Skip to content

fix: prevent CodeQL SARIF upload to resolve Default Setup conflict - #29

Merged
Daniel MacLaughlin (daniel-maclaughlin) merged 1 commit into
mainfrom
fix/codeql-upload-never
Oct 2, 2026
Merged

Daniel MacLaughlin (daniel-maclaughlin) merged 1 commit into
mainfrom
fix/codeql-upload-never

Conversation

@seposium

@seposium seposium commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Problem

The CodeQL workflow fails on every PR with:

CodeQL analyses from advanced configurations cannot be processed when the default setup is enabled

The repo has GitHub's Default Setup enabled for code scanning. When our custom workflow also tries to upload a SARIF file, GitHub rejects it — two systems can't both own code scanning results.

Fix

Add upload: never to the analyze step. CodeQL still runs and the job passes/fails normally, but it skips the SARIF upload that conflicts with Default Setup.

- name: Perform CodeQL Analysis
  uses: github/codeql-action/analyze@v4
  with:
    upload: never

Security findings from Default Setup continue to appear in the Security tab as before.

🤖 Generated with Claude Code

@daniel-maclaughlin
Daniel MacLaughlin (daniel-maclaughlin) merged commit 0e68c13 into main Oct 2, 2026
6 checks passed
@daniel-maclaughlin
Daniel MacLaughlin (daniel-maclaughlin) deleted the fix/codeql-upload-never branch October 2, 2026 02:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants