From d3da32ddb3063b197f4d5c9df7ae1feca3c999f3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 27 Sep 2026 21:25:06 +0900 Subject: [PATCH] fix(ci): align CodeQL runner contract with trusted main routing --- ..._and_codeql_dispatch_runner_image_contract.py | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/tests/test_scheduler_and_codeql_dispatch_runner_image_contract.py b/tests/test_scheduler_and_codeql_dispatch_runner_image_contract.py index 8f934b4fda..6ba6afe4c7 100644 --- a/tests/test_scheduler_and_codeql_dispatch_runner_image_contract.py +++ b/tests/test_scheduler_and_codeql_dispatch_runner_image_contract.py @@ -47,10 +47,22 @@ def test_hourly_review_repair_uses_explicit_supported_image(self) -> None: self.assertIn("labels: [self-hosted, linux, x64]", workflow) def test_codeql_pr_uses_explicit_supported_image(self) -> None: - """Require detect-languages, analyze-head, and the coordinator to pin Ubuntu 24.04.""" + """Require trusted-main control routing and Ubuntu fallback for all three jobs.""" workflow = CODEQL_PR.read_text(encoding="utf-8") self.assertNotIn("runs-on: ubuntu-latest", workflow) - self.assertEqual(workflow.count("runs-on: ubuntu-24.04"), 3) + selectors = [ + line.strip() for line in workflow.splitlines() + if line.strip().startswith("runs-on:") + ] + self.assertEqual(len(selectors), 3) + for selector in selectors: + self.assertIn( + "github.workflow_ref == 'ContextualWisdomLab/.github/.github/workflows/codeql-pr.yml@refs/heads/main'", + selector, + ) + self.assertIn('"group":"CWL central control"', selector) + self.assertIn('"labels":["self-hosted","linux","x64"]', selector) + self.assertIn("|| '\"ubuntu-24.04\"'", selector) def test_codeql_scan_dispatch_uses_explicit_supported_image(self) -> None: """Require validation, scan, and attempt wake jobs in the dedicated group."""