[Bug] Spurious `remote: error: GH013: Repository rule violations found for refs/heads/trunk.` `remote: - Code scanning is waiting for results from CodeQL for the commit`
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 15時間
- マージ済み PR(30日)
- 141
説明
**Description of the false positive**
```
remote: error: GH013: Repository rule violations found for refs/heads/trunk.
remote: Review all repository rules at https://github.com/SwuduSusuwu/SusuLib/rules?ref=refs%2Fheads%2Ftrunk
remote:
remote: - Code scanning is waiting for results from CodeQL for the commit 493026f.
remote:
To ssh://github.com/SwuduSusuwu/SusuLib.git
! [remote rejected] a32d469e~4 -> trunk (push declined due to repository rule violations)
error: failed to push some refs to 'ssh://github.com/SwuduSusuwu/SusuLib.git'
```
**Code samples or links to source code**
This is not related to particular source code. It happens at random when merging from continuous integration branches into `trunk`.
Have set the rules to require that all code reviews to allow to merge.
For huge pull requests, this can take over an hour (to push all of the commits to the branch in order, 1 by 1, waiting for the scans / reviews to finish after push).
- Numerous huge pull requests (which took months to produce, and over an hour just to push the individual commits in order and wait for the results after each push) [were ruined because of this](https://github.com/SwuduSusuwu/SusuLib/pull/61) (once all of the tests pass and you start to push those individual commits to `trunk`, spurious errors result in all commits pushed to `trunk` being removed from the pull request, with no possible commands to insert those back into the pull request if [branch protection of `trunk` blocks force pushes](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#about-branch-protection-rules)).
**URL to the alert on GitHub code scanning (optional)**
Irrelevant, since had to redo
コントリビューションガイド
調査の方向性
No source files, tests, or CodeQL entry point are identified. Start by reproducing the intermittent GH013 rejection during the described CI-branch merge and examining the CodeQL and branch-protection results; done requires identifying why a completed scan is reported as pending and documenting a verifiable fix.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github
- 領域
- ci-cd, security
- issue の種類
- バグ
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 20/100