ci(codeql): cancel superseded pull-request analyses (#1718)

PR CodeQL runs now share a per-PR concurrency group with cancel-in-progress; master pushes, the weekly schedule and manual dispatches get a unique group and are never cancelled. 69 superseded analyses ran to completion across 19 branches in the day before this change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Opus 5.5 authored and GitHub committed 2026-09-27 12:18:12 +02:00
1 parent 254d1fd922
commit 6b1a321c9d
1 file changed
+9
+9
View File
@@ -15,6 +15,15 @@ on:
schedule:
- cron: '0 20 * * 3'
# A newer push to a pull request cancels that PR's still-running analysis:
# only the latest commit's result matters, and superseded runs otherwise hold
# runners the rest of the pipeline is queued for. Pushes to master, the weekly
# schedule and manual dispatches get a unique group (run_id), so they are never
# cancelled or replaced, the same pattern as ci.yml.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
# Required so `codeql-action/analyze` can upload its SARIF results. Without an
# explicit grant the default token is read-only and the upload fails with
# "Resource not accessible by integration".