From d21c4605269ae96f81a366665cca495764f828cc Mon Sep 17 00:00:00 2001 From: Danglewood <85772166+deeleeramone@users.noreply.github.com> Date: Thu, 1 Oct 2026 08:20:43 -0700 Subject: [PATCH 1/2] add python config file for codeql --- .github/codeql/python.yml | 7 +++++++ .github/workflows/codeql.yml | 6 +++--- 2 files changed, 10 insertions(+), 3 deletions(-) create mode 100644 .github/codeql/python.yml diff --git a/.github/codeql/python.yml b/.github/codeql/python.yml new file mode 100644 index 000000000000..00185de62a5b --- /dev/null +++ b/.github/codeql/python.yml @@ -0,0 +1,7 @@ +name: python +paths-ignore: + # Cookiecutter template sources contain Jinja placeholders ({{ ... }}, {% ... %}) + # and are not valid Python until rendered, so CodeQL cannot parse them. + # The wildcard stands in for the literal "{{cookiecutter.project_tag}}" directory. + # The template's hooks/ are plain Python and stay in scope. + - 'cookiecutter/openbb_cookiecutter/template/*cookiecutter.project_tag*/**' diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 4e6014d469e7..2077d7d7ed95 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -13,11 +13,11 @@ name: "CodeQL Advanced" on: push: - branches: [ "develop", "PR-review", "gh-pages", "main", "v5" ] + branches: [ "develop", "PR-review", "gh-pages", "main" ] paths-ignore: - 'cookiecutter/**' pull_request: - branches: [ "develop", "PR-review", "gh-pages", "main", "v5" ] + branches: [ "develop", "PR-review", "gh-pages", "main" ] paths-ignore: - 'cookiecutter/**' schedule: @@ -52,7 +52,7 @@ jobs: config-file: '' - language: python build-mode: none - config-file: '' + config-file: .github/codeql/python.yml - language: rust build-mode: none config-file: .github/codeql/desktop-only.yml From e13048f779cbc36f49d877b1a24f5ed2e7302b33 Mon Sep 17 00:00:00 2001 From: Danglewood <85772166+deeleeramone@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:07:54 -0700 Subject: [PATCH 2/2] ci: run lint checks for CodeQL changes --- .github/workflows/lint-openbb-platform.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/lint-openbb-platform.yml b/.github/workflows/lint-openbb-platform.yml index 7ee93772ad1b..8bbd160f6de8 100644 --- a/.github/workflows/lint-openbb-platform.yml +++ b/.github/workflows/lint-openbb-platform.yml @@ -13,6 +13,8 @@ on: - '!openbb_platform/providers/**' - '!openbb_platform/obbject_extensions/**' - '.github/workflows/lint-openbb-platform.yml' + - '.github/codeql/**' + - '.github/workflows/codeql.yml' merge_group: types: [checks_requested]