Skip to content

Add custom CodeQL query to prevent project evaluator misuse in the CLI #14

Add custom CodeQL query to prevent project evaluator misuse in the CLI

Add custom CodeQL query to prevent project evaluator misuse in the CLI #14

Triggered via pull request April 23, 2026 01:14
Status Failure
Total duration 1m 11s
Artifacts

codeql.yml

on: pull_request
Analyze (actions)
51s
Analyze (actions)
Analyze (java-kotlin)
11s
Analyze (java-kotlin)
Analyze (javascript-typescript)
1m 8s
Analyze (javascript-typescript)
Fit to window
Zoom out
Zoom in

Annotations

1 error and 5 warnings
Analyze (java-kotlin)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.25.2/x64/codeql/codeql database init --force-overwrite --db-cluster /home/runner/work/_temp/codeql_databases --source-root=/home/runner/work/pkl/pkl --calculate-language-specific-baseline --sublanguage-file-coverage --extractor-include-aliases --language=java --codescanning-config=/home/runner/work/_temp/user-config.yaml --build-mode=autobuild". Exit code was 2 and error was: A fatal error occurred: Specifier for external repository is invalid: - uses: ./.github/codeql-queries/cli-project-evaluator-settings.ql. See the logs for more details.
Analyze (java-kotlin)
Debugging artifacts are unavailable since the 'init' Action failed before it could produce any.
Analyze (java-kotlin)
3 diagnostic(s) could not be written to the database and will not appear on the Tool Status Page.
Analyze (java-kotlin)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
Analyze (actions)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
Analyze (javascript-typescript)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.