Commit Graph

10236 Commits

Author SHA1 Message Date
Henry Mercer
6045ee80fc Disable overlay analysis when pull request analyses fail
Once branch selection has settled on an overlay-base build, make a single
non-paginating request for the most recent pull request failure marker. In
the happy path no markers exist and the list is empty.

On detection, save the persistent overlay status cache entry, which is what
makes pull requests skip overlay analysis too, and disable overlay analysis
for this run. Any failure is treated as if no marker was found, so the check
never disables overlay analysis on its own errors.

`overlay_analysis_status_check_pr_dry_run` performs the same request and
emits the same telemetry, but leaves overlay analysis enabled.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ff943063-d9be-440f-9cac-5e44c4fcfbaa
2026-08-19 17:28:03 +01:00
Henry Mercer
4ed9f4c994 Record pull request analyses that fail with overlay analysis
The overlay status mechanism only recorded failures from default-branch
overlay-base builds. Analyses that failed on pull requests were invisible,
because Actions cache poisoning protections mean a pull request cannot write
into the default branch's cache scope.

A pull request can write a cache entry in its own scope, so record the
failure there as a marker whose key carries everything the default branch
needs. The default branch can list key metadata even though it cannot restore
the entry itself.

The `analyze` Action exports `ANALYZE_DID_START` once its config is loaded,
so that `init-post` can distinguish an overlay analysis that failed after
`analyze` started from one that never ran.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ff943063-d9be-440f-9cac-5e44c4fcfbaa
2026-08-19 17:27:36 +01:00
Henry Mercer
8d44931b38 Treat unsuccessful overlay status cache saves as failures
`saveCache` reports most failures by returning -1 rather than by throwing,
including when the key already exists, when the cache is read-only, and for
HTTP errors. Checking only for `undefined` therefore detected timeouts alone,
so we logged that the status had been saved when nothing had been.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ff943063-d9be-440f-9cac-5e44c4fcfbaa
2026-08-19 17:26:52 +01:00
Henry Mercer
38e305d01c Add a single-page Actions cache listing helper
Unlike `listActionsCaches`, this makes exactly one request and does not
retry, which keeps the cost of the lookup predictable for latency-sensitive
callers. `DO_NOT_RETRY_STATUSES` deliberately omits 403 and 429, so without
disabling retries a permission-denied or throttled call would be retried
before failing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ff943063-d9be-440f-9cac-5e44c4fcfbaa
2026-08-19 17:26:32 +01:00
Henry Mercer
9ee088e136 Merge pull request #4080 from github/henrymercer/studious-giggle
Determine the overlay minimum disk space requirement from feature flags
2026-08-18 12:25:05 +00:00
Henry Mercer
1aef003397 Address review feedback on overlay disk flags
Document each minimum disk feature flag individually and replace the tuple list with an explicit feature-to-threshold mapping.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-18 12:09:33 +01:00
Henry Mercer
508b83bc41 Merge main into overlay minimum disk feature branch
Resolve the overlap with the separately shipped promotion of the overlay resource checks while preserving the feature-flagged minimum disk thresholds.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-08-18 12:09:09 +01:00
Michael B. Gale
d97b3428e8 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
Make `EACCES` when installing CodeQL CLI a `ConfigurationError`
2026-08-14 11:56:43 +00:00
Michael B. Gale
47fa622223 Make EACCES a ConfigurationError 2026-08-14 11:56:26 +01:00
Michael B. Gale
45693cc688 Refactor ENOSPC check into isDiskConfigurationError function 2026-08-14 11:53:32 +01:00
Mario Campos
c2fd8f54d1 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
Persist CodeQL version output to file rather than environment
2026-08-13 14:27:41 +00:00
Mario Campos
c56f48e9bd Log unexpected conditions during caching CLI output 2026-08-13 09:14:00 -05:00
Mario Campos
aa0eadc572 Merge branch 'main' into mario-campos/version-cache-to-disk
# Conflicts:
#	lib/entry-points.js
2026-08-13 09:02:15 -05:00
Mario Campos
43250d671a Change cache key to string type to include CLI args 2026-08-13 08:59:09 -05:00
Michael B. Gale
5008effa71 Merge pull request #4094 from github/mergeback/v4.37.7-to-main-ff2f1c62
Mergeback v4.37.7 refs/heads/releases/v4 into main
2026-08-13 13:48:05 +00:00
github-actions[bot]
053d41e61e Rebuild 2026-08-13 13:30:41 +00:00
github-actions[bot]
1158e1c92a Update changelog and version after v4.37.7 2026-08-13 13:30:28 +00:00
Michael B. Gale
ff2f1c621b Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8
Merge main into releases/v4
v4.37.7
2026-08-13 14:28:39 +01:00
Mario Campos
2d49edbac6 Re-order env to be first argument for consistency 2026-08-13 08:13:49 -05:00
github-actions[bot]
951a133f96 Update changelog for v4.37.7 2026-08-13 10:59:59 +00:00
Michael B. Gale
be7a3dbb81 Merge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561e04e
Bump the npm-minor group across 1 directory with 8 updates
2026-08-13 10:17:02 +00:00
Michael B. Gale
9310334b11 Merge pull request #4086 from github/mbg/thread-action-state-to-codeql
Make a `Logger` available to `getCodeQLForCmd`
2026-08-13 10:03:46 +00:00
Mario Campos
6dc633238e Bolster output-cache unit tests with more test cases 2026-08-12 13:45:22 -05:00
github-actions[bot]
b4d8a54218 Rebuild 2026-08-12 17:57:08 +00:00
dependabot[bot]
ab5db2519c Bump the npm-minor group across 1 directory with 8 updates
Bumps the npm-minor group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@octokit/core](https://github.com/octokit/core.js) | `7.0.6` | `7.0.7` |
| [@octokit/plugin-retry](https://github.com/octokit/plugin-retry.js) | `8.1.0` | `8.1.1` |
| [@types/semver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/semver) | `7.7.1` | `7.8.0` |
| [eslint-plugin-github](https://github.com/github/eslint-plugin-github) | `6.1.1` | `6.1.2` |
| [globals](https://github.com/sindresorhus/globals) | `17.8.0` | `17.9.0` |
| [nock](https://github.com/nock/nock) | `14.0.16` | `14.0.17` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.65.0` | `8.66.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.8` |



Updates `@octokit/core` from 7.0.6 to 7.0.7
- [Release notes](https://github.com/octokit/core.js/releases)
- [Commits](https://github.com/octokit/core.js/compare/v7.0.6...v7.0.7)

Updates `@octokit/plugin-retry` from 8.1.0 to 8.1.1
- [Release notes](https://github.com/octokit/plugin-retry.js/releases)
- [Commits](https://github.com/octokit/plugin-retry.js/compare/v8.1.0...v8.1.1)

Updates `@types/semver` from 7.7.1 to 7.8.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver)

Updates `eslint-plugin-github` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/github/eslint-plugin-github/releases)
- [Commits](https://github.com/github/eslint-plugin-github/compare/v6.1.1...v6.1.2)

Updates `globals` from 17.8.0 to 17.9.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](https://github.com/sindresorhus/globals/compare/v17.8.0...v17.9.0)

Updates `nock` from 14.0.16 to 14.0.17
- [Release notes](https://github.com/nock/nock/releases)
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md)
- [Commits](https://github.com/nock/nock/compare/v14.0.16...v14.0.17)

Updates `typescript-eslint` from 8.65.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/typescript-eslint)

Updates `tsx` from 4.23.1 to 4.23.8
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.1...v4.23.8)

---
updated-dependencies:
- dependency-name: "@octokit/core"
  dependency-version: 7.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: "@octokit/plugin-retry"
  dependency-version: 8.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: "@types/semver"
  dependency-version: 7.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: eslint-plugin-github
  dependency-version: 6.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: globals
  dependency-version: 17.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: nock
  dependency-version: 14.0.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
- dependency-name: typescript-eslint
  dependency-version: 8.66.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: tsx
  dependency-version: 4.23.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-12 17:54:58 +00:00
Mario Campos
6c0d9018d4 Change OutputCache to use object for entries
This will ensure it works nicely with `JSON.stringify`. And, then we can validate the type before marshaling.
2026-08-12 12:01:20 -05:00
Mario Campos
bf96b0df93 Expand test to ensure it does not throw an exception 2026-08-12 11:39:32 -05:00
Mario Campos
337136ab8a Rename CommandCacheRecord -> OutputCache 2026-08-12 11:29:11 -05:00
Mario Campos
a9baab8dee Export CLI cache types 2026-08-12 11:26:52 -05:00
Mario Campos
33d70867d5 Pass environment explicitly to CLI caching functions 2026-08-12 11:24:37 -05:00
Michael B. Gale
38055a3c3c Drop logger from databaseInitCluster in interface 2026-08-12 16:49:45 +01:00
Michael B. Gale
1f87aed5e6 Merge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3
Update default bundle to 2.26.3
2026-08-12 15:45:41 +00:00
Michael B. Gale
dc1b98ad1c Make logger available to getCodeQLForCmd 2026-08-12 16:43:22 +01:00
Michael B. Gale
6f0220ee37 Merge pull request #4084 from github/navntoft/bump-undici
Bump undici from ^6.24.0 to ^6.28.0
2026-08-12 15:31:05 +00:00
github-actions[bot]
ca1c97228c Add changelog note 2026-08-12 15:30:22 +00:00
github-actions[bot]
0e8a5d99f8 Update default bundle to codeql-bundle-v2.26.3 2026-08-12 15:30:15 +00:00
Mads Navntoft
54a084632e Bump undici from ^6.24.0 to ^6.28.0 2026-08-12 12:32:22 +02:00
Mario Campos
40f80a8df0 Rename type to better match generic intention 2026-08-11 18:09:09 -05:00
Mario Campos
b222c3aaea Generalize file cache data structure 2026-08-11 18:09:09 -05:00
Mario Campos
11569df0a1 Update JSDoc of getCachedCodeQlVersion 2026-08-11 15:55:16 -05:00
Mario Campos
0a99875ae5 Move VersionInfo-related types to cli/output-cache.ts
This brings them out of the crowded all-purpose `util.ts` and into `cli/output-cache.ts` where they are exclusively used.
2026-08-11 15:55:15 -05:00
Mario Campos
246018e041 Move VersionInfo to dedicated module 2026-08-11 15:55:15 -05:00
Mario Campos
1332611f51 Move cache-related util functions into dedicated module 2026-08-11 15:55:15 -05:00
Mario Campos
4dc327a942 Introduce basic cli/output-cache.ts module 2026-08-11 15:36:17 -05:00
Mario Campos
bb19330c5e Add test of getCachedCodeQlVersion with no file 2026-08-11 15:36:17 -05:00
Mario Campos
0e85c0e99c Refactor unit test to extract testing values 2026-08-11 15:36:17 -05:00
Mario Campos
bfcd769ba1 Fix JSDoc of env param 2026-08-11 15:36:17 -05:00
Michael B. Gale
c16c0f3f28 Merge pull request #4083 from github/mbg/features/remove-overlayResourceChecksV2
Promote `OverlayAnalysisResourceChecksV2`
codeql-bundle-v2.26.3
2026-08-11 16:15:32 +00:00
Mario Campos
208a88adc7 Simplify JSDoc of getCachedCodeQlVersion
Co-authored-by: Michael B. Gale <mbg@github.com>
2026-08-11 11:06:17 -05:00
Michael B. Gale
f47bb7b9aa Remove v2 from test title 2026-08-11 14:08:57 +01:00