Skip to content

Add scheduled CodeQL scanning - #1683

Merged
David Pine (IEvangelist) merged 4 commits into
mainfrom
dapine/restore-codeql-scanning
Sep 17, 2026
Merged

David Pine (IEvangelist) merged 4 commits into
mainfrom
dapine/restore-codeql-scanning

Conversation

@IEvangelist

Copy link
Copy Markdown
Member

Summary

  • restore CodeQL scanning for JavaScript/TypeScript and C#
  • build the .NET 10 AppHost during C# extraction
  • run on main pushes, pull requests, weekly schedule, and manual dispatch

Context

The repository's last CodeQL analysis was January 23, 2026. More recent code-scanning uploads are from Trivy and do not satisfy the Continuous SDL CodeQL requirement.

Validation

  • AppHost Release build succeeds with no warnings
  • workflow matches repository Prettier formatting

Restore CodeQL coverage for the JavaScript/TypeScript frontend and C# AppHost on pushes, pull requests, and a weekly schedule.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
Copilot AI lite review requested due to automatic review settings September 16, 2026 20:17
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The C# extraction omits standalone production projects, leaving their code unscanned.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Restores CodeQL scanning for JavaScript/TypeScript and C# with scheduled and event-based workflow triggers.

Changes:

  • Adds push, pull request, weekly, and manual triggers.
  • Configures CodeQL analysis for JavaScript/TypeScript and C#.
  • Builds the .NET AppHost during C# extraction.
File summaries
File Description
.github/workflows/codeql.yml Defines CodeQL triggers, language analysis, permissions, and build steps.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/codeql.yml Outdated
Comment on lines +46 to +49
- name: Build AppHost
if: matrix.language == 'csharp'
working-directory: src/apphost/Aspire.Dev.AppHost
run: dotnet build --configuration Release
Build every C# project in Aspire.Dev.slnx so CodeQL covers the AppHost, StaticHost, generator tools, and test projects.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
CodeQL only needs compiler extraction, so disable CLI bundle resolution while building the full solution. This keeps all C# projects covered without requiring orchestration assets.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
@aspire-repo-bot

Copy link
Copy Markdown
Contributor

Frontend HTML artifact ready

The latest frontend build uploaded the frontend-dist artifact for PR #1683. Use the VS Code button below to open this PR with GitHub Artifacts Explorer and browse the built HTML locally.

VS Code: Open PR #1683 artifacts

This comment updates automatically when a new frontend build artifact is uploaded.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blocking issues found.

Reviewed the workflow triggers, permissions, language matrix, action pinning, C# project coverage, and hosted execution. At head 532df748, both CodeQL jobs finalized their databases and successfully uploaded results; the full-solution build also addresses the earlier generator-coverage comment. All 14 PR checks are passing.

Test coverage: the workflow itself ran successfully for C# and JavaScript/TypeScript. Frontend unit/e2e/axe coverage is not applicable to this workflow-only change.

@IEvangelist
David Pine (IEvangelist) merged commit d09fc7c into main Sep 17, 2026
14 checks passed
@IEvangelist
David Pine (IEvangelist) deleted the dapine/restore-codeql-scanning branch September 17, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants