[ 
https://issues.apache.org/jira/browse/HADOOP-19858?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18075051#comment-18075051
 ] 

ASF GitHub Bot commented on HADOOP-19858:
-----------------------------------------

pan3793 commented on code in PR #8428:
URL: https://github.com/apache/hadoop/pull/8428#discussion_r3115404808


##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,102 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+# This was adapted from the GitHub-generated template.
+# See 
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-default-setup-for-code-scanning
+
+name: "CodeQL Advanced"
+
+on:
+  push:
+    branches: [ "trunk", "branch-*" ]
+  pull_request:
+    branches: [ "trunk", "branch-*" ]
+    paths:
+      - '.github/**'
+  schedule:
+    - cron: '22 4 * * 4'
+
+jobs:
+  analyze:
+    name: Analyze (${{ matrix.language }})
+    # Runner size impacts CodeQL analysis time. See:
+    #   - https://gh.io/recommended-hardware-resources-for-running-codeql
+    runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 
'ubuntu-latest' }}
+    permissions:
+      # required for all workflows
+      security-events: write
+
+      # required to fetch internal or private CodeQL packs
+      packages: read
+
+    strategy:
+      fail-fast: false
+      matrix:
+        include:
+        # Initially only enabling scans for github actions
+        - language: actions
+          build-mode: none
+        # We should consider enabling these in the future:
+        #- language: c-cpp
+        #  build-mode: autobuild
+        #- language: java-kotlin
+        #  build-mode: none # This mode only analyzes Java. Set to 'autobuild' 
or 'manual' to include Kotlin.
+        #- language: javascript-typescript
+        #  build-mode: none
+
+    steps:
+    - name: Checkout repository
+      uses: actions/checkout@v4

Review Comment:
   ```suggestion
         uses: actions/checkout@v6
   ```



##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,102 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+# This was adapted from the GitHub-generated template.
+# See 
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-default-setup-for-code-scanning
+
+name: "CodeQL Advanced"
+
+on:
+  push:
+    branches: [ "trunk", "branch-*" ]
+  pull_request:
+    branches: [ "trunk", "branch-*" ]
+    paths:
+      - '.github/**'
+  schedule:
+    - cron: '22 4 * * 4'
+
+jobs:
+  analyze:
+    name: Analyze (${{ matrix.language }})
+    # Runner size impacts CodeQL analysis time. See:
+    #   - https://gh.io/recommended-hardware-resources-for-running-codeql
+    runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 
'ubuntu-latest' }}

Review Comment:
   swift won't happen, and prefer to pin the runner version explicitly
   ```suggestion
       runs-on: ubuntu-24.04
   ```



##########
.github/workflows/codeql.yml:
##########
@@ -0,0 +1,102 @@
+# Copyright 2026 The Apache Software Foundation
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+# This was adapted from the GitHub-generated template.
+# See 
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configuring-default-setup-for-code-scanning
+
+name: "CodeQL Advanced"
+
+on:
+  push:
+    branches: [ "trunk", "branch-*" ]
+  pull_request:
+    branches: [ "trunk", "branch-*" ]
+    paths:
+      - '.github/**'
+  schedule:
+    - cron: '22 4 * * 4'
+
+jobs:
+  analyze:
+    name: Analyze (${{ matrix.language }})
+    # Runner size impacts CodeQL analysis time. See:
+    #   - https://gh.io/recommended-hardware-resources-for-running-codeql
+    runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 
'ubuntu-latest' }}
+    permissions:
+      # required for all workflows
+      security-events: write
+
+      # required to fetch internal or private CodeQL packs
+      packages: read
+
+    strategy:
+      fail-fast: false
+      matrix:
+        include:
+        # Initially only enabling scans for github actions
+        - language: actions
+          build-mode: none
+        # We should consider enabling these in the future:
+        #- language: c-cpp
+        #  build-mode: autobuild
+        #- language: java-kotlin
+        #  build-mode: none # This mode only analyzes Java. Set to 'autobuild' 
or 'manual' to include Kotlin.
+        #- language: javascript-typescript
+        #  build-mode: none

Review Comment:
   ```suggestion
           # - language: c-cpp
           #   build-mode: autobuild
           # - language: java-kotlin
           #   build-mode: none # This mode only analyzes Java. Set to 
'autobuild' or 'manual' to include Kotlin.
           # - language: javascript-typescript
           #   build-mode: none
   ```





> Set up build workflow in GitHub Actions
> ---------------------------------------
>
>                 Key: HADOOP-19858
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19858
>             Project: Hadoop Common
>          Issue Type: Sub-task
>          Components: build
>            Reporter: Cheng Pan
>            Priority: Major
>              Labels: pull-request-available
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to