From c05e4456966d95a9899fe19d6f0dddcba28231f9 Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Mon, 24 Aug 2026 18:32:04 +0100 Subject: [PATCH 1/8] Report tools download durations on both download paths The streaming path reported no timings at all, so we have no data for the path that most runs take. It now reports a total duration, which is also populated on the download-then-extract path. That path additionally reports the extraction duration, which was previously computed but only logged. `downloadDurationMs` keeps its existing meaning of time spent downloading alone, so existing telemetry stays comparable. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 628ce334-991a-4578-9c1b-93d2e96bbddb --- src/setup-codeql.test.ts | 2 ++ src/tools-download.test.ts | 11 ++++++++--- src/tools-download.ts | 33 +++++++++++++++++++++++++-------- 3 files changed, 35 insertions(+), 11 deletions(-) diff --git a/src/setup-codeql.test.ts b/src/setup-codeql.test.ts index 219e39984..a41c24ac4 100644 --- a/src/setup-codeql.test.ts +++ b/src/setup-codeql.test.ts @@ -234,6 +234,7 @@ test.serial( codeqlFolder: "codeql", statusReport: { downloadDurationMs: 200, + totalDurationMs: 300, }, toolsVersion: LINKED_CLI_VERSION.cliVersion, }); @@ -286,6 +287,7 @@ test.serial( codeqlFolder: "codeql", statusReport: { downloadDurationMs: 200, + totalDurationMs: 300, }, toolsVersion: expectedVersion, }); diff --git a/src/tools-download.test.ts b/src/tools-download.test.ts index 66fe0e72e..d2f15f4dc 100644 --- a/src/tools-download.test.ts +++ b/src/tools-download.test.ts @@ -15,7 +15,7 @@ import { withTmpDir } from "./util"; setupTests(test); test.serial( - "downloadAndExtract reports the duration when downloading before extracting", + "downloadAndExtract reports the durations when downloading before extracting", async (t) => { await withTmpDir(async (tmpDir) => { const archivePath = path.join(tmpDir, "codeql-bundle.tar.gz"); @@ -34,6 +34,8 @@ test.serial( ); t.assert(Number.isInteger(statusReport.downloadDurationMs)); + t.assert(Number.isInteger(statusReport.extractionDurationMs)); + t.assert(Number.isInteger(statusReport.totalDurationMs)); }); }, ); @@ -67,6 +69,7 @@ test.serial( ); t.assert(Number.isInteger(statusReport.downloadDurationMs)); + t.assert(Number.isInteger(statusReport.totalDurationMs)); t.true(request.isDone()); t.false(extractTarZst.called); t.true(downloadTool.calledOnce); @@ -76,7 +79,7 @@ test.serial( ); test.serial( - "downloadAndExtract omits the download duration when streaming extraction", + "downloadAndExtract reports only the total duration when streaming extraction", async (t) => { await withTmpDir(async (tmpDir) => { sinon.stub(process, "platform").value("linux"); @@ -106,7 +109,9 @@ test.serial( getRunnerLogger(true), ); - t.deepEqual(statusReport, {}); + t.assert(Number.isInteger(statusReport.totalDurationMs)); + t.is(statusReport.downloadDurationMs, undefined); + t.is(statusReport.extractionDurationMs, undefined); t.false(downloadTool.called); t.true(extractTarZst.calledOnce); t.true(request.isDone()); diff --git a/src/tools-download.ts b/src/tools-download.ts index 9b2fa8723..d7a978908 100644 --- a/src/tools-download.ts +++ b/src/tools-download.ts @@ -31,7 +31,21 @@ const STREAMING_STALL_TIMEOUT_MS = 5 * 60 * 1000; // 5 minutes const TOOLCACHE_TOOL_NAME = "CodeQL"; export type ToolsDownloadStatusReport = { + /** + * Time spent downloading the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently, since the two cannot be told apart. + */ downloadDurationMs?: number; + /** + * Time spent extracting the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently, since the two cannot be told apart. + */ + extractionDurationMs?: number; + /** + * Total time taken to make the bundle available on disk, in milliseconds. This includes any time + * spent on a streaming attempt that failed and fell back to downloading before extracting. + */ + totalDurationMs: number; }; export async function downloadAndExtract( @@ -47,11 +61,12 @@ export async function downloadAndExtract( `Downloading CodeQL tools from ${codeqlURL} . This may take a while.`, ); + const startTime = performance.now(); + try { if (compressionMethod === "zstd" && process.platform === "linux") { logger.info(`Streaming the extraction of the CodeQL bundle.`); - const toolsInstallStart = performance.now(); await downloadAndExtractZstdWithStreaming( codeqlURL, dest, @@ -61,16 +76,14 @@ export async function downloadAndExtract( logger, ); - const combinedDurationMs = Math.round( - performance.now() - toolsInstallStart, - ); + const totalDurationMs = Math.round(performance.now() - startTime); logger.info( `Finished downloading and extracting CodeQL bundle to ${dest} (${formatDuration( - combinedDurationMs, + totalDurationMs, )}).`, ); - return {}; + return { totalDurationMs }; } } catch (e) { core.warning( @@ -98,7 +111,7 @@ export async function downloadAndExtract( )}).`, ); - let extractionDurationMs: number; + let extractionDurationMs: number | undefined; try { logger.info("Extracting CodeQL bundle."); @@ -120,7 +133,11 @@ export async function downloadAndExtract( await cleanUpPath(archivedBundlePath, "CodeQL bundle archive", logger); } - return { downloadDurationMs }; + return { + downloadDurationMs, + extractionDurationMs, + totalDurationMs: Math.round(performance.now() - startTime), + }; } async function downloadAndExtractZstdWithStreaming( From bee82de8ba4472941ae3a399ce0e402e30f0cdb4 Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Mon, 24 Aug 2026 18:32:08 +0100 Subject: [PATCH 2/8] Add tools download durations to the init status report Surface `tools_extraction_duration_ms` and `tools_total_duration_ms` from both the `init` and `setup-codeql` actions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 628ce334-991a-4578-9c1b-93d2e96bbddb --- src/init-action.ts | 8 ++++++++ src/setup-codeql-action.ts | 8 ++++++++ src/status-report.ts | 15 ++++++++++++++- 3 files changed, 30 insertions(+), 1 deletion(-) diff --git a/src/init-action.ts b/src/init-action.ts index 6b5ed392e..8173d67aa 100644 --- a/src/init-action.ts +++ b/src/init-action.ts @@ -174,6 +174,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== undefined) { + initToolsDownloadFields.tools_extraction_duration_ms = + toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== undefined) { + initToolsDownloadFields.tools_total_duration_ms = + toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/setup-codeql-action.ts b/src/setup-codeql-action.ts index 7873449f9..bb6b73c9a 100644 --- a/src/setup-codeql-action.ts +++ b/src/setup-codeql-action.ts @@ -85,6 +85,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== undefined) { + initToolsDownloadFields.tools_extraction_duration_ms = + toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== undefined) { + initToolsDownloadFields.tools_total_duration_ms = + toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/status-report.ts b/src/status-report.ts index e61b04f9d..57020c394 100644 --- a/src/status-report.ts +++ b/src/status-report.ts @@ -620,8 +620,21 @@ export interface InitWithConfigStatusReport extends InitStatusReport { /** Fields of the init status report populated when the tools source is `download`. */ export interface InitToolsDownloadFields { - /** Time taken to download the bundle, in milliseconds. */ + /** + * Time taken to download the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently. + */ tools_download_duration_ms?: number; + /** + * Time taken to extract the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently. + */ + tools_extraction_duration_ms?: number; + /** + * Total time taken to make the bundle available on disk, in milliseconds. This includes any time + * spent on a streaming attempt that failed and fell back to downloading before extracting. + */ + tools_total_duration_ms?: number; /** * Whether the relevant tools dotcom feature flags have been misconfigured. * Only populated if we attempt to determine the default version based on the dotcom feature flags. */ From 9d89e2d1d6874f3f7fab0eacb3e77d4150f1833c Mon Sep 17 00:00:00 2001 From: Henry Mercer Date: Mon, 24 Aug 2026 18:32:11 +0100 Subject: [PATCH 3/8] Rebuild Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 628ce334-991a-4578-9c1b-93d2e96bbddb --- lib/entry-points.js | 28 +++++++++++++++++++++------- 1 file changed, 21 insertions(+), 7 deletions(-) diff --git a/lib/entry-points.js b/lib/entry-points.js index 497e44d9d..3bb1b0e04 100644 --- a/lib/entry-points.js +++ b/lib/entry-points.js @@ -151503,10 +151503,10 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat logger.info( `Downloading CodeQL tools from ${codeqlURL} . This may take a while.` ); + const startTime = import_perf_hooks2.performance.now(); try { if (compressionMethod === "zstd" && process.platform === "linux") { logger.info(`Streaming the extraction of the CodeQL bundle.`); - const toolsInstallStart = import_perf_hooks2.performance.now(); await downloadAndExtractZstdWithStreaming( codeqlURL, dest, @@ -151515,15 +151515,13 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat tarVersion, logger ); - const combinedDurationMs = Math.round( - import_perf_hooks2.performance.now() - toolsInstallStart - ); + const totalDurationMs = Math.round(import_perf_hooks2.performance.now() - startTime); logger.info( `Finished downloading and extracting CodeQL bundle to ${dest} (${formatDuration( - combinedDurationMs + totalDurationMs )}).` ); - return {}; + return { totalDurationMs }; } } catch (e) { core11.warning( @@ -151565,7 +151563,11 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat } finally { await cleanUpPath(archivedBundlePath, "CodeQL bundle archive", logger); } - return { downloadDurationMs }; + return { + downloadDurationMs, + extractionDurationMs, + totalDurationMs: Math.round(import_perf_hooks2.performance.now() - startTime) + }; } async function downloadAndExtractZstdWithStreaming(codeqlURL, dest, authorization, headers, tarVersion, logger) { fs13.mkdirSync(dest, { recursive: true }); @@ -161677,6 +161679,12 @@ async function sendCompletedStatusReport2(startedAt, config, configFile, toolsIn if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) { initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== void 0) { + initToolsDownloadFields.tools_extraction_duration_ms = toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { + initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } @@ -162697,6 +162705,12 @@ async function sendCompletedStatusReport3(startedAt, toolsInput, toolsDownloadSt if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) { initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== void 0) { + initToolsDownloadFields.tools_extraction_duration_ms = toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { + initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } From adcdf4a70d247343cf9c29e0f7a6658b51c3a2b1 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 08:23:20 +0000 Subject: [PATCH 4/8] Update default bundle to codeql-bundle-v2.26.4 --- lib/defaults.json | 8 ++++---- lib/entry-points.js | 4 ++-- src/defaults.json | 8 ++++---- 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/lib/defaults.json b/lib/defaults.json index b5d9f1364..1098ef459 100644 --- a/lib/defaults.json +++ b/lib/defaults.json @@ -1,6 +1,6 @@ { - "bundleVersion": "codeql-bundle-v2.26.3", - "cliVersion": "2.26.3", - "priorBundleVersion": "codeql-bundle-v2.26.2", - "priorCliVersion": "2.26.2" + "bundleVersion": "codeql-bundle-v2.26.4", + "cliVersion": "2.26.4", + "priorBundleVersion": "codeql-bundle-v2.26.3", + "priorCliVersion": "2.26.3" } diff --git a/lib/entry-points.js b/lib/entry-points.js index 497e44d9d..d5f422239 100644 --- a/lib/entry-points.js +++ b/lib/entry-points.js @@ -147569,8 +147569,8 @@ var path6 = __toESM(require("path")); var semver4 = __toESM(require_semver2()); // src/defaults.json -var bundleVersion = "codeql-bundle-v2.26.3"; -var cliVersion = "2.26.3"; +var bundleVersion = "codeql-bundle-v2.26.4"; +var cliVersion = "2.26.4"; // src/overlay/index.ts var fs5 = __toESM(require("fs")); diff --git a/src/defaults.json b/src/defaults.json index b5d9f1364..1098ef459 100644 --- a/src/defaults.json +++ b/src/defaults.json @@ -1,6 +1,6 @@ { - "bundleVersion": "codeql-bundle-v2.26.3", - "cliVersion": "2.26.3", - "priorBundleVersion": "codeql-bundle-v2.26.2", - "priorCliVersion": "2.26.2" + "bundleVersion": "codeql-bundle-v2.26.4", + "cliVersion": "2.26.4", + "priorBundleVersion": "codeql-bundle-v2.26.3", + "priorCliVersion": "2.26.3" } From ecfa6e16817b8f490bc9a59baa391baf4fa3e3c2 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 08:23:26 +0000 Subject: [PATCH 5/8] Add changelog note --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 54dd1bcd0..8fe4db0b7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ See the [releases page](https://github.com/github/codeql-action/releases) for th ## [UNRELEASED] -No user facing changes. +- Update default CodeQL bundle version to [2.26.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#4106](https://github.com/github/codeql-action/pull/4106) ## 4.37.8 - 21 Aug 2026 From 7243f38558d187dde99730d224bb47aa26a95306 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 12:56:36 +0000 Subject: [PATCH 6/8] Update changelog for v4.37.9 --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8fe4db0b7..10917e328 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,7 +2,7 @@ See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. -## [UNRELEASED] +## 4.37.9 - 26 Aug 2026 - Update default CodeQL bundle version to [2.26.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#4106](https://github.com/github/codeql-action/pull/4106) From 0f2e2bde5c66decfb2b189511e1b8fa54802862e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 14:41:24 +0000 Subject: [PATCH 7/8] Update changelog and version after v4.37.9 --- CHANGELOG.md | 4 ++++ package-lock.json | 4 ++-- package.json | 2 +- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 10917e328..e3610058d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,10 @@ See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. +## [UNRELEASED] + +No user facing changes. + ## 4.37.9 - 26 Aug 2026 - Update default CodeQL bundle version to [2.26.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#4106](https://github.com/github/codeql-action/pull/4106) diff --git a/package-lock.json b/package-lock.json index c63a1e310..2ef7d4791 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "license": "MIT", "workspaces": [ "pr-checks" diff --git a/package.json b/package.json index 8f1232ef3..4eaef40a6 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "private": true, "description": "CodeQL action", "scripts": { From f37565646f9db632472ac4d8730a8b4e706fbacb Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 14:41:38 +0000 Subject: [PATCH 8/8] Rebuild --- lib/entry-points.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/entry-points.js b/lib/entry-points.js index d5f422239..d14a2241c 100644 --- a/lib/entry-points.js +++ b/lib/entry-points.js @@ -146023,7 +146023,7 @@ function getDiffRangesJsonFilePath(env = getEnv()) { return path2.join(getTemporaryDirectory(env), PR_DIFF_RANGE_JSON_FILENAME); } function getActionVersion() { - return "4.37.9"; + return "4.37.10"; } function getWorkflowEventName(env = getEnv()) { return env.getRequired("GITHUB_EVENT_NAME" /* GITHUB_EVENT_NAME */);