Skip to content

Add CodeQL workflow with path exclusions for generated files - #3128

Merged
turbomam merged 2 commits into
mainfrom
codeql-exclude-generated-files
Jun 5, 2026
Merged

turbomam merged 2 commits into
mainfrom
codeql-exclude-generated-files

Conversation

@turbomam

@turbomam turbomam commented Jun 4, 2026

Copy link
Copy Markdown
Member

Adds .github/codeql/codeql-config.yml and .github/workflows/codeql.yml to exclude generated artifacts from CodeQL scanning.

The generated files account for about 892 of the 903 current Standard findings:

  • 504 "First parameter not named self" in nmdc_schema/nmdc_pydantic.py — these are Pydantic v2 @field_validator methods that correctly use cls; CodeQL treats them as regular instance methods.
  • ~380 "Implicit string concatenation in a list" across nmdc_schema/nmdc_pydantic.py and nmdc_schema/nmdc.py — linkml's pydanticgen wraps long description strings across lines without +, which is intentional.

Migrator partials are also excluded; they are versioned snapshots of released migrations and should not be retroactively edited for style.

Closes #3040

Excludes nmdc_schema/nmdc.py, nmdc_schema/nmdc_pydantic.py, and
nmdc_schema/migrators/partials/** from CodeQL scanning.

The generated files account for ~892 of 903 Standard findings:
504 'not-named-self' (pydantic @field_validator methods correctly use
cls) and ~380 'implicit string concatenation' from long description
strings wrapped by linkml's pydanticgen. Migrator partials are
versioned snapshots of released migrations.

Closes #3040

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 4, 2026 18:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@github-actions

github-actions Bot commented Jun 4, 2026 •

Copy link
Copy Markdown
PR Preview Action v1.8.1

QR code for preview link

🚀 View preview at
https://microbiomedata.github.io/nmdc-schema/pr-preview/pr-3128/

Built to branch gh-pages at 2026-06-05 13:26 UTC.
Preview will be ready when the GitHub Pages deployment is complete.

GitHub's default code scanning setup reads .github/codeql/codeql-config.yml
automatically. Adding an explicit codeql.yml workflow caused a SARIF upload
conflict because both tried to upload results under the same category
(/language:python).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@turbomam
turbomam merged commit 47286be into main Jun 5, 2026
8 checks passed
@turbomam
turbomam deleted the codeql-exclude-generated-files branch June 5, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CodeQL: high-volume Python findings dominated by generated artifacts

2 participants