Skip to content

feat(security): add CodeQL analysis and pre-release version gate #201

feat(security): add CodeQL analysis and pre-release version gate

feat(security): add CodeQL analysis and pre-release version gate #201

Triggered via pull request April 9, 2026 18:08
Status Success
Total duration 54s
Artifacts

self-pr-validation.yml

on: pull_request
validation  /  Blocking Checks
10s
validation / Blocking Checks
YAML Lint
6s
YAML Lint
Action Lint
11s
Action Lint
Pinned Actions Check
5s
Pinned Actions Check
Markdown Link Check
15s
Markdown Link Check
Spelling Check
6s
Spelling Check
Shell Check
5s
Shell Check
README Check
5s
README Check
Composite Schema Lint
5s
Composite Schema Lint
CodeQL Analysis
42s
CodeQL Analysis
validation  /  Advisory Checks
11s
validation / Advisory Checks
validation  /  PR Checks Summary
5s
validation / PR Checks Summary
validation  /  ...  /  Send Notification
9s
validation / Notify / Send Notification
Fit to window
Zoom out
Zoom in

Annotations

8 warnings and 1 notice
Pinned Actions Check
Found 5 internal action(s) not pinned to a version. Consider pinning to vX.Y.Z.
Pinned Actions Check: .github/workflows/pr-security-scan.yml#L291
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-reporter@feat/pr-security-scan-codeql-prerelease
Pinned Actions Check: .github/workflows/pr-security-scan.yml#L284
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-analyze@feat/pr-security-scan-codeql-prerelease
Pinned Actions Check: .github/workflows/pr-security-scan.yml#L265
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-init@feat/pr-security-scan-codeql-prerelease
Pinned Actions Check: .github/workflows/pr-security-scan.yml#L258
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/codeql-config@feat/pr-security-scan-codeql-prerelease
Pinned Actions Check: .github/workflows/pr-security-scan.yml#L213
Internal action not pinned to a version: uses: LerianStudio/github-actions-shared-workflows/src/security/prerelease-check@feat/pr-security-scan-codeql-prerelease
CodeQL Analysis
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
CodeQL Analysis
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
validation / Advisory Checks
PR size: M (375 lines changed)