docs: record the CodeQL advanced-setup decision for apps - #47
Merged
Conversation
Default-setup CodeQL wrote a never-repeating dependency cache entry per analysis, and the hourly prune workflow in apps existed only to clean up after it. Record why apps moved to a checked-in advanced-setup workflow (dependency caching off at the source, zero open CodeQL alerts to lose, same per-push cost) so later audits stop re-flagging the prune workflow, and swap the inventory row from prune-actions-cache.yml to codeql.yml. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016XRddumw4ZNvFqHSd9KSf6
The checked-in workflow is code-scanning only; the action rejects analysis-kinds in custom workflows. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016XRddumw4ZNvFqHSd9KSf6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
docs/code-scanning-strategy.md: new "Decision: CodeQL advanced setup, not default setup" section with the measured numbers, and a since-then note on the baseline bullet.docs/ci-standards.md:appsinventory row swapsprune-actions-cache.ymlforcodeql.yml.Numbers behind the decision (measured 2026-08-29)
codeql-*entries = 3.88 GiB of 5.83 GiB total (67%).Companion change: jdwlabs/apps#209 adds
codeql.ymland deletes the prune workflow. Merge that one first; this doc describes the post-merge state.Refs JDWLABS-450.
🤖 Generated with Claude Code
https://claude.ai/code/session_016XRddumw4ZNvFqHSd9KSf6