From 8b704aa9a3d77142ed72389d2a97287e36d7759b Mon Sep 17 00:00:00 2001 From: Gergo Magyar Date: Sun, 14 Jun 2026 17:18:43 +0000 Subject: [PATCH] ci(codeql): exclude nested test fixtures from the CodeQL gate (#2195) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The CodeQL results gate failed on test/integration/cfg/fixtures/python-hazards.py ('total' may be used before init, unused vars) — but that file is an intentional CFG/PDG hazard fixture, exactly the synthetic broken-code the existing '**/test/fixtures/**' exclusion is meant to skip. That glob does not match the deeper test/integration/cfg/fixtures/ path, so the hazard fixtures leaked into the scan. Add '**/test/**/fixtures/**' to cover fixtures nested anywhere under a test tree. Analyze (python) and Analyze (javascript-typescript) both already pass — production code is clean; this only silences fixture noise. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/codeql.yml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6835403db..95598e9ef 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -65,8 +65,12 @@ jobs: - 'gitnexus/src/core/parsing/**/parser.js' # Test fixtures are intentionally synthetic inputs (broken/unused # code, malformed samples) used to exercise the analyzer. CodeQL - # findings here are noise, not real bugs. + # findings here are noise, not real bugs. The second glob also + # covers fixtures nested deeper in the test tree, e.g. + # test/integration/cfg/fixtures/ (the CFG/PDG hazard inputs that + # deliberately contain use-before-init / unused-variable shapes). - '**/test/fixtures/**' + - '**/test/**/fixtures/**' - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0