Skip to content

ci: add CodeQL analysis - #128

Closed
rowkav09 wants to merge 1 commit into
mainfrom
rowkav09-patch-42
Closed

rowkav09 wants to merge 1 commit into
mainfrom
rowkav09-patch-42

Conversation

@rowkav09

Copy link
Copy Markdown
Member

What changed

  • add CodeQL analysis for JavaScript/TypeScript
  • run on relevant PRs, main changes and a weekly schedule
  • use security-extended queries with a 15-minute bound
  • keep default workflow permissions read-only and grant security-events: write only to the analysis job

Why

The hosted HTTP service and updater process untrusted external data. CodeQL adds dataflow and injection analysis beyond syntax and unit tests.

Checks

  • Workflow syntax reviewed
  • Permissions are job-scoped and least-privilege
  • No secrets, tokens, server URLs, or personal media data are committed
  • The change is scoped to one roadmap issue

Issue

Refs #127

Add least-privilege JavaScript security analysis on relevant changes, main and a weekly schedule. Refs #127.
@mira-reviewer-rk

mira-reviewer-rk Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Mira PR Walkthrough


❌ Review failed — click for details

The code review failed to complete due to an unexpected error.

Stage: Code review
Error type: LLMError
Message: LLM tool-call failed

@rowkav09

Copy link
Copy Markdown
Member Author

/mira mute

@rowkav09

Copy link
Copy Markdown
Member Author

Closing for now: code scanning isn't enabled on this private repo (the CodeQL run fails with 'Code scanning is not enabled for this repository'). It needs GitHub Advanced Security while the repo is private. Worth reopening once nowplaying is public. Still tracked in #127.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant