Skip to content

Conversation

@paulmedynski
Copy link
Contributor

Description.

This PR creates a CodeQL config file that GitHub will use to perform scans. It disables scanning of Actions since those always fail. We leave C# scanning active.

Commented out the scanning of Actions in CodeQL workflow.
Copilot AI review requested due to automatic review settings December 2, 2025 11:43
@paulmedynski paulmedynski requested a review from a team as a code owner December 2, 2025 11:43
@paulmedynski paulmedynski added the Area\Engineering Use this for issues that are targeted for changes in the 'eng' folder or build systems. label Dec 2, 2025
Copilot finished reviewing on behalf of paulmedynski December 2, 2025 11:45
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a new CodeQL Advanced workflow for automated security scanning of the repository. The workflow is configured to run on pushes to main, pull requests, and on a weekly schedule, focusing on C# code analysis while disabling GitHub Actions scanning.

Key Changes

  • Adds CodeQL workflow file with C# language scanning enabled
  • Disables Actions language scanning (commented out) due to recurring failures
  • Configures workflow to run on push, pull requests, and weekly schedule (Saturday at 11:33 PM)

You can also share your feedback on Copilot code review for a chance to win a $100 gift card. Take the survey.

Updated CodeQL workflow to use manual build mode for C# and added .NET Core SDK setup step.
Copilot AI review requested due to automatic review settings December 2, 2025 14:36
Create a packages directory before building the project.
Copilot finished reviewing on behalf of paulmedynski December 2, 2025 14:41
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 2 comments.


You can also share your feedback on Copilot code review for a chance to win a $100 gift card. Take the survey.

Copy link
Contributor

@mdaigle mdaigle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks ok for now

Copy link
Member

@cheenamalhotra cheenamalhotra left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎉

@cheenamalhotra cheenamalhotra merged commit 3548fba into main Dec 3, 2025
7 checks passed
@cheenamalhotra cheenamalhotra deleted the dev/paul/codeql-config branch December 3, 2025 02:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area\Engineering Use this for issues that are targeted for changes in the 'eng' folder or build systems.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants