Live
AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCAI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPC
GitHub

GitHub Code Quality Actions Path Separation

AI SummaryPowered by AI

A dedicated workflow path for GitHub Code Quality actions is now generally available, distinguishing these runs from standard code scanning in history and billing reports. This change requires platform teams to update their monitoring filters and scripts that rely on the legacy actor or shared paths.

GitHub has introduced a distinct Actions path specifically for its CodeQL analysis workflows within GitHub Code Quality. Previously, these operations ran under the dynamic/github-code-scanning/codeql path with the github-advanced-security actor. The new implementation utilizes dynamic/github-code-quality/codeql, assigning it a unique identifier to separate its execution history from general code scanning activities.

Operational Impact on Monitoring and Billing

The primary implication for DevOps engineers involves the management of Actions usage reports. Because workflow run histories are now segregated, any existing dashboards or billing filters that aggregate all CodeQL runs under a single path will no longer capture 100% of activity if they do not explicitly account for both paths.

Practitioners must audit their current reporting logic to ensure it accounts for the new dynamic/github-code-quality/codeql identifier. If your organization relies on a single filter string or actor name (specifically looking only at github-advanced-security) to track security scanning costs and performance, you risk under-reporting usage metrics.

Maintenance of Existing Workflows

The transition is designed with backward compatibility in mind. Repositories currently enabled for Code Quality do not require immediate reconfiguration; they will continue operating as expected on the legacy path until updated or migrated by platform policy. However, any custom scripts that parse workflow logs to identify specific analysis runs must be modified.

For teams building automated dashboards using GitHub's API, this distinction means you may need to adjust query parameters if your logic assumes a monolithic code scanning actor for all static analysis tasks performed by CodeQL. The separation ensures that billing and usage data are attributed correctly between general security scans and the specific quality assurance runs.

What This Means For Practitioners

The architectural shift is primarily administrative rather than functional, but it demands attention from platform engineering teams responsible for cost tracking. You should update your monitoring scripts to filter on both paths or explicitly exclude one if you wish to isolate legacy data.

  • Update Filters: Modify Actions usage reports that currently aggregate all CodeQL runs under the old path.
  • Audit Dashboards: Review any visualizations relying on github-advanced-security to ensure they still capture quality-specific metrics.
Originally published atGitHub Changelog