Skip to content

ci: Explicit codeql workflow#2202

Open
thompson-tomo wants to merge 4 commits into
open-telemetry:mainfrom
thompson-tomo:patch-1
Open

ci: Explicit codeql workflow#2202
thompson-tomo wants to merge 4 commits into
open-telemetry:mainfrom
thompson-tomo:patch-1

Conversation

@thompson-tomo

@thompson-tomo thompson-tomo commented Apr 11, 2026

Copy link
Copy Markdown
Contributor

This adds an explicit codeql Workflow to ensure it runs on all pr's/commits as currently alot is being missed.

This will need someone to enable advanced codeql -> https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-advanced-setup-for-code-scanning

This enable sent has already been done to numerous otel repos see https://github.com/search?q=org%3Aopen-telemetry+codeql-Action%2FInit+language%3AYAML+path%3A%2F%5E%5C.github%5C%2Fworkflows%5C%2F%2F&type=code

@arielvalentin

Copy link
Copy Markdown
Contributor

@trask do we have standard workflows that are centrally defined like codeql that should be run in every repo?

If so, should that be provisioned though terraform instead of on a repo by repo basis?

@trask

trask commented May 5, 2026

Copy link
Copy Markdown
Member

hey @arielvalentin! are you asking about provisioning the codeql repo settings? or the codeql yml?

@thompson-tomo

Copy link
Copy Markdown
Contributor Author

@trask I am going to assume he is referring to the CI Workflow which would be added via this pr.

@kaylareopelle this pr also needs the repo config change to enable advanced codeql scanning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants