Skip to content

Check for versions of macOS and Xcode that are unsupported for traced Swift analysis - #4221

Draft
mbg wants to merge 12 commits into
mbg/diagnostics/failed-sariffrom
mbg/macos27/warn
Draft

mbg wants to merge 12 commits into
mbg/diagnostics/failed-sariffrom
mbg/macos27/warn

Conversation

@mbg

@mbg mbg commented Oct 9, 2026

Copy link
Copy Markdown
Member

Traced analysis is unsupported for Swift on macOS 27 (or newer) or with Xcode 27 (or newer). This PR refactors the existing OS check for swift into a new function which is then extended with checks for whether the macOS version is < 27 and the Xcode version is < 27.

If either is >= 27, then we report this issue to the user with a suitable diagnostic. I have also added a FF which controls whether this is just a warning or a fatal error which aborts the analysis.

Further, there is a new ToolsFeature which allows the CLI to indicate to us when it is ready to support swift on all platforms. Once the CLI reports that it supports this, we skip all of the checks for swift.

I wanted to add a URL to a page with more information in the messages, but I don't think such a page exists yet.

Risk assessment

For internal use only. Please select the risk level of this change:

  • Low risk: Changes are fully under feature flags, or have been fully tested and validated in pre-production environments and are highly observable, or are documentation or test only.
  • High risk: Changes are not fully under feature flags, have limited visibility and/or cannot be tested outside of production.

Which use cases does this change impact?

Workflow types:

  • Advanced setup - Impacts users who have custom CodeQL workflows.
  • Managed - Impacts users with dynamic workflows (Default Setup, Code Quality, ...).

Products:

  • Code Scanning - The changes impact analyses when analysis-kinds: code-scanning.
  • Code Quality - The changes impact analyses when analysis-kinds: code-quality.
  • Other first-party - The changes impact other first-party analyses.

Environments:

  • Dotcom - Impacts CodeQL workflows on github.com and/or GitHub Enterprise Cloud with Data Residency.
  • GHES - Impacts CodeQL workflows on GitHub Enterprise Server.

How did/will you validate this change?

  • Unit tests - I am depending on unit test coverage (i.e. tests in .test.ts files).
  • End-to-end tests - I am depending on PR checks (i.e. tests in pr-checks).

If something goes wrong after this change is released, what are the mitigation and rollback strategies?

  • Feature flags - All new or changed code paths can be fully disabled with corresponding feature flags.
  • Rollback - Change can only be disabled by rolling back the release or releasing a new version with a fix.

How will you know if something goes wrong after this change is released?

  • Telemetry - I rely on existing telemetry or have made changes to the telemetry.
    • Dashboards - I will watch relevant dashboards for issues after the release. Consider whether this requires this change to be released at a particular time rather than as part of a regular release.
    • Alerts - New or existing monitors will trip if something goes wrong with this change.

Are there any special considerations for merging or releasing this change?

  • Special considerations - This change should only be merged once certain preconditions are met. Please provide details of those or link to this PR from an internal issue.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Consider adding a changelog entry for this change.
  • Confirm the readme and docs have been updated if necessary.

@github-actions github-actions Bot added the size/XL May be very hard to review label Oct 9, 2026
@mbg
mbg changed the base branch from main to mbg/diagnostics/failed-sarif October 9, 2026 22:42
@mbg
mbg force-pushed the mbg/macos27/warn branch from b6de93b to 8baf1db Compare October 9, 2026 22:44
@mbg
mbg added this pull request to stack #4224 October 9, 2026 22:45

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XL May be very hard to review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant