GitHub has introduced a distinct Actions path specifically for its CodeQL analysis workflows within GitHub Code Quality. Previously, these operations ran under the dynamic/github-code-scanning/codeql path with the github-advanced-security actor. The new implementation utilizes dynamic/github-code-quality/codeql, assigning it a unique identifier to separate its execution history from general code scanning activities.
Operational Impact on Monitoring and Billing
The primary implication for DevOps engineers involves the management of Actions usage reports. Because workflow run histories are now segregated, any existing dashboards or billing filters that aggregate all CodeQL runs under a single path will no longer capture 100% of activity if they do not explicitly account for both paths.
Practitioners must audit their current reporting logic to ensure it accounts for the new dynamic/github-code-quality/codeql identifier. If your organization relies on a single filter string or actor name (specifically looking only at github-advanced-security) to track security scanning costs and performance, you risk under-reporting usage metrics.
Maintenance of Existing Workflows
The transition is designed with backward compatibility in mind. Repositories currently enabled for Code Quality do not require immediate reconfiguration; they will continue operating as expected on the legacy path until updated or migrated by platform policy. However, any custom scripts that parse workflow logs to identify specific analysis runs must be modified.
For teams building automated dashboards using GitHub's API, this distinction means you may need to adjust query parameters if your logic assumes a monolithic code scanning actor for all static analysis tasks performed by CodeQL. The separation ensures that billing and usage data are attributed correctly between general security scans and the specific quality assurance runs.
What This Means For Practitioners
The architectural shift is primarily administrative rather than functional, but it demands attention from platform engineering teams responsible for cost tracking. You should update your monitoring scripts to filter on both paths or explicitly exclude one if you wish to isolate legacy data.
- Update Filters: Modify Actions usage reports that currently aggregate all CodeQL runs under the old path.
- Audit Dashboards: Review any visualizations relying on
github-advanced-securityto ensure they still capture quality-specific metrics.
