diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0c617b5..5efcda9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -57,6 +57,9 @@ jobs: const isForkPullRequest = Boolean( pullRequest && pullRequest.head.repo.full_name !== pullRequest.base.repo.full_name, ); + const isDependabotPullRequest = Boolean( + pullRequest && pullRequest.user?.login === 'dependabot[bot]', + ); const requiredChecks = []; if (process.env.JS_CHANGED === 'true') { @@ -81,6 +84,13 @@ jobs: return; } + if (isDependabotPullRequest) { + core.info( + `Skipping CodeQL gate for Dependabot pull request ${pullRequest.number}; GitHub-managed CodeQL default setup does not run Analyze on Dependabot-authored PRs.`, + ); + return; + } + const ref = context.payload.pull_request?.head?.sha || context.sha; const owner = context.repo.owner; const repo = context.repo.repo;