Repository navigation
MAINT: Restore CodeQL security scanning - #3049
Merged
Spencer Schoenberg (spencrr) merged 1 commit intoOct 9, 2026
Merged
Conversation
Spencer Schoenberg (spencrr)
enabled auto-merge
October 9, 2026 01:06
Roman Lutz (romanlutz)
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
PyRIT's CodeQL security results stopped updating on March 27. The successful Code Quality runs use a different query suite and do not replace security scanning.
Add a dedicated security workflow based on RAMPART's working advanced setup:
Code Quality is unchanged. This PR does not change repository settings. After merging, verify fresh security results for all three languages and require
CodeQL (actions),CodeQL (javascript-typescript), andCodeQL (python)in branch protection. Blocking on finding severity requires a separate code-scanning merge-protection rule.Tests and Documentation
uv tool run --from pre-commit pre-commit run --files .github\workflows\codeql.yml- passed.git diff --cached --check- passed before committing.JupyText was not run; no Python or notebook files changed.