From b1de9b8f8fb9626ca22b81da0d96307fd4ce2296 Mon Sep 17 00:00:00 2001 From: Ruslan Konviser Date: Tue, 14 Jul 2026 14:07:31 +0200 Subject: [PATCH 1/2] ci: x4 runner (not x8) + bump actions to latest Node-24 versions (removes Node-20 deprecation warnings) [skip ci] --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index fe254c8..3a85a5d 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,7 +24,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v7 - name: Initialize CodeQL uses: github/codeql-action/init@v2 From 0f9c1b9f50085235cf63e2c20046277652244ef1 Mon Sep 17 00:00:00 2001 From: evereq Date: Sun, 19 Jul 2026 14:11:25 +0200 Subject: [PATCH 2/2] ci: run CodeQL on self-hosted ARC runner (RUNNER_LINUX_X64_4) Migrate the CodeQL analyze job off GitHub-hosted ubuntu-latest onto our self-hosted ARC fleet via vars.RUNNER_LINUX_X64_4 (smallest pool per security-scan policy), keeping the ubuntu-latest fallback. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 3a85a5d..4f56492 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -11,7 +11,7 @@ on: jobs: analyze: name: Analyze - runs-on: ubuntu-latest + runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }} permissions: actions: read contents: read