Skip to content

upload-sarif 3.30.4 silently stopped uploading (2025-09-25) #3156

Description

@TWiStErRob
Image

The only difference between the below two runs is the upload-sarif version.
The file being uploaded is identical: ghlint.sarif.json

3.30.3: https://github.com/TWiStErRob/net.twisterrob.astro/actions/runs/18020471393/job/51276343360?pr=275#step:5:1
Image
The corresponding reusable workflow in case you want to see the usage: TWiStErRob/github-workflows@209b85b

3.30.4: https://github.com/TWiStErRob/net.twisterrob.astro/actions/runs/18020535044/job/51276572449?pr=276#step:5:1
Image
The corresponding reusable workflow in case you want to see the usage: TWiStErRob/github-workflows@0699579

Workaround

-        uses: github/codeql-action/upload-sarif@v3
-        uses: github/codeql-action/upload-sarif@v3.30.4
-        uses: github/codeql-action/upload-sarif@303c0aef88fc2fe5ff6d63d3b1596bfd83dfa1f9
+        uses: github/codeql-action/upload-sarif@v3.30.3
+        uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3

Activity

  1. mbg commented on Sep 25, 2025

    @mbg
    Member

    Hi @TWiStErRob 👋🏻

    I think the problem here is probably the .json extension. We recently made some changes and probably (inadvertently) introduced an assumption that files used with the upload-sarif action always have a .sarif extension.

    If you want to avoid pinning the older version of the Action, you could change the extension of your file from .json to .sarif before using upload-sarif with it.

  2. self-assigned this
    on Sep 25, 2025
  3. added
    bugSomething isn't working
    on Sep 25, 2025
  4. TWiStErRob commented on Sep 25, 2025

    @TWiStErRob
    Author

    Thanks! Makes sense. Will give it a try.

  5. TWiStErRob commented on Sep 25, 2025

    @TWiStErRob
    Author

    Depending on whether you want to support again it or not - if this is indeed the issue - will you make it clear if it's not supported via an error or at least a warning?

  6. added a commit that references this issue on Sep 25, 2025
  7. TWiStErRob commented on Sep 25, 2025

    @TWiStErRob
    Author

    Workaround by rename confirmed working.

    Image
  8. mbg commented on Sep 25, 2025

    @mbg
    Member

    Depending on whether you want to support again it or not - if this is indeed the issue - will you make it clear if it's not supported via an error or at least a warning?

    This was unintentional, so I have put together #3157 to restore the previous behaviour for non-.sarif files. I've also included a check that something was actually uploaded and a warning will be logged if not; hopefully that shouldn't be happening once that's merged and shipped, but I added it just in case.

    Workaround by renaming confirmed working.

    Thanks for confirming!

  9. mbg commented on Sep 26, 2025

    @mbg
    Member

    We have released v3.30.5 of the CodeQL Action which includes an initial fix for this. You should be able to upgrade to that version now, if you want.

  10. mbg commented on Oct 10, 2025

    @mbg
    Member

    Closing this now since we have not observed any further issues since we fixed this.

  11. TWiStErRob commented on Oct 10, 2025

    @TWiStErRob
    Author

    Agreed, thank you for the quick turnaround on the fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions