From 1cdb2019d1e525704fd4d04ff9867603fb4dd54d Mon Sep 17 00:00:00 2001 From: 4gray Date: Mon, 21 Sep 2026 07:45:28 +0200 Subject: [PATCH] ci: allow manual CodeQL validation of PR branches --- .github/workflows/codeql-analysis.yml | 1 + docs/architecture/validation-map.md | 10 ++++++++++ 2 files changed, 11 insertions(+) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 5f87782aa..93b8e120f 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -6,6 +6,7 @@ name: "CodeQL" on: + workflow_dispatch: push: branches: [master] pull_request: diff --git a/docs/architecture/validation-map.md b/docs/architecture/validation-map.md index a3cdd0a07..1d2c6685c 100644 --- a/docs/architecture/validation-map.md +++ b/docs/architecture/validation-map.md @@ -11,6 +11,16 @@ pnpm nx show projects --withTarget lint pnpm nx show projects --withTarget e2e ``` +## Manual CI Runs + +When a PR event does not start checks for the current head, dispatch CI and E2E +with `gh workflow run ci.yml --ref ` and +`gh workflow run e2e-tests.yaml --ref `. CodeQL also supports +`gh workflow run codeql-analysis.yml --ref `; this analyzes the selected +branch commit instead of the PR merge commit. Verify each run's head SHA before +using its result as evidence. Docker validation can use +`gh workflow run docker.yml --ref -f push=false`. + ## Unit And Type Checks | Area | Command |