Conversation
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 16, 2026 16:01
eecc9cd to
9a59042
Compare
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 22, 2026 10:25
9a59042 to
39bbd41
Compare
mbg
added this pull request to stack #4158
September 22, 2026 10:25
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 22, 2026 10:42
39bbd41 to
b07d4ae
Compare
mbg
marked this pull request as ready for review
September 22, 2026 11:10
Contributor
There was a problem hiding this comment.
Warning
- Copilot's review of this pull request may be incomplete because some of the changed files are excluded by your Copilot content exclusion settings. See Excluding content from Copilot for details.
Copilot review overview
🟡 Changes recommended
Path comparison can produce false warnings on Windows, and several updated Git tests no longer stub the intended calls.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Adds validation for the analyze action’s checkout_path and persists the repository root for consistent Git operations.
Changes:
- Persists and propagates the detected repository root.
- Validates
checkout_pathand emits actionable warnings. - Refactors Git helpers to accept explicit environment and checkout context.
| File | Description |
|---|---|
src/analyze.ts |
Adds checkout-path validation. |
src/analyze-action.ts |
Integrates validation into analysis. |
src/analyze-action.test.ts |
Updates analyze-action fixtures. |
src/actions-util.ts |
Accepts read-only environments. |
src/codeql.ts |
Uses persisted repository root. |
src/config/action-config.ts |
Adds repository-root state. |
src/config-utils.ts |
Discovers and propagates repository root. |
src/config-utils.test.ts |
Updates configuration tests. |
src/database-upload.ts |
Passes environment and checkout path to Git helpers. |
src/environment.ts |
Adds bulk environment-variable assignment. |
src/git-utils.ts |
Makes Git context explicit. |
src/git-utils.test.ts |
Updates Git helper tests. |
src/init-action-post-helper.ts |
Uses persisted root for failed SARIF. |
src/init-action-post.ts |
Uses repository root for branch detection. |
src/overlay/caching.ts |
Passes environment to commit lookup. |
src/status-report.ts |
Uses repository root for ref detection. |
src/testing-utils.ts |
Adds repository-root test defaults. |
src/trap-caching.ts |
Uses repository root for cache decisions. |
src/trap-caching.test.ts |
Updates cache helper invocation. |
src/upload-lib.ts |
Passes environment and checkout path to Git helpers. |
src/workflow.ts |
Resolves repository roots from persisted state or workflow inputs. |
src/workflow.test.ts |
Tests repository-root resolution. |
lib/entry-points.js |
Generated bundle; excluded from review. |
Files excluded by content exclusion policy (1)
- lib/entry-points.js
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
36
to
+37
| const callback = sinon.stub(gitUtils, "getCommitOid"); | ||
| callback.withArgs("HEAD").resolves(currentSha); | ||
| callback.withArgs(sinon.match.any, "HEAD").resolves(currentSha); |
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 22, 2026 14:16
1f60da6 to
c4bb0cf
Compare
mbg
force-pushed
the
mbg/improve-checkout-path
branch
from
September 22, 2026 15:25
c4bb0cf to
9f57eb3
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The
checkout_pathinput of theanalyzeaction must be set to the path at which the repository that is being analysed is checked out at if it is not the workspace root. However, currently we do not perform any kind of validation of thecheckout_pathinput to ensure that it actually points at a valid Git repository, which may lead to unexpected and difficult-to-observe results.This PR makes the following changes:
initaction persists the discovered repository root in the CodeQL Action configuration state, if any.analyzeaction now performs the following validation on thecheckout_pathinput value and warns if a check fails:checkout_pathrefers to a path in the work tree of a Git repository.checkout_pathrefers to the root of a Git repository.checkout_pathmatches that stored by theinitaction, if any.Risk assessment
For internal use only. Please select the risk level of this change:
Which use cases does this change impact?
Workflow types:
dynamicworkflows (Default Setup, Code Quality, ...).Products:
analysis-kinds: code-scanning.analysis-kinds: code-quality.upload-sarifaction.Environments:
github.comand/or GitHub Enterprise Cloud with Data Residency.How did/will you validate this change?
.test.tsfiles).pr-checks).If something goes wrong after this change is released, what are the mitigation and rollback strategies?
How will you know if something goes wrong after this change is released?
Are there any special considerations for merging or releasing this change?
Merge / deployment checklist