cloudbase-ai opened a new pull request, #7362:
URL: https://github.com/apache/shenyu/pull/7362

   ### What changed
   
   Use CodeQL `build-mode: none` for pull requests while retaining the current 
full manual Maven build for pushes to `master`.
   
   For pull requests, the workflow now skips:
   
   - JDK setup;
   - Maven cache restore;
   - the full repository Maven package build.
   
   `github/codeql-action/analyze` still runs as the required security gate.
   
   ### Why
   
   On PR #6528, CodeQL took 18.47 minutes and was the overall CI critical path:
   
   | Step | Duration |
   | --- | ---: |
   | Full Maven build | 16.25 min |
   | CodeQL analysis | 1.62 min |
   | Initialization and setup | about 0.6 min |
   
   GitHub officially supports `build-mode: none` for Java. ShenYu currently 
contains no Kotlin sources, so the documented Kotlin exclusion for no-build 
analysis does not apply.
   
   The full manual build remains on `master`, preserving the existing complete 
built-code analysis after merge.
   
   Official reference: 
https://docs.github.com/en/code-security/how-tos/find-and-fix-code-vulnerabilities/manage-your-configuration/codeql-for-compiled-languages
   
   ### Expected effect
   
   - PR CodeQL: approximately 18.5 min to 2-4 min.
   - Master CodeQL: unchanged full manual build.
   - Overall Java PR wall clock: E2E becomes the next critical path until it is 
optimized separately.
   
   ### Verification
   
   - Workflow YAML parsed successfully.
   - Actionlint passed after ignoring the repository's pre-existing 
`actions/checkout@v3` version warning.
   - `git diff --check` passed.
   - This PR itself triggers CodeQL and provides the end-to-end timing 
validation.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to