From a49c5569b4d94829c954b90a2f69abb694f7b645 Mon Sep 17 00:00:00 2001 From: Mike Odnis Date: Wed, 30 Sep 2026 10:06:01 -0400 Subject: [PATCH] ci(security-scan): let a CodeQL configuration error fail the job The Analyze step carried `continue-on-error: true` with the comment "default-setup collision otherwise fails". It did exactly that -- and in doing so converted a rejected upload into a permanent green check. --- .github/workflows/security-scan.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 04e9f3d..49f62be 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -200,10 +200,17 @@ jobs: - name: Autobuild uses: github/codeql-action/autobuild@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - name: Analyze + # Deliberately NOT continue-on-error. This step used to carry + # `continue-on-error: true` so the default-setup collision would not + # fail the job -- which turned "Analysis upload status is failed. / + # CodeQL job status was configuration error." into a permanent green + # check. Callers whose repositories have default setup enabled now omit + # `languages` instead of uploading an analysis that is discarded, so + # every failure left here is a real one -- extraction faults, autobuild + # breakage, a rejected SARIF -- and a real one must fail the job. uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: category: "/language:${{ matrix.language }}" - continue-on-error: true # default-setup collision otherwise fails # ── Gitleaks ────────────────────────────────────────────────────────────── # The MIT gitleaks CLI, pinned by version and checksum — deliberately NOT