Skip to content
Latchkey

CodeQL workflow (nestjs/nest)

The CodeQL workflow from nestjs/nest, explained and optimized by Latchkey.

C

CI health: C - fair

The optimized version below adds run de-duplication, job timeouts.

Source: nestjs/nest.github/workflows/codeql-analysis.ymlLicense MITView source

What it does

This is the CodeQL workflow from the nestjs/nest repository, a real project running GitHub Actions. It is shown here with attribution under its MIT license.

Below, Latchkey shows a faster, safer version produced by its optimization engine.

The workflow

workflow (.yml)
name: "CodeQL"

on:
  push:
    branches: [master, ]
  pull_request:
    # The branches below must be a subset of the branches above
    branches: [master]
  schedule:
    - cron: '0 17 * * 4'

permissions:
  contents: read

jobs:
  analyse:
    permissions:
      security-events: write
    name: Analyse
    runs-on: ubuntu-latest

    steps:
    - name: Checkout repository
      uses: actions/checkout@v7
      with:
        # We must fetch at least the immediate parents so that if this is
        # a pull request then we can checkout the head.
        fetch-depth: 2

    # If this run was triggered by a pull request event, then checkout
    # the head of the pull request instead of the merge commit.
    - run: git checkout HEAD^2
      if: ${{ github.event_name == 'pull_request' }}

    # Initializes the CodeQL tools for scanning.
    - name: Initialize CodeQL
      uses: github/codeql-action/init@v4
      with:
        queries: +security-extended
      # Override language selection by uncommenting this and choosing your languages
      # with:
      #   languages: go, javascript, csharp, python, cpp, java

    # Autobuild attempts to build any compiled languages  (C/C++, C#, or Java).
    # If this step fails, then you should remove it and run the build manually (see below)
    - name: Autobuild
      uses: github/codeql-action/autobuild@v4

    # ℹ️ Command-line programs to run using the OS shell.
    # 📚 https://git.io/JvXDl

    # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
    #    and modify them (or add more) to build your code if your project
    #    uses a compiled language

    #- run: |
    #   make bootstrap
    #   make release

    - name: Perform CodeQL Analysis
      uses: github/codeql-action/analyze@v4

The same workflow, on Latchkey

Removes redundant runs and caps runaway jobs. Added and changed lines are highlighted.

name: "CodeQL" on:  push:    branches: [master, ]  pull_request:    # The branches below must be a subset of the branches above    branches: [master]  schedule:    - cron: '0 17 * * 4' permissions:  contents: read concurrency:  group: ${{ github.workflow }}-${{ github.ref }}  cancel-in-progress: true jobs:  analyse:    timeout-minutes: 30    permissions:      security-events: write    name: Analyse    runs-on: latchkey-small     steps:    - name: Checkout repository      uses: actions/checkout@v7      with:        # We must fetch at least the immediate parents so that if this is        # a pull request then we can checkout the head.        fetch-depth: 2     # If this run was triggered by a pull request event, then checkout    # the head of the pull request instead of the merge commit.    - run: git checkout HEAD^2      if: ${{ github.event_name == 'pull_request' }}     # Initializes the CodeQL tools for scanning.    - name: Initialize CodeQL      uses: github/codeql-action/init@v4      with:        queries: +security-extended      # Override language selection by uncommenting this and choosing your languages      # with:      #   languages: go, javascript, csharp, python, cpp, java     # Autobuild attempts to build any compiled languages  (C/C++, C#, or Java).    # If this step fails, then you should remove it and run the build manually (see below)    - name: Autobuild      uses: github/codeql-action/autobuild@v4     # ℹ️ Command-line programs to run using the OS shell.    # 📚 https://git.io/JvXDl     # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines    #    and modify them (or add more) to build your code if your project    #    uses a compiled language     #- run: |    #   make bootstrap    #   make release     - name: Perform CodeQL Analysis      uses: github/codeql-action/analyze@v4 

What changed

  • Run on Latchkey managed runners with one line (runs-on), which apply the fixes below automatically and self-heal transient failures. This example uses latchkey-small; pick the runner size that fits the job.
  • Cancel superseded runs when a branch or PR gets a newer push.
  • Add a job timeout so a hung step cannot burn hours of runner time.

This workflow runs 1 job per trigger. On Latchkey the same minutes cost up to 58% less than GitHub-hosted, with zero queue time.

Actions used in this workflow

Frequently asked questions

What does the CodeQL workflow (nestjs/nest) workflow do?
This is the CodeQL workflow from the nestjs/nest repository, a real project running GitHub Actions. It is shown here with attribution under its MIT license.
What CI health grade does this workflow get?
This Automation and other workflow grades C. Paste your own workflow into the Latchkey grader to see its grade and the exact fixes.
How can I improve this Automation and other workflow?
Apply run de-duplication, job timeouts. Latchkey applies these automatically on managed runners when you point runs-on at Latchkey.

References