Skip to content

ci: Explicit codeql workflow#2202

Open
thompson-tomo wants to merge 4 commits into
open-telemetry:mainfrom
thompson-tomo:patch-1
Open

ci: Explicit codeql workflow#2202
thompson-tomo wants to merge 4 commits into
open-telemetry:mainfrom
thompson-tomo:patch-1

Conversation

@thompson-tomo
Copy link
Copy Markdown
Contributor

@thompson-tomo thompson-tomo commented Apr 11, 2026

This adds an explicit codeql Workflow to ensure it runs on all pr's/commits as currently alot is being missed.

This will need someone to enable advanced codeql -> https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-advanced-setup-for-code-scanning

This enable sent has already been done to numerous otel repos see https://github.com/search?q=org%3Aopen-telemetry+codeql-Action%2FInit+language%3AYAML+path%3A%2F%5E%5C.github%5C%2Fworkflows%5C%2F%2F&type=code

@arielvalentin
Copy link
Copy Markdown
Contributor

@trask do we have standard workflows that are centrally defined like codeql that should be run in every repo?

If so, should that be provisioned though terraform instead of on a repo by repo basis?

@trask
Copy link
Copy Markdown
Member

trask commented May 5, 2026

hey @arielvalentin! are you asking about provisioning the codeql repo settings? or the codeql yml?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants