Skip to content

feat(security): add CodeQL composites and integrate into pr-security-scan #90

feat(security): add CodeQL composites and integrate into pr-security-scan

feat(security): add CodeQL composites and integrate into pr-security-scan #90

Triggered via pull request March 24, 2026 14:44
Status Success
Total duration 1m 20s
Artifacts

self-pr-validation.yml

on: pull_request
validation  /  Skip if Draft
4s
validation / Skip if Draft
YAML Lint
6s
YAML Lint
Action Lint
12s
Action Lint
Pinned Actions Check
5s
Pinned Actions Check
Markdown Link Check
14s
Markdown Link Check
Spelling Check
6s
Spelling Check
Shell Check
6s
Shell Check
README Check
5s
README Check
Composite Schema Lint
5s
Composite Schema Lint
CodeQL Analysis
52s
CodeQL Analysis
validation  /  Validate Source Branch
6s
validation / Validate Source Branch
validation  /  Validate PR Title
6s
validation / Validate PR Title
validation  /  Check PR Size
8s
validation / Check PR Size
validation  /  Check PR Description
5s
validation / Check PR Description
validation  /  Auto-label PR
7s
validation / Auto-label PR
validation  /  Check Assignee
5s
validation / Check Assignee
validation  /  Check Linked Issues
5s
validation / Check Linked Issues
validation  /  Check Changelog Update
0s
validation / Check Changelog Update
validation  /  PR Checks Summary
6s
validation / PR Checks Summary
validation  /  ...  /  Send Notification
9s
validation / Notify / Send Notification
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
CodeQL Analysis
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
CodeQL Analysis
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.