Conversation
The job declared no `permissions`, so it ran with whatever the repository default grants. That default is configurable outside this file, and a restricted one withholds `security-events: write`, which the analysis needs to upload its results. Declare the two scopes the job uses. Every other scope is dropped, which is the intent: the job checks out the sources and analyzes them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The workflow ran `codeql-action/autobuild` between `init` and `analyze`. Both analyzed languages are interpreted, so that step had nothing to build and the surrounding comments described a compiled-language setup this repository does not have. Set `build-mode: none` on `init`, which states the same thing directly, and drop the step along with the commented-out manual build it pointed at. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The matrix uploads one set of results per language, and without a category they were told apart only by the job they came from. Code scanning uses the category to match an upload against the analysis it replaces. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Every other workflow pins `ubuntu-26.04` so that CI matches the VMs, which makes this one look like an oversight. It is not: the analysis neither builds nor runs the sources, so the runner image has no bearing on the findings. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The list of supported languages predated `actions`, `ruby`, `rust` and `swift`, and the documentation link still carried the retired `free-pro-team@latest` prefix, reaching the current page only through a redirect. Note also that `javascript` covers TypeScript, which is not obvious from the matrix. Name the job after the language it analyzes, so the two matrix legs are told apart in the checks list. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The Node steps have cached their store all along, while every run reinstalled the pinned packages from `requirements_frozen.txt` from scratch. Enable pip caching on `setup-python` and key it on the frozen requirements file. Naming the file matters: the default pattern matches `requirements.txt`, which is not what these workflows install, so the key would not change when a pinned version does and a stale cache would be served. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Each workflow ran `python -m pip install --upgrade pip` before installing its requirements, leaving the one tool that resolves the pinned packages as the only unpinned part of the environment. Use `setup-python`'s `pip-version` instead, which the action applies as an exact `pip==` requirement, and drop the upgrade step. Bumping it is a manual edit; Dependabot does not track this input. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two changes to how the four Python workflows set up their environment.
Stacked on the "update the GitHub actions" branch, which this needs for
setup-python@v7; review that one first.Cache the Python dependencies
The Node steps have cached their store all along, while the pinned
packages from
requirements_frozen.txtwere reinstalled from scratch onevery run.
cache: 'pip'is enabled on the foursetup-pythonstepsthat install them.
The dependency path is named explicitly, and that part is load-bearing:
the default pattern is
**/requirements.txt, which matches a file thisrepository has but does not install. Left implicit, the cache key would
never change when a pinned version in
requirements_frozen.txtdoes, anda stale cache would be served after every dependency update.
The type-check workflow is not cached. It installs an unpinned
pyrightplus a local editable package, with no pinned manifest to key on.
Pin pip
Each of those workflows ran
python -m pip install --upgrade pipbeforeinstalling its requirements, leaving the tool that resolves the pinned
packages as the only unpinned part of the environment.
setup-python'spip-versioninput replaces it and the step is dropped.Note this is an exact pin: the action applies the value as
pip==<value>,not as a range, and nothing updates it automatically -- Dependabot tracks
uses:lines, not input values.Scope and impact
sphinx-books-tests.js.yml,sphinx-content-tests.js.yml,sphinx-plugin-tests.js.yml,typescript-tests.js.yml. No otherworkflow, and no content or frontend file, is touched.
Validation
All workflows parse. Each cached step was checked to name a dependency
path that exists relative to the repository root, and to run after the
checkout that creates it. The
pip-versionvalue matches the format theaction validates, and no manual pip upgrade remains in any workflow.
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com