Add custom CodeQL query to prevent project evaluator misuse in the CLI #14
codeql.yml
on: pull_request
Analyze (actions)
51s
Analyze (java-kotlin)
11s
Analyze (javascript-typescript)
1m 8s
Annotations
1 error and 5 warnings
|
Analyze (java-kotlin)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.25.2/x64/codeql/codeql database init --force-overwrite --db-cluster /home/runner/work/_temp/codeql_databases --source-root=/home/runner/work/pkl/pkl --calculate-language-specific-baseline --sublanguage-file-coverage --extractor-include-aliases --language=java --codescanning-config=/home/runner/work/_temp/user-config.yaml --build-mode=autobuild". Exit code was 2 and error was: A fatal error occurred: Specifier for external repository is invalid: - uses: ./.github/codeql-queries/cli-project-evaluator-settings.ql. See the logs for more details.
|
|
Analyze (java-kotlin)
Debugging artifacts are unavailable since the 'init' Action failed before it could produce any.
|
|
Analyze (java-kotlin)
3 diagnostic(s) could not be written to the database and will not appear on the Tool Status Page.
|
|
Analyze (java-kotlin)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.
To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
|
|
Analyze (actions)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.
To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
|
|
Analyze (javascript-typescript)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.
To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
|