thiết lập mặc định và nâng cao được mô tả trong issue. Tái hiện lỗi CodeQL đã được báo cáo và xung đột giữa cấu hình mặc định và nâng cao; hoàn thành khi xác định được một cấu hình được hỗ trợ hoặc một hồi quy đã được xác nhận với phạm vi sửa lỗi cụ thể.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Have used CodeQL for 2 years (without config files), all commits passed.
But https://github.blog/changelog/2025-07-21-code-scanning-will-stop-combining-multiple-sarif-runs-uploaded-in-the-same-sarif-file/ broke https://github.com/codacy/codacy-analysis-cli/ (https://github.com/codacy/codacy-analysis-cli/issues/541), so Codacy was removed, which caused Exit code was 32 and last log line was: CodeQL detected code written in C/C++, but not any written in GitHub Actions. (guess the reason is that there were no other config files for GitHub Actions in .github/workflows/, but if so this new "error" is a regression, since CodeQL used to allow to use the default setup).
To workaround, used https://github.com/github/codeql/blob/main/.github/codeql/codeql-config.yml + https://github.com/github/codeql/blob/main/.github/workflows/codeql-analysis.yml (just as templates; replaced the directories + languages with those which SusuLib uses), but those config files trigger CodeQL analyses from advanced configurations cannot be processed when the default setup is enabled.
Is the sole solution to have CodeQL removed too? If so, are there other tools to use (which were not broken), or must produce scan tools from scratch now?
- Ngôn ngữ chính
- TypeScript
- Star
- 1.6k
- Fork
- 493
- Merge trung bình
- 1 ngày 13 giờ
- Pull request đã merge (30 ngày)
- 44
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/codeql-action
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/codeql-action#4052 · 4 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
github/codeql-action#4078 · 1 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
github/codeql-action#4008 · 9 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
github/codeql-action#3978 · 4 bình luận · 1 reaction ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100
github/codeql-action#3915 · 6 bình luận · 3 reaction ·
Tất cả issue của github/codeql-action
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
safetrustcr/dApp-SafeTrust#426 ·
-
area:workflow bug ready-for-agent
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
fil-donadoni/tolaria#4409 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Fission-AI/OpenSpec#1960 ·
-
Add dependabot Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
corsairdev/corsair#1764 ·