fix(codeql): bind merge analysis to merge commit SHA - #1206
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Exact-head review and failure RCA
Exact local evidence:
The PR remains open with 5 queued and 5 skipped hosted check-runs and no formal approval. Decision: |
Exact-head review disposition
Decision: WAIT_AND_REMEDIATE. Do not merge until current-head required Checks and protected review requirements complete. No bypass, force push, direct protected-branch write, or fabricated status was used. |
…/codeql-merge-sha-followup-current
Maintainer verification — exact head
|
Current-head audit
|
Outcome
Make CodeQL merge-preview analysis reliable for stacked and non-default-base PRs. GitHub's merge_commit_sha existed for the merged #1178 run, but refs/pull/1178/merge was absent; both CodeQL merge jobs failed during checkout before analysis.
Change
Related: #1178
Exact verification
No direct protected-branch mutation, fake status, approval bypass, or force push was used.