codeant-ai-for-open-source[bot] commented on code in PR #44699:
URL: https://github.com/apache/superset/pull/44699#discussion_r4111684419
##########
.github/workflows/codeql-analysis.yml:
##########
@@ -66,18 +65,38 @@ jobs:
persist-credentials: false
# Initializes the CodeQL tools for scanning.
- - name: Initialize CodeQL
+ - name: Initialize CodeQL (python)
+ if: needs.changes.outputs.python == 'true'
uses:
github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
- languages: ${{ matrix.language }}
+ languages: python
Review Comment:
✅ **CodeAnt verified this suggestion was addressed in subsequent commits and
marked this thread resolved** as of `9c88534`.
CodeQL initialization now uses `matrix.language`, so each matrix job scans
only its assigned language. The analysis category also uses the same matrix
value.
<sub>If that's not right, unresolve this thread and CodeAnt will leave it
open.</sub>
<!-- codeant-auto-resolve-reply -->
##########
.github/workflows/codeql-analysis.yml:
##########
@@ -66,18 +65,38 @@ jobs:
persist-credentials: false
# Initializes the CodeQL tools for scanning.
- - name: Initialize CodeQL
+ - name: Initialize CodeQL (python)
+ if: needs.changes.outputs.python == 'true'
uses:
github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
- languages: ${{ matrix.language }}
+ languages: python
# If you wish to specify custom queries, you can do so here or in a
config file.
# By default, queries listed here will override any specified in a
config file.
# Prefix the list here with "+" to use these queries and those in
the config file.
# For more details on CodeQL's query packs, refer to:
https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality
- - name: Perform CodeQL Analysis
+ - name: Initialize CodeQL (javascript)
+ if: needs.changes.outputs.frontend == 'true'
+ uses:
github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ with:
+ languages: javascript
+ # If you wish to specify custom queries, you can do so here or in a
config file.
+ # By default, queries listed here will override any specified in a
config file.
+ # Prefix the list here with "+" to use these queries and those in
the config file.
+
+ # For more details on CodeQL's query packs, refer to:
https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
+ # queries: security-extended,security-and-quality
+
+ - name: Perform CodeQL Analysis (python)
+ if: needs.changes.outputs.python == 'true'
+ uses:
github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
+ with:
+ category: "/language:python"
+
+ - name: Perform CodeQL Analysis (javascript)
+ if: needs.changes.outputs.python == 'true'
uses:
github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
- category: "/language:${{matrix.language}}"
+ category: "/language:javascript"
Review Comment:
✅ **CodeAnt verified this suggestion was addressed in subsequent commits and
marked this thread resolved** as of `9c88534`.
The language-specific Python condition is gone. Initialization and analysis
now run per `matrix.language`, allowing JavaScript and Python changes to be
analyzed independently.
<sub>If that's not right, unresolve this thread and CodeAnt will leave it
open.</sub>
<!-- codeant-auto-resolve-reply -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]