openclaw/.github/workflows
Vincent Koc cd6efd1a42
chore(ci): add MCP process CodeQL shard
Adds the focused MCP/process/tool-execution CodeQL security shard and documents it in CI docs.

Proof:
- Branch CodeQL security run https://github.com/openclaw/openclaw/actions/runs/25132942030 passed on 9d8ca2bae7.
- New mcp-process-tool-boundary analysis 1200250367 returned 0 results.
- Branch open CodeQL alerts: none.
- Workflow Sanity, Blacksmith Testbox, Blacksmith Build Artifacts Testbox, and OpenGrep PR Diff passed.
2026-04-29 13:48:53 -07:00
..
auto-response.yml fix(triage): extract barnacle workflow 2026-04-25 17:43:08 -07:00
ci-build-artifacts-testbox.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
ci-check-testbox.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
ci.yml ci: fallback deadcode check for legacy targets 2026-04-29 13:50:27 +01:00
clawsweeper-dispatch.yml fix(ci): stop ClawSweeper dispatch PAT fallback 2026-04-29 13:26:02 -07:00
codeql-android-critical-security.yml ci: schedule android codeql shard (#73430) 2026-04-28 01:54:57 -07:00
codeql-critical-quality.yml ci: add codeql quality profile input (#74348) 2026-04-29 22:39:54 +08:00
codeql-macos-critical-security.yml ci: split macos codeql shard 2026-04-28 03:14:07 -07:00
codeql.yml chore(ci): add MCP process CodeQL shard 2026-04-29 13:48:53 -07:00
control-ui-locale-refresh.yml feat(i18n): align docs and ui locales 2026-04-29 10:25:47 -07:00
docker-release.yml fix(security): harden CodeQL secret ref validation 2026-04-27 13:53:27 -07:00
docs-agent.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
docs-sync-publish.yml ci: rebase docs sync with source preference 2026-04-24 18:58:53 +01:00
docs-translate-trigger-release.yml feat(i18n): align docs and ui locales 2026-04-29 10:25:47 -07:00
docs.yml ci: split docs-only push checks 2026-04-24 17:41:04 +01:00
duplicate-after-merge.yml ci: add duplicate PR cleanup workflow 2026-04-23 18:41:32 +01:00
full-release-validation.yml ci: speed up release validation 2026-04-29 19:55:37 +01:00
install-smoke.yml ci: shard release validation hotspots 2026-04-29 20:40:42 +01:00
labeler.yml ci: rename clawsweeper automation labels 2026-04-29 10:18:57 +01:00
live-media-runner-image.yml ci: preinstall ffmpeg for live media checks 2026-04-29 03:48:33 +01:00
macos-release.yml ci: keep pnpm alignment scoped to CI 2026-04-22 05:58:50 +01:00
maintainer-command-reactions.yml ci: rename clawsweeper automation labels 2026-04-29 10:18:57 +01:00
npm-telegram-beta-e2e.yml ci: harden npm telegram artifact upload 2026-04-27 22:13:21 +01:00
openclaw-cross-os-release-checks-reusable.yml ci: use same-run release package artifacts 2026-04-29 16:06:02 +01:00
openclaw-live-and-e2e-checks-reusable.yml ci: shard release validation hotspots 2026-04-29 20:40:42 +01:00
openclaw-npm-release.yml ci(release): use github runner for npm release gate 2026-04-23 16:49:53 +01:00
openclaw-release-checks.yml ci: speed up release validation 2026-04-29 19:55:37 +01:00
openclaw-scheduled-live-checks.yml ci: pass provider secrets to testbox 2026-04-28 04:24:15 +01:00
opengrep-precise-full.yml feat(security): add GHSA detector-review pipeline and OpenGrep CI workflows (#69483) 2026-04-30 02:42:20 +10:00
opengrep-precise.yml feat(security): add GHSA detector-review pipeline and OpenGrep CI workflows (#69483) 2026-04-30 02:42:20 +10:00
package-acceptance.yml ci: use same-run release package artifacts 2026-04-29 16:06:02 +01:00
parity-gate.yml fix: normalize QA model refs for parity gates 2026-04-28 23:01:58 +01:00
plugin-clawhub-release.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
plugin-npm-release.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
plugin-prerelease.yml fix(ci): gate plugin prerelease docker suite 2026-04-29 01:06:57 -07:00
qa-live-transports-convex.yml ci: reduce release runner queue pressure 2026-04-29 17:45:53 +01:00
sandbox-common-smoke.yml Revert "ci: use Blacksmith checkout cache" 2026-04-21 03:21:48 +01:00
stale.yml Adjust message for stale workflow 2026-04-26 20:31:00 -05:00
test-performance-agent.yml fix(ci): harden workflow checkouts 2026-04-28 01:37:00 -07:00
workflow-sanity.yml ci: move lightweight automation off blacksmith 2026-04-22 15:44:34 +01:00