Skip to content

fix(ci): repoint codeql-action at a SHA that exists - #62

Merged
hyperpolymath merged 5 commits into
mainfrom
fix/codeql-action-sha
Jul 28, 2026
Merged

fix(ci): repoint codeql-action at a SHA that exists#62
hyperpolymath merged 5 commits into
mainfrom
fix/codeql-action-sha

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

github/codeql-action@29b1f65c1f735799893313399435a59f54045865 is pinned here but exists in no repository — the GitHub API returns 422 for it.

CodeQL therefore could not start: the run graph fails to build and the job reports startup_failure, so this repository has had no CodeQL scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3 tag currently resolves to (v3.37.3), verified against the API.

Found while auditing the estate: the same non-existent SHA was pinned in 104 repositories, so CodeQL was dead across nearly all of them.

hyperpolymath and others added 4 commits July 26, 2026 14:46
github/codeql-action@29b1f65 is pinned here but exists in no
repository -- the GitHub API returns 422 for it. CodeQL therefore could
not start: the run graph fails to build and the job reports
startup_failure, so this repository has had no CodeQL scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, which is what the v3
tag currently resolves to (v3.37.3), verified against the API.

Found while auditing the estate: the same non-existent SHA is pinned in
over 100 repositories, so CodeQL is dead across nearly all of them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Comment thread guix.scm
Comment thread guix.scm
@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

CI failed: Security scan failure caused by Gitleaks detecting a potential secret in the repository source files.

Overview

1 CI job failure detected across 1 analyzed log, caused by a Gitleaks security scan violation.

Failures

Gitleaks Secret Detection Failure (confidence: high)

  • Type: tooling
  • Affected jobs: 90323905066
  • Related to change: yes
  • Root cause: Gitleaks found a potential secret or sensitive information within the repository source files during the security scan.
  • Suggested fix: Review the gitleaks scan output or run gitleaks locally to identify the detected secret, remove or properly redact/ignore it, and commit the fix.

Summary

  • Change-related failures: 1 failure due to Gitleaks detecting a secret leak.
  • Infrastructure/flaky failures: 0
  • Recommended action: Inspect the repository for exposed secrets or credentials, remove them, and ensure any false positives are appropriately configured or ignored.
Code Review ✅ Approved 2 resolved / 2 findings

Updates CodeQL action references to use a valid SHA, but the Guix package definition mislabels the repository as squisher-corpus and the license header is truncated.

✅ 2 resolved
Bug: guix.scm mislabels laminar package as squisher-corpus

📄 guix.scm:2 📄 guix.scm:10 📄 guix.scm:14-16
This is the laminar repository, but the Guix package definition was overwritten to identify as squisher-corpus (name, synopsis, description, and home-page all point to a different project). This appears to be an accidental copy from another repo (commit 'chore: update guix.scm from squisher-corpus') and unrelated to the CodeQL SHA fix. guix shell -f guix.scm will now build the wrong package with a home-page pointing at the wrong repository. Revert the name/synopsis/description/home-page back to laminar.

Quality: License header (MPL-2.0) contradicts declared license

📄 guix.scm:1 📄 guix.scm:17
Line 1 still declares SPDX-License-Identifier: MPL-2.0, but the package license field was changed to PMPL-1.0-or-later. These two statements now disagree about the license of the file/package, creating ambiguity about the actual licensing terms. Make the SPDX header and the package license field consistent (pick the intended license for laminar).

Tip

Comment Gitar fix CI to trigger a fix.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@hyperpolymath
hyperpolymath merged commit 13932b9 into main Jul 28, 2026
17 of 18 checks passed
@hyperpolymath
hyperpolymath deleted the fix/codeql-action-sha branch July 28, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant