ramanathan1504 commented on PR #4286:
URL: https://github.com/apache/logging-log4j2/pull/4286#issuecomment-5525127580

   @ppkarwasz 
   
   The same rule this PR applies to `close-stale` and `labeler` also catches 
one file that
   isn't in the diff: `.github/workflows/codeql-analysis.yaml` still declares
   
       schedule:
         - cron: '32 12 * * 5'
   
   at lines 28-29. `schedule` is only evaluated on the default branch, so that 
stanza never
   fires here either. The file itself must stay -- its `push` and 
`pull_request` triggers are
   branch-local and working -- but the `schedule:` block is dead weight, same 
as the workflows
   being removed.
   
   Worth noting the consequence before dropping it: it means the weekly CodeQL 
sweep only ever
   covers `2.x`. This branch gets CodeQL on push and PR only. If that's the 
intended posture for
   a maintenance branch, then removing the stanza just makes it explicit; if it 
isn't, the fix
   belongs on `2.x` instead. Happy either way -- flagging it since this PR is 
precisely an audit
   of which triggers fire on which branch.
   
   Minor while you're in here: the `concurrency` comment on line 31 still reads 
"pushes to 2.x
   run to completion" -- copy-paste from `2.x`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to