Skip to content

STF-1604: Analyze the merge commit in CodeQL on pull requests - #300

Merged
horgh merged 1 commit into
mainfrom
greg/remove-codeql-head-checkout
Oct 5, 2026
Merged

horgh merged 1 commit into
mainfrom
greg/remove-codeql-head-checkout

Conversation

@oschwald

@oschwald oschwald commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

The CodeQL init step warns on every run:

1 issue was detected with this workflow: git checkout HEAD^2 is no longer necessary. Please remove this step as Code Scanning recommends analyzing the merge commit for best results.

This removes the git checkout HEAD^2 step and the fetch-depth: 2 it needed. On pull requests, CodeQL now analyzes the merge commit that actions/checkout fetches by default. The init, autobuild, and analyze steps are unchanged.

This PR's own CodeQL run should show no warning in the "Initialize CodeQL" step.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the automated security analysis workflow to use the default checkout depth and remain on the checked-out revision during pull request runs. This does not change any user-facing features or behavior.

Remove the git checkout HEAD^2 step and the fetch-depth it needed.
The CodeQL init action warns that the step is no longer necessary,
and code scanning recommends analyzing the merge commit, which
actions/checkout fetches by default.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:55
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6064c5c0-8f0f-4df9-803e-e88cae7b5bef

📥 Commits

Reviewing files that changed from the base of the PR and between 200ae34 and 2c5946e.

📒 Files selected for processing (1)
  • .github/workflows/codeql-analysis.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/codeql-analysis.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The CodeQL workflow no longer sets fetch-depth: 2 or checks out HEAD^2 for pull requests. Subsequent steps use the commit provided by the checkout action.

Changes

CodeQL workflow

Layer / File(s) Summary
Checkout configuration
.github/workflows/codeql-analysis.yml
The checkout step no longer sets fetch-depth: 2. The pull-request-only step that checked out HEAD^2 is removed.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 2c594

CodeQL now analyzes the pull-request merge commit as intended. No actionable merge-blocking risk was identified; the change is ready to merge after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: CodeQL will analyze the merge commit on pull requests.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit hops past the checkout gate
The default depth is set in place
No second parent takes the ride
CodeQL follows the checked-out side
Then clover waits on the other side

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused workflow change is correct, and the updated CodeQL run completed successfully without the targeted warning.

Review effort: Balanced
Findings: None

What changed in this PR

Updates CodeQL pull-request analysis to use the default merge commit checkout.

Changes:

  • Removed the unnecessary HEAD^2 checkout.
  • Restored the default shallow checkout depth.
  • Confirmed the PR’s CodeQL run succeeds without the warning.
File Description
.github/​workflows/​codeql-analysis.yml Uses the default checked-out revision for CodeQL analysis.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@oschwald oschwald changed the title Analyze the merge commit in CodeQL on pull requests STF-1604: Analyze the merge commit in CodeQL on pull requests Oct 2, 2026
@horgh
horgh merged commit 29bfde1 into main Oct 5, 2026
39 checks passed
@horgh
horgh deleted the greg/remove-codeql-head-checkout branch October 5, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants