Make codeql.yml a reusable workflow_call workflow - #29
Merged
Merged
Conversation
Every consumer repo currently carries its own full copy of this file, differing only in the language matrix (ruby-only, js/ts-only, rust-only, or some mix, plus "actions" everywhere). That means fixes like the stale-version-comment cleanup in #28 have to be repeated by hand across ~20 repos instead of landing once here, same as ci.yml/cd.yml/stale.yml/ triage.yml already solved for their own workflows. Converts codeql.yml to workflow_call, taking the language list as a JSON-array input (e.g. '["actions","ruby"]') instead of a hardcoded matrix. build-mode is now unconditionally "none" for every language, since that's what every current caller already used (GA since CodeQL 2.23.3, including for Rust/C++). Since codeql.yml no longer has its own push/pull_request/schedule triggers, shared-config would otherwise stop scanning its own .github/workflows/ - added codeql-self-scan.yml to carry those triggers and call the reusable workflow locally (`uses: ./.github/workflows/ codeql.yml`, not @main, so a PR that edits codeql.yml is tested against its own in-PR version rather than whatever's already on main). Verified with zizmor (offline + --gh-token) and actionlint: 0 findings on both new/changed files.
This was referenced Jul 25, 2026
dduugg
added a commit
to rubyatscale/bigrails-redis
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
1 of 2 tasks
dduugg
added a commit
to rubyatscale/singed
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
This was referenced Jul 25, 2026
dduugg
added a commit
to rubyatscale/danger-packwerk
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/code_manifest
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/packs-specification
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/chatwerk
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/packwerk-vscode
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","javascript"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/code-ownership-vscode
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","javascript"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/codeowners-rs
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","rust"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/pks
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","rust"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/code_ownership
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby","rust"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/visualize_packs
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby","javascript"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/packs
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/packwerk-extensions
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/pack_stats
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/rubocop-packs
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/code_teams
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/parse_packwerk
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
dduugg
added a commit
to rubyatscale/query_packwerk
that referenced
this pull request
Jul 25, 2026
Replaces the full copy-pasted codeql.yml with a thin caller of rubyatscale/shared-config/.github/workflows/codeql.yml@main (rubyatscale/shared-config#29), passing this repo's language list (["actions","ruby"]) as input instead of a hardcoded matrix. Functionally identical - same checkout/codeql-action SHAs, same build-mode: none, same permissions - but future fixes (like the stale version-comment cleanup in shared-config#28) now land once in shared-config instead of needing to be repeated by hand across every repo.
3 tasks done
dduugg
added a commit
that referenced
this pull request
Sep 29, 2026
The README never picked up codeql.yml or codeql-self-scan.yml from #29. Both are now in the tables, with a caller example and the languages input. The zizmor section now names the check to require (zizmor / zizmor with the example), notes that actions: read is only needed in private repos, and warns that callers tracking @main pick up zizmor-action upgrades, and any new audits, at once. The job comment in zizmor.yml now says what callers should grant instead of reading as a guarantee.
dduugg
added a commit
that referenced
this pull request
Sep 29, 2026
* Make zizmor.yml a reusable workflow_call workflow Gem repos can now call zizmor from here instead of carrying their own copy, as codeql.yml did in #29. zizmor-self-scan.yml keeps the push and PR triggers and calls it locally, so shared-config still scans itself, with the same Security tab upload as before. The advanced-security input defaults to true, the zizmor-action default. Setting it to false reports findings as annotations and fails the job, which a required check needs: zizmor exits 0 whenever it writes SARIF. The job has no permissions block so that it takes the caller's, since the two modes need different ones. * Bump zizmor-action to v0.6.4 v0.6.4 makes zizmor 1.30.1 the default. The v0.6.2 pin still ran 1.29.0, and rubyfmt-action is already on v0.6.3, so moving it onto this workflow would otherwise be a downgrade. action.sh is unchanged between the two; action.yml only bumps its upload-sarif pin. * Document CodeQL and the zizmor check name in the README The README never picked up codeql.yml or codeql-self-scan.yml from #29. Both are now in the tables, with a caller example and the languages input. The zizmor section now names the check to require (zizmor / zizmor with the example), notes that actions: read is only needed in private repos, and warns that callers tracking @main pick up zizmor-action upgrades, and any new audits, at once. The job comment in zizmor.yml now says what callers should grant instead of reading as a guarantee. * Call the self-scan workflows with the $/ self-repository syntax zizmor 1.30 (now the default via zizmor-action v0.6.4) flags ./ calls to in-repo workflows with its self-repository audit. $/ resolves to this repository at the commit that is running, like ./ does, so a PR that edits zizmor.yml or codeql.yml is still tested against its own version. GitHub also treats $/ references as pinned under the policy requiring full-length SHA pins, which ./ references are not. codeql-self-scan.yml gets the same change, since it would otherwise gain the same alert on main once this merges. actionlint 1.7.12 doesn't recognize $/ yet (rhysd/actionlint#711).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every consumer repo (~20 across the org) currently carries its own full copy of
codeql.yml, differing only in the language matrix (ruby-only, js/ts-only, rust-only, or some mix, plusactionseverywhere). That means fixes like the stale-version-comment cleanup in #28 have to be repeated by hand across every repo instead of landing once here — same problemci.yml/cd.yml/stale.yml/triage.ymlalready solved for their own workflows.Converts
codeql.ymltoworkflow_call, taking the language list as a JSON-array input (e.g.'["actions","ruby"]') instead of a hardcoded matrix.build-modeis now unconditionallynonefor every language, since that's what every current caller already used (GA since CodeQL 2.23.3, including for Rust/C++).Since
codeql.ymlno longer has its ownpush/pull_request/scheduletriggers, shared-config would otherwise stop scanning its own.github/workflows/— addedcodeql-self-scan.ymlto carry those triggers and call the reusable workflow locally (uses: ./.github/workflows/codeql.yml, not@main, so a PR that editscodeql.ymlis tested against its own in-PR version rather than whatever's already onmain).Consumer repos will follow up with a separate PR each, converting their own
codeql.ymlto a caller like:Test plan
zizmor .github/workflows/— 0 findings, offline and with--gh-tokenactionlint— 0 findings on both new/changed filescodeql-self-scan.ymlactually runs and reports results once merged