mirror of
https://github.com/openclaw/openclaw.git
synced 2026-06-03 15:44:06 +00:00
Extract shared normalization/coercion helpers into private @openclaw/normalization-core workspace package while preserving existing plugin SDK helper subpaths.\n\nAlso keeps direct normalization-core imports internal, wires UI/build/loader resolution, and replaces the slow PR network CodeQL lane with a fast added-line boundary scan while retaining full CodeQL for scheduled/manual runs.\n\nVerification: local moved tests, plugin SDK boundary tests, extension loader tests, agents-support shard, UI build/test, build artifacts, lint, workflow guards, autoreview, and GitHub CI passed on PR head 963d893715.
38 lines
960 B
YAML
38 lines
960 B
YAML
name: openclaw-codeql-network-runtime-boundary-critical-quality
|
|
|
|
disable-default-queries: true
|
|
|
|
queries:
|
|
- uses: ./.github/codeql/openclaw-boundary/queries/raw-socket-callsite-classification.ql
|
|
- uses: ./.github/codeql/openclaw-boundary/queries/managed-proxy-runtime-mutation.ql
|
|
|
|
paths:
|
|
- src/cli/gateway-cli/run-loop.ts
|
|
- src/infra/gateway-lock.ts
|
|
- src/infra/jsonl-socket.ts
|
|
- src/infra/net
|
|
- src/infra/push-apns-http2.ts
|
|
- src/infra/ssh-tunnel.ts
|
|
- src/proxy-capture
|
|
- extensions/codex-supervisor/src/json-rpc-client.ts
|
|
- extensions/irc/src
|
|
- extensions/qa-lab/src
|
|
- packages/net-policy/src
|
|
|
|
paths-ignore:
|
|
- "**/node_modules"
|
|
- "**/coverage"
|
|
- "**/*.generated.ts"
|
|
- "**/*.bundle.js"
|
|
- "**/*-runtime.js"
|
|
- "**/*.test.ts"
|
|
- "**/*.test.tsx"
|
|
- "**/*.e2e.test.ts"
|
|
- "**/*.e2e.test.tsx"
|
|
- "**/*test-support*"
|
|
- "**/*test-helper*"
|
|
- "**/*mock*"
|
|
- "**/*fixture*"
|
|
- "**/*bench*"
|
|
- "extensions/diffs/assets/**"
|