Run CI and CodeQL in a merge queue - #168
Closed
squarepots wants to merge 1 commit into
Closed
squarepots wants to merge 1 commit into
squarepots wants to merge 1 commit into
Conversation
Main required every pull request to be up to date before merging, so landing several pull requests meant updating each branch and re-running every check after each merge. A merge queue tests the queued pull request on top of the current main and the entries ahead of it, then merges that exact commit, without manual updates. CI now runs on merge_group events and runs every source job for a queue entry, since its commit becomes main. CodeQL moves from default setup to a repository workflow, because default setup does not analyze merge-queue commits and its required Analyze checks would stay pending in the queue. The workflow keeps the same languages, default query suite, analysis categories, and check names, and also runs on pull requests, main pushes, and weekly. Default setup must be turned off for the workflow's results to be accepted.
Member
Author
|
Closing under the maintainer-approved decision to defer the merge queue and retain CodeQL default setup with the existing required checks. The current main ruleset does not require branches to be up to date. #167 has merged independently and is no longer a merge-queue acceptance case. The CI and CodeQL migration proposed here will not be applied. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
ci.yml):merge_group;main;git diff --checkuses the queue's base and head;codeql.yml): a repository workflow replaces CodeQL default setup:mainpushes, and weekly;build-mode: none, and the/language:<lang>categories, so existing alerts carry over;Analyze (actions),Analyze (javascript-typescript), andAnalyze (rust);docs/testing.md: describes the queue run and the CodeQL workflow, and that default setup must stay off.Why
With "require branches to be up to date", every merge forced the other open pull requests to update and re-run all checks. A merge queue tests each queued pull request on top of the current
mainand the entries ahead of it, then merges that exact commit, without manual updates.CodeQL default setup does not analyze
merge_groupcommits, so its requiredAnalyze (...)checks would never report in the queue and every entry would stall. That is the reason for the workflow (see, for example, kamp-us/phoenix#3369).Rollout
This stays a draft until default setup is off. While default setup is on, GitHub rejects this workflow's results, so its
Analyzejobs fail here.Analyzechecks pass from the workflow, and merge.Protect mainruleset (squash, ALLGREEN, build concurrency 2, merge 1 entry at a time, 60-minute timeout) and read it back. "Require branches to be up to date" stays off.main, and confirm it merges without updating its branch.Rollback: remove the queue rule, turn default setup back on, and revert this pull request.
Validation
ci.ymlacross all platforms.merge_grouppath can only run once the queue is enabled; step 5 is its real check.Remaining
Steps 2–5 above.