Problem
Documentation and agent-instruction files inside native package directories currently match broad CI and CodeQL path filters such as packages/apple/** and libraries/<wrapper>/**. GitHub reevaluates the complete pull request diff on every push, so a small follow-up documentation commit can restart native build and Swift CodeQL matrices even when no native source changed.
PR #361 exposed the behavior:
packages/apple/CONTRIBUTING.md selected the Swift core scan.
AGENTS.md, CLAUDE.md, GEMINI.md, and contribution docs under React Native, Expo, Flutter, and Godot selected their Swift wrapper scans.
- Six Swift CodeQL jobs remained after the functional checks had completed.
PR #361 also changes workflows, scripts, the root lockfile, and IAPKit code, so its current full run should not be weakened retroactively. This issue is for future changes whose effective scope is documentation or agent instructions only.
Proposed direction
- Narrow
.github/workflows/codeql.yml scope detection to native source, generated code, build manifests, and build scripts that can affect each analyzed target.
- Apply the same principle to package workflow
pull_request.paths filters where broad directory globs trigger expensive native matrices for Markdown-only changes.
- Keep push, scheduled, and manual CodeQL coverage unchanged.
- Continue treating workflow, dependency, generated-code, manifest, and native-source changes conservatively.
- Add a small executable regression test or audit for representative changed-file sets so later filter edits cannot silently skip real code changes.
Acceptance criteria
- A PR changing only Markdown, assistant instructions, or compatibility symlinks under a native package or wrapper directory does not start unrelated native build or Swift CodeQL matrices.
- Apple, Google, wrapper source, generated bindings, build configuration, dependency manifests, and relevant CI workflow changes still select every required job.
- Mixed PRs select the union of all affected jobs.
- Pushes to protected branches, scheduled scans, and manual scans retain full security coverage.
- Tests cover at least one docs-only case and one code/build case for Apple core and each Swift wrapper component.
- Required-check behavior is verified so path-filtered or skipped jobs do not block merging.
Context
This is a CI efficiency improvement, not a request to reduce security coverage. The goal is to make the path contract explicit and testable while avoiding long native scans for changes that cannot affect compiled artifacts.
Problem
Documentation and agent-instruction files inside native package directories currently match broad CI and CodeQL path filters such as
packages/apple/**andlibraries/<wrapper>/**. GitHub reevaluates the complete pull request diff on every push, so a small follow-up documentation commit can restart native build and Swift CodeQL matrices even when no native source changed.PR #361 exposed the behavior:
packages/apple/CONTRIBUTING.mdselected the Swift core scan.AGENTS.md,CLAUDE.md,GEMINI.md, and contribution docs under React Native, Expo, Flutter, and Godot selected their Swift wrapper scans.PR #361 also changes workflows, scripts, the root lockfile, and IAPKit code, so its current full run should not be weakened retroactively. This issue is for future changes whose effective scope is documentation or agent instructions only.
Proposed direction
.github/workflows/codeql.ymlscope detection to native source, generated code, build manifests, and build scripts that can affect each analyzed target.pull_request.pathsfilters where broad directory globs trigger expensive native matrices for Markdown-only changes.Acceptance criteria
Context
This is a CI efficiency improvement, not a request to reduce security coverage. The goal is to make the path contract explicit and testable while avoiding long native scans for changes that cannot affect compiled artifacts.