github / github/codeql

[Bug] Spurious `remote: error: GH013: Repository rule violations found for refs/heads/trunk.` `remote: - Code scanning is waiting for results from CodeQL for the commit`

オープン
#19,459 コメント 3 件 リアクション 1 件 担当者 0 名 GitHub で見る
false-positive
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**
```
remote: error: GH013: Repository rule violations found for refs/heads/trunk.
remote: Review all repository rules at https://github.com/SwuduSusuwu/SusuLib/rules?ref=refs%2Fheads%2Ftrunk
remote:
remote: - Code scanning is waiting for results from CodeQL for the commit 493026f.
remote:
To ssh://github.com/SwuduSusuwu/SusuLib.git
! [remote rejected] a32d469e~4 -> trunk (push declined due to repository rule violations)
error: failed to push some refs to 'ssh://github.com/SwuduSusuwu/SusuLib.git'
```

**Code samples or links to source code**
This is not related to particular source code. It happens at random when merging from continuous integration branches into `trunk`.

Have set the rules to require that all code reviews to allow to merge.
For huge pull requests, this can take over an hour (to push all of the commits to the branch in order, 1 by 1, waiting for the scans / reviews to finish after push).
- Numerous huge pull requests (which took months to produce, and over an hour just to push the individual commits in order and wait for the results after each push) [were ruined because of this](https://github.com/SwuduSusuwu/SusuLib/pull/61) (once all of the tests pass and you start to push those individual commits to `trunk`, spurious errors result in all commits pushed to `trunk` being removed from the pull request, with no possible commands to insert those back into the pull request if [branch protection of `trunk` blocks force pushes](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#about-branch-protection-rules)).

**URL to the alert on GitHub code scanning (optional)**

Irrelevant, since had to redo

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

No source files, tests, or CodeQL entry point are identified. Start by reproducing the intermittent GH013 rejection during the described CI-branch merge and examining the CodeQL and branch-protection results; done requires identifying why a completed scan is reported as pending and documenting a verifiable fix.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github
領域
ci-cd, security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
20/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。