Skip to content

QL4QL: Install CodeQL with setup-codeql rather than init - #22777

Merged
henrymercer merged 3 commits into
mainfrom
henrymercer/fix-workflow-per-language-bundles
Oct 7, 2026
Merged

henrymercer merged 3 commits into
mainfrom
henrymercer/fix-workflow-per-language-bundles

Conversation

@henrymercer

@henrymercer henrymercer commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

The QL for QL workflows ran the init Action with a placeholder languages: javascript input just to get a CodeQL CLI. With per-language bundles, the Action can download a JavaScript-only bundle for that input. This bundle doesn't contain the YAML extractor that the QL extractor uses in pre-finalize.sh and qltest.sh, so the build fails with "There's no CodeQL extractor named 'yaml' installed" (example).

This uses the setup-codeql Action instead, which only installs the CLI and always uses the bundle that contains all languages. Since init no longer runs:

  • On PRs, the uploaded QL for QL results are no longer filtered to the lines the PR changes. This is fine as they will be filtered by the code scanning UI.
  • CODEQL_THREADS is no longer set, so this passes --threads=0 to codeql database create and codeql test run instead. When creating the database, this gives the QL extractor all cores as before and also parallelises TRAP import, which dropped from about 40s to 8s in my test runs. When running tests, it parallelises query evaluation, but doesn't reach the test extractor, which now uses one thread fewer than the number of cores.

This also removes the redundant CODEQL_THREADS setting from the database stats workflow. I checked locally that its --threads 4 argument to codeql database create already gives the extractor the same value.

I tested this on a branch with CODEQL_ACTION_PER_LANGUAGE_BUNDLES=true, which makes the build and test workflows fail without this change. With this change, all three workflows passed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused replacements preserve CLI-path compatibility and provide the required extractors, with no unresolved findings.

Review effort: Balanced
Findings: None

What changed in this PR

Updates QL-for-QL workflows to install the complete CodeQL bundle, ensuring the required YAML extractor is available.

Changes:

  • Replaces init with setup-codeql and removes placeholder JavaScript inputs.
  • Preserves nightly tooling for build and test workflows.
File Description
.github/​workflows/​ql-for-ql-tests.yml Switches both test jobs to CLI-only setup.
.github/​workflows/​ql-for-ql-dataset_measure.yml Switches dataset measurement to CLI-only setup.
.github/​workflows/​ql-for-ql-build.yml Switches the build workflow to CLI-only setup.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

henrymercer and others added 2 commits October 7, 2026 12:46
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ats workflow

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment on lines -20 to -21
env:
CODEQL_THREADS: 4 # TODO: remove this once it's set by the CLI

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is indeed now set by the CLI.

@henrymercer
henrymercer marked this pull request as ready for review October 7, 2026 12:26
@henrymercer
henrymercer requested a review from a team as a code owner October 7, 2026 12:26

@mbg mbg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These changes look good to me from a CodeQL Action / CLI perspective, but it might be good for someone more familiar with these workflows to have a look over this as well.

In particular, I saw that there's some caching going on ("Cache entire extractor" step) and it's not immediately obvious to me whether that is restoring some cached that would otherwise require a full init step to generate. Have you tried a test run with that step removed?

- name: Find codeql
id: find-codeql
uses: github/codeql-action/init@main
uses: github/codeql-action/setup-codeql@main

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice to see setup-codeql here! Is there a good reason that this was pinned to main? Should we move that to a tag or sha while we are here? (Same question for other instances of this.)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's pointing to main to get some internal testing in case we can pick up some bugs before they get released. We can pin it, but perhaps it makes more sense to do that consistently across the other Actions too in a separate PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[..] but perhaps it makes more sense to do that consistently across the other Actions too in a separate PR.

Sure, that's fair.

@henrymercer

Copy link
Copy Markdown
Contributor Author

In particular, I saw that there's some caching going on ("Cache entire extractor" step) and it's not immediately obvious to me whether that is restoring some cached that would otherwise require a full init step to generate. Have you tried a test run with that step removed?

Good idea, I triggered each of the workflows with the caching steps removed:

@mbg mbg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for running all the workflows without caching! Pretty happy to approve on that basis 👍🏻

@henrymercer
henrymercer merged commit 0490821 into main Oct 7, 2026
9 checks passed
@henrymercer
henrymercer deleted the henrymercer/fix-workflow-per-language-bundles branch October 7, 2026 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants