mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-08-29 04:26:20 +00:00
The CodeQL Analyze Python job failed on the #757 merge commit with ECONNRESET while streaming the CodeQL bundle download in codeql-action/init's "Setup CodeQL tools" step. This is unrelated to the merged code — it's a known, currently-unaddressed gap in codeql-action: the download error is retryable but the action doesn't retry it internally (confirmed via codeql-action's issue tracker and changelog). Since a `uses:` step can't be wrapped by a shell-level retry action, Initialize CodeQL now runs up to 3 times, cascading to the next attempt only if the previous one failed, so the common case (success on attempt 1) costs nothing extra.
98 lines
3.4 KiB
YAML
98 lines
3.4 KiB
YAML
name: CodeQL
|
||
|
||
on:
|
||
push:
|
||
branches: [main]
|
||
pull_request:
|
||
branches: [main]
|
||
schedule:
|
||
- cron: '30 1 * * 1' # Every Monday 7 AM IST
|
||
|
||
permissions:
|
||
contents: read
|
||
security-events: write
|
||
actions: read
|
||
|
||
jobs:
|
||
analyze:
|
||
name: Analyze Python
|
||
runs-on: ubuntu-latest
|
||
|
||
steps:
|
||
- name: Checkout repository
|
||
uses: actions/checkout@v7
|
||
|
||
# The CodeQL bundle download (github/codeql-action/init's "Setup CodeQL
|
||
# tools" step) streams a ~1GB tarball from GitHub's release CDN and
|
||
# does not retry on a transient connection reset (ECONNRESET) itself
|
||
# (github/codeql-action, unresolved as of v4 / CLI 2.26.1: the HTTP
|
||
# error is retryable but isn't retried internally). Since a `uses:`
|
||
# step can't be wrapped by a shell-level retry action, attempt init
|
||
# up to 3 times; each retry is a fresh download attempt with no
|
||
# meaningful state carried over from a failed attempt.
|
||
- name: Initialize CodeQL (attempt 1)
|
||
id: codeql-init-1
|
||
uses: github/codeql-action/init@v4
|
||
continue-on-error: true
|
||
with:
|
||
languages: python
|
||
queries: security-and-quality
|
||
config-file: .github/codeql/codeql-config.yml
|
||
|
||
- name: Initialize CodeQL (attempt 2)
|
||
id: codeql-init-2
|
||
if: steps.codeql-init-1.outcome == 'failure'
|
||
uses: github/codeql-action/init@v4
|
||
continue-on-error: true
|
||
with:
|
||
languages: python
|
||
queries: security-and-quality
|
||
config-file: .github/codeql/codeql-config.yml
|
||
|
||
- name: Initialize CodeQL (attempt 3)
|
||
id: codeql-init-3
|
||
if: steps.codeql-init-2.outcome == 'failure'
|
||
uses: github/codeql-action/init@v4
|
||
with:
|
||
languages: python
|
||
queries: security-and-quality
|
||
config-file: .github/codeql/codeql-config.yml
|
||
|
||
- name: Autobuild
|
||
uses: github/codeql-action/autobuild@v4
|
||
|
||
- name: Perform CodeQL Analysis
|
||
uses: github/codeql-action/analyze@v4
|
||
with:
|
||
category: "/language:python"
|
||
upload: false
|
||
id: codeql
|
||
|
||
- name: Upload SARIF (Advanced Setup only)
|
||
# Uploads results only when Default Setup is not active.
|
||
# If Default Setup is still enabled, this step skips gracefully
|
||
# instead of failing the workflow with HTTP 409.
|
||
uses: github/codeql-action/upload-sarif@v4
|
||
with:
|
||
sarif_file: ${{ steps.codeql.outputs.sarif-output }}
|
||
category: "/language:python"
|
||
wait-for-processing: true
|
||
continue-on-error: true
|
||
|
||
# NOTE: Auto-dismissal by rule-id is intentionally removed.
|
||
# Dismissing every alert that matches a rule ID would silently suppress
|
||
# future real vulnerabilities of the same type. The alerts below were
|
||
# individually triaged and dismissed manually in the security-enhancement
|
||
# PR (alerts #12–#18). New alerts must be reviewed and dismissed by hand,
|
||
# or will auto-close when the underlying code no longer triggers them.
|
||
#
|
||
# If you need to dismiss a specific known-safe alert, pin its alert NUMBER
|
||
# here and remove it once CodeQL stops reporting it naturally. Example:
|
||
#
|
||
# PINNED_ALERT_NUMBERS=(12 13 14 15 16 17 18)
|
||
# for NUM in "${PINNED_ALERT_NUMBERS[@]}"; do
|
||
# gh api repos/$REPO/code-scanning/alerts/$NUM \
|
||
# -X PATCH -f state=dismissed -f dismissed_reason="false positive" \
|
||
# -f dismissed_comment="<reason>"
|
||
# done
|