From 6b1a321c9d0eb62c168c0cff13953d0622bcb3ab Mon Sep 17 00:00:00 2001 From: 4gray <4gray@users.noreply.github.com> Date: Sun, 27 Sep 2026 12:18:12 +0200 Subject: [PATCH] ci(codeql): cancel superseded pull-request analyses (#1718) PR CodeQL runs now share a per-PR concurrency group with cancel-in-progress; master pushes, the weekly schedule and manual dispatches get a unique group and are never cancelled. 69 superseded analyses ran to completion across 19 branches in the day before this change. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/codeql-analysis.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 93b8e120f..74e397a8f 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -15,6 +15,15 @@ on: schedule: - cron: '0 20 * * 3' +# A newer push to a pull request cancels that PR's still-running analysis: +# only the latest commit's result matters, and superseded runs otherwise hold +# runners the rest of the pipeline is queued for. Pushes to master, the weekly +# schedule and manual dispatches get a unique group (run_id), so they are never +# cancelled or replaced, the same pattern as ci.yml. +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + # Required so `codeql-action/analyze` can upload its SARIF results. Without an # explicit grant the default token is read-only and the upload fails with # "Resource not accessible by integration".