FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Don't upload the ESLint SARIF from merge queue refs by henrymercer · Pull Request #4125 · github/codeql-action · GitHub

Repository navigation

Don't upload the ESLint SARIF from merge queue refs - #4125

Merged
henrymercer merged 1 commit into
mainfrom
henrymercer/merge-queue-sarif-upload-flake
Sep 4, 2026
Merged

henrymercer merged 1 commit into
mainfrom
henrymercer/merge-queue-sarif-upload-flake

Conversation

Copy link
Copy Markdown
Contributor

The Unit Tests job uploads its ESLint SARIF via upload-sarif, gated only on OS and Node version. PR Checks runs on merge_group, and also on push for the gh-readonly-queue branch that the merge queue creates, so in both cases the upload targets a ref that GitHub deletes as soon as the queue entry resolves. When the upload loses that race the code scanning API returns 404 and the step fails.

This accounts for every merge queue failure of PR Checks in the visible run history — five of them, going back to May.

Gate the step on the ref rather than the event, since both the merge_group run and the paired push run use the ephemeral ref. Nothing is lost: alerts on a queue ref are never surfaced, and the same results are uploaded by the pull_request run and again by the push run on main.

codeql.yml already skips its uploads for merge queue runs. It only needs the event check because its push trigger is limited to main and releases/v*.

Lint enforcement is unaffected — lint-ci still fails the job on any lint error. Only the alert upload is skipped.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
henrymercer requested a balanced review from Copilot September 4, 2026 16:23
github-actions Bot added the size/XS Should be very easy to review label Sep 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Copilot review overview

🟢 Approval recommended

The focused workflow change has no unresolved issues.

Review tier: Balanced
Findings: None

What changed in this PR

Prevents transient merge-queue failures by skipping ESLint SARIF uploads for ephemeral queue refs.

Changes:

  • Adds a ref-based guard for gh-readonly-queue refs.
  • Documents coverage of merge-group and paired push runs.
File Description
.github/​workflows/​pr-checks.yml Skips ESLint SARIF uploads from merge-queue refs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

henrymercer marked this pull request as ready for review September 4, 2026 16:27
henrymercer requested a review from a team as a code owner September 4, 2026 16:27

mbg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Good observation. Thanks for noticing and fixing it! The fix looks sensible to me.

henrymercer added this pull request to the merge queue Sep 4, 2026
Merged via the queue into main with commit e06b60f Sep 4, 2026
225 checks passed
henrymercer deleted the henrymercer/merge-queue-sarif-upload-flake branch September 4, 2026 16:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Should be very easy to review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL