Dargon789/forge-std

#### Flow diagram for CodeQL Advanced workflow execution

開放

#4 建立於 2025年10月3日

 (0 則留言) (0 個反應) (1 位負責人)Solidity (0 個分叉)auto 404
documentationduplicateenhancementgood first issuehelp wantedinvalidquestion

倉庫指標

星標
 (1 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Reviewer's Guide

Introduces a new CodeQL Advanced workflow for automated security scanning using GitHub Actions with a multi-language matrix and customizable build modes.

Flow diagram for CodeQL Advanced workflow execution

flowchart TD
  Start(["Trigger: push, pull_request, schedule"]) --> AnalyzeJob["Job: Analyze (per language)"]
  AnalyzeJob --> Checkout["Checkout repository"]
  AnalyzeJob --> InitCodeQL["Initialize CodeQL"]
  AnalyzeJob --> ManualBuild["Manual build (if required)"]
  AnalyzeJob --> PerformAnalysis["Perform CodeQL Analysis"]
  PerformAnalysis --> End(["Security scan results"])

File-Level Changes

Change Details Files
Add CodeQL Advanced GitHub Actions workflow Define triggers for push, pull_request on master and schedule a weekly cron runConfigure multi-language analysis matrix with runner selection and build modesSet up job permissions, checkout, initialization, manual build fallback, and analysis steps .github/workflows/codeql.yml

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an issue from a review comment by replying to it. You can also reply to a review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull request title to generate a title at any time. You can also comment @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in the pull request body to generate a PR summary at any time exactly where you want it. You can also comment @sourcery-ai summary on the pull request to (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the pull request to resolve all Sourcery comments. Useful if you've already addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull request to dismiss all existing Sourcery reviews. Especially useful if you want to start fresh with a new review - don't forget to comment @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Originally posted by @sourcery-ai[bot] in https://github.com/Dargon789/forge-std/issues/3#issuecomment-3367192400

貢獻者指南