Visitar URL original
Properly Support multi-project repos · Issue #4199 · github/codeql-action · GitHub
Skip to content

Properly Support multi-project repos #4199

Description

@GregJohnStewart

Hello, Came across the CodeQL action but it looks like I am not really able to use it effectively as I have a monorepo that has multiple sub-projects.

Main issues:

  1. While main syntax of the workflow is capable of being configured to focus on just one sub-project, it is cumbersome to do so.
  2. The integration with GitHub (at the project level) simply does not support the practice at all; does not separate per sub-project, but shows an aggregation of all projects

Any way we can get to where this is doable, or am I just not finding how to do this? Example of what I have going here: https://github.com/Epic-Breakfast-Productions/ebp-ci/blob/main/.github/workflows/quarkus-ci-pipeline.yml#L33

Activity

  1. hvitved commented on Oct 7, 2026

    @hvitved

    Hi 👋

    Monorepos are indeed handled as ordinary repos, which means that alerts are generated for the whole repo, and it is not possible to have per-sub-project alerts.

    What is possible, though, is to define individual scanning configurations per sub project, using advanced setup, but as I said, alerts will still aggregate up to the repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions