Skip to content

Add opt-in early skips for draft and non-code-only pull requests - #4213

Open
asdf8675309 wants to merge 4 commits into
github:mainfrom
asdf8675309:codex/early-skip-prototype
Open

asdf8675309 wants to merge 4 commits into
github:mainfrom
asdf8675309:codex/early-skip-prototype

Conversation

@asdf8675309

Copy link
Copy Markdown

Summary

Repeated CodeQL runs of about five minutes during rapid draft-PR iteration occupy runners before the author is ready for review. On limited capacity runners, those runs can also delay merge-queue validation. This change adds opt-in early exits for confirmed draft PRs and conservatively identified non-code-only PR changes.

Couldn't find a way to not have the Code Quality scan run on draft PR's and PR's that didn't change any of the file types that were scanned. This adds skip-if-draft and skip-if-no-language-changes to init, both defaulting to false.

  • Check confirmed draft state before GitHub API setup, repository-property/configuration lookups, and starting/completed status reports. This avoids telemetry requests and their retries as well as CodeQL CLI download and database initialization.
  • For the change gate, require one explicit built-in language and immutable PR event base/head SHAs. Include both sides of renames and decline to skip when the comparison may be truncated (300 or more files), fails, or contains unknown paths. Only recognized non-code paths qualify; source, workflow, build/dependency configuration, and shell-script changes retain analysis.
  • Preserve complete language analysis whenever a scan runs. This does not extract or query only changed files.
  • Export analysis-skipped and analysis-skip-reason; make autobuild, analyze, and their post actions handle intentional skips successfully. Custom build steps can use the output to guard their own work.
  • Add usage documentation, a change note, regression tests, and regenerated compiled artifacts.

A workflow enabling draft skips must include ready_for_review in its PR event types. The path gate is a conservative heuristic: repositories that generate code from documentation or other allowed non-code inputs should leave it disabled.

Managed Code Quality integration and review questions

GitHub-managed Code Quality uses a generated dynamic workflow. This PR supplies an action-side mechanism; it does not modify that generator or the product's repository settings. The proposed CODE_SCANNING_IS_DRAFT environment signal allows the generator to supply draft state. Managed adoption would also need the appropriate opt-in inputs, immutable PR commit metadata for the change gate, and ready-for-review scheduling.

Feedback is particularly welcome on:

  1. Whether these opt-in controls belong in the action, and whether the input names and proposed managed draft signal fit existing integration conventions.
  2. Whether confirmed draft skips should deliberately omit start/completion status telemetry. The job remains successful and the logs/outputs state explicitly that analysis was skipped.
  3. Whether the initial non-code allowlist is appropriately conservative, or a narrower policy should ship first.

DRAFT risk assessment from Codex --

Proposed classification for maintainer review:

  • High risk: The new inputs are disabled by default, but enabling them intentionally omits analysis. A false skip is possible when recognized non-code paths are inputs to generated code. The changed-file gate and managed integration have limited live validation, and confirmed draft skips omit status telemetry. The README documents the path-policy limitation and required ready-for-review trigger.

Which use cases does this change impact?

Workflow types:

  • Advanced setup - Impacts users who have custom CodeQL workflows and enable the new inputs.
  • Managed - Provides a proposed integration point for dynamic workflows. Current generators are not changed by this PR; adoption requires GitHub-side integration.

@asdf8675309
asdf8675309 requested a review from a team as a code owner October 8, 2026 01:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant