[
https://issues.apache.org/jira/browse/HADOOP-19858?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18074705#comment-18074705
]
ASF GitHub Bot commented on HADOOP-19858:
-----------------------------------------
pan3793 commented on code in PR #8428:
URL: https://github.com/apache/hadoop/pull/8428#discussion_r3107292689
##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,117 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements. See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership. The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+
+name: "CodeQL Advanced"
Review Comment:
you should really mention where the workflow YAML comes from, I read the
https://codeql.github.com/docs/ and find nothing about how to integrate it with
GHA, and finally found it at
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-default-setup-for-code-scanning
##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,117 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements. See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership. The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+
+name: "CodeQL Advanced"
Review Comment:
and it seems you modified this general-purpose generated YAML a few places
in
https://github.com/apache/hadoop/pull/8428/changes/84c54dccfb616fdfba6076804a716e3629344f77
for this case, I would suggest either
- (preferred) keeping everything as-is, with minimal changes and clear
comments about each modification, makes it easy for us to adopt future upstream
changes. or
- making a major refactor to make it hadoop specific, e.g., it's not likely
hadoop will have swift language in the codebase
##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,115 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements. See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership. The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+
+name: "CodeQL Advanced"
+
+on:
+ push:
+ branches: [ "trunk", "branch-*" ]
+ pull_request:
+ branches: [ "trunk", "branch-*" ]
+ schedule:
+ - cron: '22 4 * * 4'
+
+jobs:
+ analyze:
+ name: Analyze (${{ matrix.language }})
+ # Runner size impacts CodeQL analysis time. To learn more, please see:
+ # - https://gh.io/recommended-hardware-resources-for-running-codeql
+ runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') ||
'ubuntu-latest' }}
+ permissions:
+ # required for all workflows
+ security-events: write
Review Comment:
yes, it works in your forked repo, as you are the owner of that repo. but
are you sure we are granted sufficient permission to enable it in
`apache/hadoop` repo? I didn't find this option, which is mentioned by
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-advanced-setup-for-code-scanning
<img width="746" height="255" alt="Image"
src="https://github.com/user-attachments/assets/a89513e9-df89-4bc7-87f8-3bf6e15db1b4"
/>
> Set up build workflow in GitHub Actions
> ---------------------------------------
>
> Key: HADOOP-19858
> URL: https://issues.apache.org/jira/browse/HADOOP-19858
> Project: Hadoop Common
> Issue Type: Sub-task
> Components: build
> Reporter: Cheng Pan
> Priority: Major
> Labels: pull-request-available
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]