Skip to content

codeql: preserve base/head configuration identity for PR differential analysis #2133

Description

@seonghobae

Fresh consumer evidence

Wardnet PR ContextualWisdomLab/wardnet#129 current exact head 2cedf7098723cd12f59125e72f4354226165a112 completed its central current-head CodeQL dispatch successfully (Dispatch current-head CodeQL scan, job 103602823188, completed 2026-09-12T18:46:14Z). The same exact head still has GitHub Advanced Security CodeQL comparison check 103602491771 terminal neutral with title 1 configuration not found and this warning:

Code scanning cannot determine the alerts introduced by this pull request, because 1 configuration present on refs/heads/main was not found.

Missing configuration reported by GHAS: Default setup /language:rust.

Protected Wardnet base is main@f8260f1e03836039ff9463dd99fa982e4e270c4b. This means the current PR security path can execute/dispatch CodeQL while GHAS still cannot establish one compatible base/head CodeQL configuration identity for introduced-alert analysis. Treat that as incomplete security evidence, not a clean CodeQL comparison and not as consumer source debt.

Ownership boundary

The organization-central CodeQL producer/handler/settlement layer owns cross-repository CodeQL execution/evidence identity. Do not copy CodeQL workflows into Wardnet, disable Default Setup as a leaf workaround, weaken branch protection, synthesize statuses, or reinterpret a neutral comparison as GREEN.

This should be coordinated with #1929 and the active #2040/#2106 settlement stack. If those changes already supply the canonical fix, use this issue as the explicit GHAS configuration-identity acceptance gap rather than introducing a second producer/handler authority.

RED → GREEN acceptance

  • For a PR exact head whose protected base has a Rust CodeQL configuration, the current-head analysis is published under a configuration identity that GHAS can pair with the protected-base configuration for introduced-alert computation.
  • Exact unchanged-head canary has no 1 configuration not found / Default setup /language:rust warning and no neutral result caused by configuration discontinuity.
  • Preserve immutable target repository, base SHA, head SHA, language, workflow/run identity, SARIF attribution, and terminal-receipt binding from the canonical CodeQL stack.
  • Preserve current severity/gate semantics, immutable workflow/action pins, least privilege, and fail-closed behavior. No leaf-side custom workflow copy and no status fabrication.
  • Add an executable contract/fixture covering the configuration identity expected by GHAS, including a negative case where base and head use incompatible/missing configuration identities.
  • After protected central integration, verify on unchanged Wardnet 🧪 테스트 개선: parse_conflict_reason 함수 단위 테스트 추가 #129 exact head (or an equivalent Rust consumer canary) that GHAS can calculate introduced alerts and that the canonical central CodeQL terminal proof is still exact-head bound.

Search found no existing .github issue matching the exact Code scanning cannot determine the alerts introduced warning. Keep this issue distinct from scan execution success: dispatch completion alone does not satisfy differential-analysis evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions