CI: CodeQL Modify: Unbounded loop driven by profile field - #2340
Merged
Conversation
xsscx
requested review from
ChrisCoxArt,
colourbill-ctrl,
dwtza and
maxderhak
as code owners
August 28, 2026 00:15
Contributor
There was a problem hiding this comment.
Pull request overview
Updates the repo’s CodeQL maintenance surface to reduce/triage false positives for the unbounded-profile-loop query (notably recognizing Begin() as an invariant-establishing setup method), adds a checked-in query test harness, and bumps the pinned CodeQL CLI bundle used by CI bootstrap.
Changes:
- Bump pinned CodeQL bundle to 2.26.4 (with updated SHA-256) in CI bootstrap paths and document the lockstep update requirement.
- Refine
unbounded-profile-loopquery logic (narrow exclusions + treatBegin()as a setup/guard method) and add a minimal CodeQL query test pack + fixture. - Add/extend maintainer guidance for CodeQL alert triage (reachability/guard propagation expectations).
Reviewed changes
Copilot reviewed 13 out of 13 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| docs/codeql.md | Documents the CodeQL bundle pin and adds triage guidance for unbounded-profile-loop false positives. |
| .github/workflows/ci-preflight-safety.yml | Updates the pinned CodeQL bundle version + SHA for the preflight bootstrap. |
| .github/workflows/ci-codeql-security.yml | Updates the pinned CodeQL bundle version + SHA for the CodeQL workflow bootstrap. |
| .github/skills/sanitizer-repro/SKILL.md | Adds a “reachability first” step when reproducing CodeQL alerts. |
| .github/prompts/reproduce-security-issue.prompt.md | Adds explicit “tool reachability” guidance for CodeQL-driven reports. |
| .github/codeql-queries/unbounded-profile-loop.ql | Adjusts guard detection (including Begin) and adds narrow exclusions for known bounded internal fields. |
| .github/codeql-queries/test/unbounded-profile-loop/UnboundedProfileLoop.qlref | Adds a CodeQL test reference for the query. |
| .github/codeql-queries/test/unbounded-profile-loop/UnboundedProfileLoop.expected | Adds expected test output for the negative/positive control. |
| .github/codeql-queries/test/unbounded-profile-loop/case.cpp | Adds the C++ test fixture used by codeql test run. |
| .github/codeql-queries/test/qlpack.yml | Introduces a dedicated CodeQL test pack definition. |
| .github/codeql-queries/test/codeql-pack.lock.yml | Pins dependencies for the CodeQL test pack. |
| .github/codeql-queries/README.md | Documents how to run the checked-in query tests and the query’s updated guard assumptions. |
| .github/agents/maintainer-label-triage.agent.md | Adds guidance for distinguishing “alert-only” vs. “triaged” CodeQL-labeled issues. |
Contributor
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.
Suppressed comments (1)
.github/codeql-queries/test/unbounded-profile-loop/case.cpp:8
- The new C++ test fixture has an abbreviated license header (it references the ICC Software License but does not include the BSD 3-Clause conditions/disclaimer). Other repo C++ fixtures under
.github/include the full BSD 3-Clause header text (e.g.,.github/ci/regression/clut-avx2-benchmark.cpp). Please replace this header with the full standard header block.
/*
* Copyright (c) 2026 International Color Consortium.
* SPDX-License-Identifier: BSD-3-Clause
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the conditions in the
* ICC Software License are met.
*/
xsscx
enabled auto-merge (squash)
August 28, 2026 00:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Summary
#2313
Checklist
docs/build.mddocs/ctest.mdbase...HEADcontract matrix for cross-cutting changes:producer, consumer, build/runtime behavior, platform/toolchain boundary,
CI trigger, dependency owner, and local evidence
docs/python-packaging-release.mdfor PR and merge requirementsm_membersLegal Requirements
All official software projects hosted by the International Color Consoritum (ICC)
follows the open source software best practice policies. The International Color Consoritum IP policy governs ICC specification development and contributions to ICC open source software. Software contributions are also covered by the Contributor License Agreement (CLA).
Contributor License Agreements
Developers who wish to contribute code to be considered for inclusion
in ICC software must first complete a Contributor License Agreement
(CLA).
There is no cost or membership requirement to sign the ICC Contributor License Agreement (CLA). Please note that this is different from membership in the International Color Consortium (ICC). If your organization relies on our projects, please become a member. Membership dues are an essential source of funding and investment for these projects.
If you are an individual writing the code on your own time and you are SURE you are the sole owner of any intellectual property you contribute, you can sign the CLA as an individual contributor.
If you are writing the code as part of your job, or if there is any possibility that your employer might think they own any intellectual property you create, then you should use the Corporate Contributor Licence Agreement
License
ICC software is licensed under the BSD 3-Clause "New" or "Revised" License. Contributions to ICC software projects should abide by that license unless otherwised specified or approved by the ICC.
Copyright Notices
All new source files must begin with the ICC Copyright notice and include or reference the BSD 3-Clause "New" or "Revised" License.
INTELLECTUAL PROPERTY & PATENTS
Participation in ICC's development activities is subject to ICC's Patent Policy.
Maintainer Review Required
If you have questions, contact a listed Maintainer.