Add scheduled CodeQL scanning - #1683
Conversation
Restore CodeQL coverage for the JavaScript/TypeScript frontend and C# AppHost on pushes, pull requests, and a weekly schedule. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
There was a problem hiding this comment.
🟡 Changes recommended
The C# extraction omits standalone production projects, leaving their code unscanned.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Restores CodeQL scanning for JavaScript/TypeScript and C# with scheduled and event-based workflow triggers.
Changes:
- Adds push, pull request, weekly, and manual triggers.
- Configures CodeQL analysis for JavaScript/TypeScript and C#.
- Builds the .NET AppHost during C# extraction.
File summaries
| File | Description |
|---|---|
.github/workflows/codeql.yml |
Defines CodeQL triggers, language analysis, permissions, and build steps. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| - name: Build AppHost | ||
| if: matrix.language == 'csharp' | ||
| working-directory: src/apphost/Aspire.Dev.AppHost | ||
| run: dotnet build --configuration Release |
Build every C# project in Aspire.Dev.slnx so CodeQL covers the AppHost, StaticHost, generator tools, and test projects. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
CodeQL only needs compiler extraction, so disable CLI bundle resolution while building the full solution. This keeps all C# projects covered without requiring orchestration assets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
Frontend HTML artifact readyThe latest frontend build uploaded the This comment updates automatically when a new frontend build artifact is uploaded. |
James Newton-King (JamesNK)
left a comment
There was a problem hiding this comment.
No blocking issues found.
Reviewed the workflow triggers, permissions, language matrix, action pinning, C# project coverage, and hosted execution. At head 532df748, both CodeQL jobs finalized their databases and successfully uploaded results; the full-solution build also addresses the earlier generator-coverage comment. All 14 PR checks are passing.
Test coverage: the workflow itself ran successfully for C# and JavaScript/TypeScript. Frontend unit/e2e/axe coverage is not applicable to this workflow-only change.
Summary
Context
The repository's last CodeQL analysis was January 23, 2026. More recent code-scanning uploads are from Trivy and do not satisfy the Continuous SDL CodeQL requirement.
Validation