github / github/codeql

CodeQL detected code written in `some language`, but not any written in GitHub Actions. Confirm that there is some source code for GitHub Actions in the project.

Offen
#20,102 4 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

While investigating another problem involving CodeQL, I switched from the default setup to the advanced setup. This resulted in the creation of a [`.github/workflows/codeql.yml`](https://github.com/user-attachments/files/21353129/codeql.yml.txt).

Later, I switched back to the default setup, but found it impossible to push a commit that removed the `codeql.yml` because

> Error: Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.22.1/x64/codeql/codeql database finalize --finalize-dataset --threads=8 --ram=29878 /home/runner/work/_temp/codeql_databases/actions". Exit code was 32 and last log line was: CodeQL detected code written in JavaScript/TypeScript, but not any written in GitHub Actions. Confirm that there is some source code for GitHub Actions in the project. For more information, review our troubleshooting guide at https://gh.io/troubleshooting-code-scanning/no-source-code-seen-during-build . See the logs for more details.

Look, I don't want to confirm that there is some source code for GitHub Actions. I want to reassure CodeQL that there is no source code for GitHub Actions and everything is A-OK. Based on the troubleshooting guide, I set `strategy.matrix.language` to `['javascript-typescript']`, but of course this had no effect because CodeQL was now operating in default mode and ignoring the configuration.

Switching back to advanced mode should work, right? Nope, it tried to create another `codeql.yml`, and that failed because

> There was an error committing your changes: A file with the same name already exists. Please choose a different name and try again.

Now CodeQL is not working at all, so there's no way to merge anything into the main branch.

What's the right way to remove `codeql.yml` and reset CodeQL to default mode? How would one rescue this seemingly broken CodeQL setup?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the attached .github/workflows/codeql.yml and compare it with the repository's current default and advanced CodeQL setup. Read the linked CodeQL troubleshooting guide and inspect the workflow logs to understand why the actions database is still finalized. Done means CodeQL is restored to the intended setup and the main branch can merge without this failure.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github-actions, yaml
Bereich
ci-cd, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.