Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
# Restores PR-head CodeQL coverage for this repo.
#
# History: commit 83ecc6e (PR #118, "ci: remove local governance workflows
# duplicated by central required workflows") deleted the previous local
# .github/workflows/codeql.yml on the assumption that the org-wide required
# workflow ruleset (ContextualWisdomLab, ruleset id 18156473) already runs
# ContextualWisdomLab/.github's central codeql-pr.yml against every PR here.
#
# That assumption was verified FALSE on 2026-09-02: ruleset 18156473 does not
# actually include codeql-pr.yml, so this repo has had zero CodeQL coverage on
# pull requests since #118 merged. This file is an interim, repo-local safety
# net until an org admin adds codeql-pr.yml to ruleset 18156473 (tracked
# separately — out of scope for a repo-level change). Remove this file once
# that ruleset fix is confirmed live.
#
# Language: "actions" only, verified against this repo's own file extensions
# (no first-party Python/JS-TS/Java-Kotlin source; the ~980 .c/.h/.hpp files
# under packrat/lib/ are vendored R package dependencies, not repo-authored
# code) and against the CodeQL analyses this repo has actually produced
# historically (always /language:actions, never anything else).
name: CodeQL

on:
pull_request:
branches: ["master"]
workflow_dispatch:

permissions:
contents: read

jobs:
analyze:
name: Analyze (actions)
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd

- name: Initialize CodeQL
uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8

Check warning on line 49 in .github/workflows/codeql.yml

View workflow job for this annotation

GitHub Actions / quality

49:82 [comments] too few spaces before comment: expected 2
with:
languages: actions
build-mode: none

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8

Check warning on line 55 in .github/workflows/codeql.yml

View workflow job for this annotation

GitHub Actions / quality

55:85 [comments] too few spaces before comment: expected 2
with:
category: "/language:actions"
3 changes: 3 additions & 0 deletions .jules/bolt.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,6 @@
## 2025-02-12 - R 언어에서 반복적인 mirt 모델 생성 시 불필요한 데이터프레임 부분집합 추출 최적화
**Learning:** R에서 데이터프레임의 특정 열을 추출하는 작업(`df[cols]`)은 O(N)의 메모리 복사를 수반합니다. `autoFIPC`에서 `mirt` 모델의 파라미터를 설정하거나 호출하는 과정 중에 `newformXDataK[colnames(newFormModel@Data$data)]` 코드가 반복해서 사용되었고, 심지어 `ncol()`을 위해 단순히 개수를 구할 때도 사용되어 불필요한 메모리 할당과 오버헤드를 초래했습니다.
**Action:** 조건문이나 반복문 내부에서 불필요하게 데이터프레임 부분집합 연산이 반복되지 않도록 외부에서 한 번만 `linkedFormData <- newformXDataK[colnames(newFormModel@Data$data)]`로 캐싱(caching)한 뒤, `ncol(linkedFormData)`와 `data = linkedFormData` 형태로 재사용하여 메모리 복사와 O(N) 오버헤드를 방지해야 합니다.
## 2025-02-13 - R 언어에서 데이터 프레임 불필요한 부분집합 추출 오버헤드 제거
**Learning:** R에서 열 이름을 얻기 위해 `colnames(df[cols])` 처럼 데이터 프레임을 서브셋팅(subsetting)하는 것은, 모든 해당 데이터를 복사하므로 불필요한 O(N) 메모리 할당 및 복사 오버헤드를 발생시킵니다.
**Action:** 단순히 열 이름 배열이 필요한 경우에는 `df[cols]`처럼 부분집합을 만들지 않고 기존에 확보된 열 이름 벡터(`cols`)를 그대로 재사용하여 O(1) 수준으로 불필요한 메모리 복사를 제거해야 합니다.
8 changes: 4 additions & 4 deletions R/aFIPC.R
Original file line number Diff line number Diff line change
Expand Up @@ -620,8 +620,8 @@ autoFIPC <-
IPDItemCount <- 0

# IPD target item checking
newFormColNames <- colnames(newformXDataK[colnames(newFormModel@Data$data)])
oldFormColNames <- colnames(oldformYDataK[colnames(oldFormModel@Data$data)])
newFormColNames <- colnames(newFormModel@Data$data)
oldFormColNames <- colnames(oldFormModel@Data$data)

# ⚡ Bolt: Vectorized match() to avoid dynamic array growth overhead inside a for loop
idxNew <- match(newformCommonItemNames, newFormColNames)
Expand Down Expand Up @@ -749,8 +749,8 @@ autoFIPC <-
}
}

newFormColNames <- colnames(newformXDataK[colnames(newFormModel@Data$data)])
oldFormColNames <- colnames(oldformYDataK[colnames(oldFormModel@Data$data)])
newFormColNames <- colnames(newFormModel@Data$data)
oldFormColNames <- colnames(oldFormModel@Data$data)

# ⚡ Bolt: Cache parameter indices to avoid O(N) linear search inside loop
newScaleParmsItemIdxCache <- split(seq_len(nrow(NewScaleParms)), NewScaleParms$item)
Expand Down
Loading