Skip to content

MAINT: Restore CodeQL security scanning - #3049

Merged
Spencer Schoenberg (spencrr) merged 1 commit into
microsoft:mainfrom
spencrr:dev/spencrr/codeql-fix
Oct 9, 2026
Merged

Spencer Schoenberg (spencrr) merged 1 commit into
microsoft:mainfrom
spencrr:dev/spencrr/codeql-fix

Conversation

@spencrr

Copy link
Copy Markdown
Contributor

Description

PyRIT's CodeQL security results stopped updating on March 27. The successful Code Quality runs use a different query suite and do not replace security scanning.

Add a dedicated security workflow based on RAMPART's working advanced setup:

  • Scan Python, JavaScript/TypeScript, and GitHub Actions with the default security queries.
  • Run on main/release pushes and PRs, merge queue events, a weekly schedule, and manual dispatch.
  • Pin actions to commit SHAs and scope permissions to the analysis jobs.

Code Quality is unchanged. This PR does not change repository settings. After merging, verify fresh security results for all three languages and require CodeQL (actions), CodeQL (javascript-typescript), and CodeQL (python) in branch protection. Blocking on finding severity requires a separate code-scanning merge-protection rule.

Tests and Documentation

  • uv tool run --from pre-commit pre-commit run --files .github\workflows\codeql.yml - passed.
  • git diff --cached --check - passed before committing.
  • The unchanged workflow also passed actionlint 1.7.12 and assertions covering triggers, languages, permissions, and action pins during initial validation.
  • Actual CodeQL execution and SARIF upload still need verification on GitHub.
  • No documentation changes. Unit tests were not run because this change only adds a workflow.

JupyText was not run; no Python or notebook files changed.

@spencrr
Spencer Schoenberg (spencrr) added this pull request to the merge queue Oct 9, 2026
Merged via the queue into microsoft:main with commit 9755489 Oct 9, 2026
51 checks passed
@spencrr
Spencer Schoenberg (spencrr) deleted the dev/spencrr/codeql-fix branch October 9, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants