Skip to content

Support meta variable for analysis kind in remote config file addresses - #4048

Draft
mbg wants to merge 2 commits into
mainfrom
mbg/config-file/meta
Draft

Support meta variable for analysis kind in remote config file addresses#4048
mbg wants to merge 2 commits into
mainfrom
mbg/config-file/meta

Conversation

@mbg

@mbg mbg commented Jul 28, 2026

Copy link
Copy Markdown
Member

Sibling to #4047 with an implementation of a possible design to support a meta variable for the analysis kind in remote configuration file addresses. With the FF here enabled, owner/repo:codeql-$kind.yml becomes e.g. owner/repo:codeql-code-quality.yml for a code-quality analysis.

Risk assessment

For internal use only. Please select the risk level of this change:

  • Low risk: Changes are fully under feature flags, or have been fully tested and validated in pre-production environments and are highly observable, or are documentation or test only.

Which use cases does this change impact?

Workflow types:

  • Advanced setup - Impacts users who have custom CodeQL workflows.
  • Managed - Impacts users with dynamic workflows (Default Setup, Code Quality, ...).

Products:

  • Code Scanning - The changes impact analyses when analysis-kinds: code-scanning.
  • Code Quality - The changes impact analyses when analysis-kinds: code-quality.
  • Other first-party - The changes impact other first-party analyses.

环境:

  • Dotcom - Impacts CodeQL workflows on github.com and/or GitHub Enterprise Cloud with Data Residency.
  • GHES - Impacts CodeQL workflows on GitHub Enterprise Server.

How did/will you validate this change?

  • Test repository - This change will be tested on a test repository before merging.
  • Unit tests - I am depending on unit test coverage (i.e. tests in .test.ts files).
  • End-to-end tests - I am depending on PR checks (i.e. tests in pr-checks).

If something goes wrong after this change is released, what are the mitigation and rollback strategies?

  • Feature flags - All new or changed code paths can be fully disabled with corresponding feature flags.

How will you know if something goes wrong after this change is released?

  • Telemetry - I rely on existing telemetry or have made changes to the telemetry.
    • 仪表盘s - I will watch relevant dashboards for issues after the release. Consider whether this requires this change to be released at a particular time rather than as part of a regular release.
    • Alerts - 新建 or existing monitors will trip if something goes wrong with this change.

Are there any special considerations for merging or releasing this change?

  • No special considerations - This change can be merged at any time.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Consider adding a changelog entry for this change.
  • Confirm the readme and docs have been updated if necessary.

@mbg mbg self-assigned this Jul 28, 2026
@github-actions github-actions Bot added the size/M Should be of average difficulty to review label Jul 28, 2026
注册 for free to join this conversation on GitHub. Already have an account? 登录 to comment

标签

size/M Should be of average difficulty to review

项目

None yet

Development

Successfully merging this pull request may close these issues.

1 participant