Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,17 @@ Actions with special purposes and unlikely to be used directly:

All advanced setup code scanning workflows must have the `security-events: write` permission. Workflows in private repositories must additionally have the `contents: read` permission. For more information, see "[Assigning permissions to jobs](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs)."

### Skipping analysis during pull request iteration

The `init` action supports two opt-in inputs, both disabled by default:

- `skip-if-draft: true` skips analysis when the pull request event confirms that the PR is a draft. Include `ready_for_review` in the workflow's `pull_request.types` so analysis runs when the PR becomes ready. Confirmed draft skips return before repository configuration lookups, status reporting, tool download, or database initialization.
- `skip-if-no-language-changes: true` skips a single explicitly selected built-in language only when a complete comparison of the PR event's immutable commit SHAs contains exclusively recognized non-code paths. Source files, workflows, build and dependency configuration, shell scripts, unknown paths, incomplete comparisons, and API errors retain full analysis. This is a conservative path heuristic; leave it disabled when documentation or other allowed non-code files are inputs to code generation.

For example, include `types: [opened, synchronize, reopened, ready_for_review]` under `on.pull_request`, assign an `id` to the `init` step, and enable the desired inputs. The `analysis-skipped` and `analysis-skip-reason` outputs describe the decision. Guard custom build steps with `if: steps.init.outputs.analysis-skipped != 'true'`. The `autobuild`, `analyze`, and post actions handle intentional skips automatically. When analysis runs, it still uses the complete language database rather than analyzing only changed files.

GitHub-managed workflows require integration by their workflow generator to provide the inputs and draft metadata. These inputs do not configure managed Code Quality from a repository workflow file.

### Build Modes

The CodeQL Action supports different build modes for analyzing the source code. The available build modes are:
Expand Down
4 changes: 4 additions & 0 deletions analyze/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,10 @@ outputs:
description: Absolute, local path to the directory containing the generated SARIF file.
sarif-id:
description: The ID of the uploaded SARIF file.
analysis-skipped:
description: Whether analysis was intentionally skipped before CodeQL finalization
analysis-skip-reason:
description: Why analysis was intentionally skipped, if applicable
runs:
using: node24
main: "../lib/analyze-entry.js"
Expand Down
22 changes: 22 additions & 0 deletions init/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,24 @@ inputs:
For more information, see
https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#changing-the-languages-that-are-analyzed.
required: false
skip-if-draft:
description: >-
When true and the current event confirms this is a draft pull request, skip CodeQL before
downloading tools or initializing a database. The workflow must run again on `ready_for_review`
to analyze the PR once it is marked ready. For a `dynamic` workflow, the workflow generator can
set `CODE_SCANNING_IS_DRAFT=true` to trigger the same early skip. If draft state is unavailable,
analysis continues.
required: false
default: 'false'
skip-if-no-language-changes:
description: >-
When true for a single explicitly requested built-in language, skip CodeQL before tool download
and database initialization if the complete pull-request diff contains no relevant source or
language configuration files. Unknown, incomplete, or unrecognized diffs fail open and run the
full analysis. This uses the complete language database when relevant changes exist; it does
not restrict analysis to changed files.
required: false
default: 'false'
build-mode:
description: >-
The build mode that will be used to analyze the language. This input is only available when
Expand Down Expand Up @@ -176,6 +194,10 @@ outputs:
description: The path of the CodeQL binary used for analysis
codeql-version:
description: The version of the CodeQL binary used for analysis
analysis-skipped:
description: Whether analysis was intentionally skipped before CodeQL initialization
analysis-skip-reason:
description: Why analysis was intentionally skipped, if applicable
runs:
using: node24
main: '../lib/init-entry.js'
Expand Down
Loading