Skip to content

ci: run the Rust CodeQL analysis weekly with room to finish - #96

Merged
crynta merged 1 commit into
mainfrom
ci/codeql-rust-weekly
Oct 8, 2026
Merged

crynta merged 1 commit into
mainfrom
ci/codeql-rust-weekly

Conversation

@crynta

@crynta crynta commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

The first CodeQL run after #88 merged: Actions and JavaScript/TypeScript finished in about 2 minutes; Rust on macOS and Windows both stopped at the 60-minute job limit, so no Rust results were uploaded.

  • Actions and JavaScript/TypeScript keep running after code reaches main and weekly (30-minute limit).
  • Rust runs weekly and on demand only, on macOS and Windows, with a 180-minute limit and no cancellation by a newer run.
  • .github/codeql/codeql-config.yml ignores results in vendor/ (upstream forks under their own review records).
  • .github/REPOSITORY.md describes the schedule.

After merging I'll start a manual run to confirm Rust finishes inside the new limit.

Summary by CodeRabbit

  • Chores
    • Updated automated security analysis schedules: Actions and JavaScript/TypeScript checks run after changes reach the main branch and weekly; Rust checks run weekly and on demand.
    • Rust analysis now runs on macOS and Windows and may take over an hour.
    • Analysis continues to skip pull requests and excludes results from the vendor directory.

The first run after merging showed Actions and JavaScript/TypeScript
finishing in about two minutes and Rust on macOS and Windows hitting the
60-minute job limit. Rust now runs weekly and on demand with a 180-minute
limit and no cancellation by a newer run, while the fast languages keep
running after merges to main. Results in the vendored forks are ignored.
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: zephium-browser/Zephium/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 35bedd8b-378d-46e4-989a-fa4f5e2823d6
📥 Commits

Reviewing files that changed from the base of the PR and between f112e09 and 1918392.

📒 Files selected for processing (3)
  • .github/REPOSITORY.md
  • .github/codeql/codeql-config.yml
  • .github/workflows/codeql.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The CodeQL workflow now runs Actions and JavaScript/TypeScript analysis separately from Rust analysis. Both jobs use a configuration that ignores vendor, and the repository description reflects their schedules.

Changes

CodeQL analysis workflow

Layer / File(s) Summary
Configure CodeQL analysis jobs
.github/codeql/codeql-config.yml, .github/workflows/codeql.yml, .github/REPOSITORY.md
The workflow runs Actions and JavaScript/TypeScript analysis on Ubuntu, and Rust analysis on macOS and Windows. The jobs use different timeouts, concurrency settings, and result categories. The shared configuration ignores vendor, and the repository description states the analysis schedules.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Suggested labels: area: build & ci, platform: macos, platform: windows, size: S

Merge Risk: ⚪ Minimal · up to 19183

This change only adjusts CodeQL scheduling, job limits, and vendor path ignoring. No concrete merge-blocking risk was found. The author plans to confirm that Rust analysis finishes within the new limit after merging.

Architecture Summary

Architecture risk: 🔵 Low · up to 19183

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/REPOSITORY.md: The CodeQL description now distinguishes Actions and JavaScript/TypeScript analysis after changes reach main and weekly from Rust analysis, which runs weekly and on demand on macOS and Windows. It adds that Rust analysis takes over an hour; the no-pull-requests statement remains.
  • observed — Modified behavior in .github/codeql/codeql-config.yml: Adds a paths-ignore entry for vendor; the accompanying comments describe vendored forks as reviewed upstream.
  • observed — Modified behavior in .github/workflows/codeql.yml: The comments now distinguish Actions and JavaScript/TypeScript analysis after changes reach main and weekly from Rust analysis weekly and on demand, and retain the explanation of Rust’s macOS/Windows host-specific extraction.
  • observed — Modified behavior in .github/workflows/codeql.yml: The analyze job now runs Actions and JavaScript/TypeScript only on Ubuntu, with a 30-minute timeout and concurrency scoped by language and ref. The prior shared 60-minute job and OS matrix—including Rust on macOS and Windows—were removed.
🚥 Pre-merge checks | ✅ 9 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title accurately describes the CodeQL scheduling change and uses an imperative summary, but it does not follow the required type(scope): summary format because it omits the scope. Add a scope, such as ci(codeql): run the Rust CodeQL analysis weekly with room to finish. Ensure the summary remains imperative and descriptive.
✅ Passed checks (9 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
One Logical Change ✅ Passed All three changed files support the single CodeQL scheduling and runtime-configuration change described in the title and description. .github/workflows/codeql.yml changes the jobs, schedules, timeou…
Linked Issue For Larger Changes ✅ Passed The PR is a small, contained CI fix and documentation change. It separates Rust CodeQL analysis, raises its timeout after the reported 60-minute failure, and adds the related CodeQL configuration. The…
Tests Cover Changed Behavior ✅ Passed The PR changes only CodeQL workflow/configuration and repository documentation. It does not change Rust or TypeScript logic, so the test-coverage failure condition does not apply.
Generated Files Follow Their Source ✅ Passed The pull request changes only .github/REPOSITORY.md, .github/codeql/codeql-config.yml, and .github/workflows/codeql.yml. It does not change frame/src/shared/ipc/bindings.ts, Rust IPC types, `C…
Privileged Boundary Intact ✅ Passed The PR changes only CodeQL workflow/configuration and repository documentation. The diff adds no Tauri IPC, Wry handler, privileged initialization object, custom protocol, CSP, devtools, or privileged…
Performance Impact Stated ✅ Passed PASS — The PR changes only CodeQL workflow/configuration and repository documentation. It does not touch a listed hot path. The description also states performance measurements and limits: Actions and…
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot added area: build & ci Build, CI, release and repository tooling platform: macos macOS-specific platform: windows Windows-specific size: S Under 100 changed lines labels Oct 8, 2026
@crynta
crynta merged commit 5dff03c into main Oct 8, 2026
9 checks passed
@crynta
crynta deleted the ci/codeql-rust-weekly branch October 8, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: build & ci Build, CI, release and repository tooling platform: macos macOS-specific platform: windows Windows-specific size: S Under 100 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant