Skip to content

CodeQL efficacy: un-dark check_codeql_language_matrix_mismatch + add effective-SAST rule #261

Description

@hyperpolymath

Refs #260 (do not auto-close).

Defect: WorkflowAudit.check_codeql_language_matrix_mismatch is gated Keyword.get(opts, :has_codeql_supported_language, true) — defaults true, so it is a silent no-op. ScorecardIngestor.check_sast only greps for the string codeql (presence, not efficacy). modshells alert #72: codeql.yml matrix was javascript-typescript on an Ada/Scheme repo → 0 results recorded.

Fix:

  • Compute has_codeql_supported_language from repo linguist/file extensions by default; absence of a scannable language is the trigger, not silence.
  • Add a paired effective-SAST rule: finding when codeql.yml language matrix ∌ any language the repo contains AND ∌ actions.
  • Canonical remediation: language: actions (always scannable; runs every commit).

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaves incorrectlyelixirPull requests that update elixir codemajorLoad-bearing / requirements-level workrequirements-targetTracks a requirement; PRs Refs not Closes; joint-close only

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions