Conversation
…out_path` itself
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 16, 2026 16:01
eecc9cd to
9a59042
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
checkout_pathinput of theanalyzeaction must be set to the path at which the repository that is being analysed is checked out at if it is not the workspace root. However, currently we do not perform any kind of validation of thecheckout_pathinput to ensure that it actually points at a valid Git repository, which may lead to unexpected and difficult-to-observe results.This PR makes the following changes:
checkout_pathinput directly and instead receive the value from the caller.initaction persists the discovered repository root in the CodeQL Action configuration state, if any.analyzeaction now performs the following validation on thecheckout_pathinput value and warns if a check fails:checkout_pathrefers to a path in the work tree of a Git repository.checkout_pathrefers to the root of a Git repository.checkout_pathmatches that stored by theinitaction, if any.Risk assessment
For internal use only. Please select the risk level of this change:
Which use cases does this change impact?
Workflow types:
dynamicworkflows (Default Setup, Code Quality, ...).Products:
analysis-kinds: code-scanning.analysis-kinds: code-quality.upload-sarifaction.Environments:
github.comand/or GitHub Enterprise Cloud with Data Residency.How did/will you validate this change?
.test.tsfiles).pr-checks).If something goes wrong after this change is released, what are the mitigation and rollback strategies?
How will you know if something goes wrong after this change is released?
Are there any special considerations for merging or releasing this change?
Merge / deployment checklist