Skip to content

packages/vscode-extension/SUMMARY.md claims a CodeQL scan passed; no CodeQL scan exists #5965

Description

@yinlianghui-tw

Found while fixing #5408 (stale CodeQL badge in README.md). Out of that
card's file surface (README.md only), so filed separately rather than
fixed there.

Measured

packages/vscode-extension/SUMMARY.md line ~164:

✅ **安全扫描**
- CodeQL扫描通过
- 无安全漏洞
- 无已知问题

("Security scan — CodeQL scan passed — no security vulnerabilities — no
known issues.")

Same underlying fact #5408 established: this repository has no
dynamic/github-code-scanning/codeql workflow entry and no codeql.yml
CodeQL was never set up here, default-setup or otherwise. A claim that a
CodeQL scan "passed" is stronger than #5408's badge (which merely implied a
scan runs) — this asserts a specific run outcome for a scan that does not
exist.

Note on this file's nature

This reads like a one-off, hand-written status summary (possibly from an AI
coding session) rather than living/maintained documentation — worth checking
whether the file should be corrected, or removed as a stale artifact, when
triaged. Flagging as finding rather than a concrete fix instruction for
that reason.

Scope

packages/vscode-extension/SUMMARY.md only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions