Skip to content

Run CI and CodeQL in a merge queue - #168

Closed
squarepots wants to merge 1 commit into
mainfrom
ci/merge-queue
Closed

squarepots wants to merge 1 commit into
mainfrom
ci/merge-queue

Conversation

@squarepots

Copy link
Copy Markdown
Member

What changed

  • CI (ci.yml):
    • runs on merge_group;
    • a queue entry runs every source job regardless of paths, because its commit is the one that becomes main;
    • git diff --check uses the queue's base and head;
    • dependency review stays on pull requests only, since a queued combination adds no dependency that its pull requests did not.
  • CodeQL (codeql.yml): a repository workflow replaces CodeQL default setup:
    • it runs on pull requests, merge-queue entries, main pushes, and weekly;
    • it keeps the same languages (Actions, JavaScript/TypeScript, Rust), the default query suite, build-mode: none, and the /language:<lang> categories, so existing alerts carry over;
    • it keeps the required check names Analyze (actions), Analyze (javascript-typescript), and Analyze (rust);
    • the CodeQL action is pinned to v4.38.2 by full SHA, like the other Actions.
  • docs/testing.md: describes the queue run and the CodeQL workflow, and that default setup must stay off.

Why

With "require branches to be up to date", every merge forced the other open pull requests to update and re-run all checks. A merge queue tests each queued pull request on top of the current main and the entries ahead of it, then merges that exact commit, without manual updates.

CodeQL default setup does not analyze merge_group commits, so its required Analyze (...) checks would never report in the queue and every entry would stall. That is the reason for the workflow (see, for example, kamp-us/phoenix#3369).

Rollout

This stays a draft until default setup is off. While default setup is on, GitHub rejects this workflow's results, so its Analyze jobs fail here.

  1. Land Refresh quota when it can have changed #163–Remove repeated dialog copy #166 first; they still need default setup's checks.
  2. The maintainer turns off CodeQL default setup: Settings → Code security → CodeQL analysis.
  3. Re-run this pull request's CodeQL jobs, confirm all three Analyze checks pass from the workflow, and merge.
  4. Add the merge queue to the Protect main ruleset (squash, ALLGREEN, build concurrency 2, merge 1 entry at a time, 60-minute timeout) and read it back. "Require branches to be up to date" stays off.
  5. Acceptance: queue the pull-request-scope change, which will be behind main, and confirm it merges without updating its branch.

Rollback: remove the queue rule, turn default setup back on, and revert this pull request.

Validation

  • Both workflow files parse as YAML. This pull request's own CI run exercises the edited ci.yml across all platforms.
  • The merge_group path can only run once the queue is enabled; step 5 is its real check.

Remaining

Steps 2–5 above.

Main required every pull request to be up to date before merging, so landing several pull requests meant updating each branch and re-running every check after each merge. A merge queue tests the queued pull request on top of the current main and the entries ahead of it, then merges that exact commit, without manual updates.

CI now runs on merge_group events and runs every source job for a queue entry, since its commit becomes main. CodeQL moves from default setup to a repository workflow, because default setup does not analyze merge-queue commits and its required Analyze checks would stay pending in the queue. The workflow keeps the same languages, default query suite, analysis categories, and check names, and also runs on pull requests, main pushes, and weekly. Default setup must be turned off for the workflow's results to be accepted.
@squarepots

Copy link
Copy Markdown
Member Author

Closing under the maintainer-approved decision to defer the merge queue and retain CodeQL default setup with the existing required checks. The current main ruleset does not require branches to be up to date. #167 has merged independently and is no longer a merge-queue acceptance case. The CI and CodeQL migration proposed here will not be applied.

@squarepots squarepots closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant