Skip to content

Allow independent updates of codeql-action/init and analyze #4013

Description

@brawer

Currently, codeql-action/init and analyze expect to be running at the exact same version. Please make this more resilient to slight version drift, so the two components can be updated separately from each other.

At the moment, codeql-action has a Dependabot Compatibility Score of only 2%. This literally means that 98% of customer projects currently see pipeline-breaking pull requests — for each and every CodeQL release. Many projects require all test pipelines to pass before merging a pull request. However, with CodeQL’s current releases, Dependabot sends two pull requests that depend on each other (examples: brawer/osmdiffs#379 and brawer/osmdiffs#380). While project maintainers can bypass their automated checks, the current mutual dependency of independently released CodeQL components causes mental load to project maintainers.

To become more resilient, perhaps you could change codeql-action/init to emit config files that also work with the past ~3 versions of codeql/analyze. Alternatively, perhaps you could change codeql/analyze to accept config files produced by newer versions of codeql/init; for this, you might want to add a “minimum required codeql-analyze version” field (or so) to your internal file format.

Whatever your technical solution ends up being, huge thanks for fixing this. The 98% of Dependabot/CodeQL users whose projects you’re currently breaking with every CodeQL release will be eternally grateful. :-)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions