Files
roboco/.github/workflows/code-ql.yml
T
20110debab fix(ci): fleet-branch push triggers + dispatcher claim prefilter (#463)
* fix(ci): fleet-branch push triggers close the absent-check gap; dispatcher claim prefilter

PROVEN with API receipts: when the PM squash-merges a subtask PR into a
branch that is itself another PR's head (GitService.merge_pull_request →
GitHub's Merge API), the pull_request synchronize webhook fires
unreliably (1 of 3 in the live sample) while plain push events fired
100% — so PR heads sat with ABSENT required checks that three review
rounds mistook for green. CI, CodeQL, e2e-smoke, and panel-ci now also
trigger on push to the fleet's branch types, deduped by a concurrency
group keyed on head_ref||ref_name so a branch that is also a PR head
never double-runs.

Dispatcher churn: _route_unassigned_pm_task consults the claim guards'
own predicate (TaskService.is_pending_claim_blocked, a public wrapper —
no duplicated SQL) before routing, so dependency- or sequence-held
tasks skip the tick with zero HTTP claim round-trips; fails open so a
DB hiccup degrades to the old behavior.

* chore(docs): reflow hard-wrapped prose inherited from the six-PR merge train

* chore(foundation): regenerate lifecycle artifacts; reflow inherited prose

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-11 09:21:15 +02:00

76 lines
2.3 KiB
YAML

name: CodeQL
on:
push:
# master plus fleet task branches: `pull_request`'s synchronize trigger
# doesn't reliably fire when a revision lands on a PR head via the
# merge API (see ci.yml for the live-proven receipts); `push` does, so
# it's the redundant trigger for a required check that must not go
# ABSENT on a fleet-authored PR revision.
branches: [master, 'feature/**', 'bug/**', 'chore/**', 'docs/**', 'hotfix/**']
paths:
- 'roboco/**'
- 'agents/**'
- 'alembic/**'
- 'scripts/**'
- 'panel/**'
- 'pyproject.toml'
- '.github/workflows/code-ql.yml'
pull_request:
branches: [master]
paths:
- 'roboco/**'
- 'agents/**'
- 'alembic/**'
- 'scripts/**'
- 'panel/**'
- 'pyproject.toml'
- '.github/workflows/code-ql.yml'
schedule:
- cron: '0 0 * * 1'
workflow_dispatch:
# A fleet branch that's also an open PR head can get both a `push` and a
# `pull_request` run for the same commit; cancel the older one instead of
# burning two runners on identical work. `head_ref` (set only for
# pull_request) and `ref_name` (the short branch name, valid for push) both
# resolve to the SAME branch name, so the two event shapes share one group —
# plain `github.ref` would NOT (it's `refs/pull/<n>/merge` for pull_request
# vs `refs/heads/<branch>` for push, so it'd never collapse them).
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref_name }}
cancel-in-progress: true
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
include:
- language: python
build-mode: none
- language: javascript-typescript
build-mode: none
steps:
- name: Checkout code
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{ matrix.language }}"