Repository navigation
ci: scan maintained JavaScript and Python with CodeQL - #823
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
OkTest Summary❌ Failed for Ruby SDK PR #823. SDK merge ( |
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 84 mixed files remain; 0 existing customizations changed. Compared 84 existing customizations unchanged
44 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37989763666 --repo openai/openai-ruby \
--name castiron-custom-code-37989763666-1 --dir /tmp/castiron-custom-code-37989763666-1
git apply --stat /tmp/castiron-custom-code-37989763666-1/custom-code.patch
cat /tmp/castiron-custom-code-37989763666-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin ab350864252bdc66f45f9e398032ad162c6a95b2 d7c59992ea537d3293d944b03cf30a94b5c631a3
python3 scripts/castiron/custom_code_report.py report \
--base ab350864252bdc66f45f9e398032ad162c6a95b2 \
--head d7c59992ea537d3293d944b03cf30a94b5c631a3 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-d7c59992ea53
cat /tmp/castiron-custom-code-d7c59992ea53/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
|
Readiness correction: all 20 native repository checks passed (two intentionally skipped), but overall CI is not green. The external OkTest report is FAILED for head I verified run 37989711081 / job 114020884900: Docker Hub returned HTTP 429 to the No retry, registry/authentication/permission change, or gate bypass was performed. Keep the external failure unresolved pending normal service recovery or separately authorized recovery; native CodeQL success does not replace OkTest validation. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed d7c59992ea537d3293d944b03cf30a94b5c631a3. The new languages use the existing CodeQL job and separate output directories. They keep the pinned actions and SARIF findings gate. Actions and Ruby coverage, limited permissions, and checkout credential handling remain intact. The updated assertions cover all four languages. I found no actionable issues in this two-file change.
The repository's reported checks passed or were intentionally skipped, including all four CodeQL jobs. External OkTest remains failed for this exact head. Its Docker Hub image request returned HTTP 429 before compatibility tests started, so overall CI remains incomplete. I reviewed source and hosted CI evidence without running local tests. Main-branch coverage still needs validation after merge.
Maintained browser examples and JavaScript/Python repository tooling were omitted from the security CodeQL matrix. Add
javascript-typescriptandpythonto the existing PR, main, and merge-group analyses, preserving Ruby/Actions coverage and the existing all-findings rejection step.Updated the focused workflow regression tests. Validation: 10 tests / 40 assertions pass; rubyfmt and
git diff --checkpass. Two independent review rounds found no blockers. Full Bundler checks require CI because the local checkout lacks its locked dependencies.The existing native CodeQL ruleset now requires all alert severities; no new check names were invented or protections bypassed. This addresses both SDK Health Code scanning and its derived GitHub security coverage finding. Main-head coverage remains pending merge and successful analysis; this PR does not claim a current-main Green rating.