chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: bump vendor/zoekt with CodeQL security fixes - #1141

Merged
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes
Apr 21, 2026
Merged

chore: bump vendor/zoekt with CodeQL security fixes#1141
msukkari merged 3 commits into
mainfrom
msukkari/zoekt-codeql-fixes

Conversation

@msukkari

@msukkarimsukkari commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps vendor/zoekt from da9bf1a3 (current main — zoekt upstream sync) to 945c3e96, which includes:

  1. chore: resolve open CodeQL security alerts zoekt#13 (open) — resolves all 12 open CodeQL alerts on zoekt:

    • go/clear-text-logging (high): redact URL userinfo before logging git clone args in gitindex/clone.go.
    • go/incorrect-integer-conversion (high): use size-matched parsers in api.go (Atoi for tenantID) and cmd/zoekt-sourcegraph-indexserver/sg.go (ParseUint(_,10,32) for SG_ID).
    • actions/missing-workflow-permissions (medium × 8): add top-level permissions: contents: read to ci.yml and buf-breaking-check.yml.
    • actions/untrusted-checkout/high (high): switch semgrep.yml trigger from pull_request_target to pull_request so PR code is no longer checked out in a trusted context with access to secrets.
  2. Carries through chore: bump go-git/v5 to 5.18.0 (GHSA-3xc5-wrhm-f963) zoekt#11 (merged) — go-git/v5 5.17.0 → 5.18.0 for GHSA-3xc5-wrhm-f963 (Dependabot Filter symbols by kind #16).

  3. Carries through chore: bump grpc and otel to patch GHSA alerts zoekt#12 (merged) — google.golang.org/grpc 1.75.0 → 1.80.0 and go.opentelemetry.io/otel* 1.42.0/1.33.0 → 1.43.0 for Dependabot Add 'install' event that is fired once on first run #11 (critical), FR: Support indexing code hosted on a local Bitbucket instance #14 (medium), and Support Line Number Highlighting #15 (high).

These last two weren't in #1140's final squash because their respective zoekt merges landed after the Sourcebot PR merged.

Important

The submodule pointer in this PR currently references the feature-branch tip of sourcebot-dev/zoekt#13 (945c3e96). Once #13 merges to zoekt@main, this pointer must be re-pinned to the resulting merge commit before this PR lands.

Test plan

  • yarn build — full monorepo build passes topologically across all 10 packages.
  • yarn test — all test workspaces pass: queryLanguage 269/269, shared 32/32, backend 122/122, web 295/295.
  • go build -C vendor/zoekt -o bin ./cmd/... — all 18 zoekt binaries build.
  • go build ./... and go test -count=1 -short ./... pass across all 24 zoekt packages.
  • Dev stack end-to-end: fresh-indexed all three configured connections (GitHub sourcebot, GitLab gitlab-org/cli, Bitbucket atlassian/jira-rest-java-client), all 19 documented search features work, cross-host repo:, sym:, streaming search, /api/source, and /api/repos all return expected data.

Summary by CodeRabbit

  • Chores
    • Updated a vendored dependency to a newer revision to keep bundled tooling current.
    • Minor maintenance: pointer updated; no public APIs or user-facing behavior changed.

Pulls in sourcebot-dev/zoekt#13 (open), which resolves all open
CodeQL security alerts on the zoekt repo:
- go/clear-text-logging (high) in gitindex/clone.go
- go/incorrect-integer-conversion (high) in api.go and
zoekt-sourcegraph-indexserver/sg.go
- actions/missing-workflow-permissions (medium x8) in ci.yml and
buf-breaking-check.yml
- actions/untrusted-checkout/high (high) in semgrep.yml
Also carries through the dependency bumps from sourcebot-dev/zoekt#11
and #12 (go-git 5.18.0, grpc 1.80.0, otel 1.43.0) that were merged
after #1140 so weren't included when main shipped the original zoekt
sync.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@msukkari your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ba40bb2e-f508-484c-83dc-d00f1008ab39

📥 Commits

Reviewing files that changed from the base of the PR and between b5682ca and ae0d18f.

📒 Files selected for processing (1)
  • vendor/zoekt
✅ Files skipped from review due to trivial changes (1)
  • vendor/zoekt

Walkthrough

Updates the vendor/zoekt submodule reference from commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e, changing the vendored zoekt code included in the repository.

Changes

Cohort / File(s)Summary
Vendored Dependency Update
vendor/zoekt
Submodule commit reference updated from da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9 to df983ea1170b43829f4317660bdf2345791f350e.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: bumping the vendor/zoekt submodule to include CodeQL security fixes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/zoekt-codeql-fixes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@vendor/zoekt`:
- Line 1: The vendor/zoekt submodule is pointing to the feature branch tip
commit 945c3e96 (msukkari/codeql-fixes) which is unstable; wait for
sourcebot-dev/zoekt#13 to be merged to main, then update the vendor/zoekt
gitlink to the exact merge commit on zoekt@main (replace the current
msukkari/codeql-fixes pointer), run git submodule sync && git submodule update
--init --recursive to fetch the new commit, and re-run the project tests to
confirm the merge commit works correctly before merging this PR.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d66a348d-86e1-4409-a4c3-26474ecdc36b

📥 Commits

Reviewing files that changed from the base of the PR and between 9d3bb1b and 4001a1b.

📒 Files selected for processing (1)
  • vendor/zoekt

Comment threadvendor/zoekt Outdated
@@ -1 +1 @@
Subproject commit da9bf1a3c96b438268e2692c4b4fd7a3d341c2c9
Subproject commit 945c3e96b253d242b2f2f31df872e81cacaa3bf3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Submodule points to feature branch instead of main branch.

The submodule currently references commit 945c3e96 from the feature branch msukkari/codeql-fixes. As stated in the PR objectives, this pointer must be updated to the eventual merge commit on zoekt@main once sourcebot-dev/zoekt#13 is merged.

Referencing a feature branch tip is risky because:

  • The branch may be rebased, force-pushed, or deleted after merging
  • This breaks reproducibility and can cause git submodule update failures
  • Production submodules should point to stable commits on the main branch

Action required: Do not merge this PR until:

  1. sourcebot-dev/zoekt#13 is merged to main
  2. The submodule pointer is updated to reference the merge commit on main
  3. Testing is re-run to confirm the merge commit works correctly
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@vendor/zoekt` at line 1, The vendor/zoekt submodule is pointing to the
feature branch tip commit 945c3e96 (msukkari/codeql-fixes) which is unstable;
wait for sourcebot-dev/zoekt#13 to be merged to main, then update the
vendor/zoekt gitlink to the exact merge commit on zoekt@main (replace the
current msukkari/codeql-fixes pointer), run git submodule sync && git submodule
update --init --recursive to fetch the new commit, and re-run the project tests
to confirm the merge commit works correctly before merging this PR.

msukkariand others added 2 commits April 20, 2026 23:20
sourcebot-dev/zoekt#13 merged as 7c6c629f. Updating the submodule
pointer from the feature-branch tip (945c3e96) to the merge commit
on main so vendor/zoekt tracks canonical history before merging.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
sourcebot-dev/zoekt#10 was squash-merged into zoekt@main, which
flattened the merge commit and left GitHub reporting the fork as 108
commits behind sourcegraph/zoekt:main even though all upstream content
was present. Fixed by performing a 'git merge -s ours upstream/main'
on zoekt@main: this records upstream/main as a second parent without
changing any files, restoring the ancestry link.
Bumping this submodule pointer from 7c6c629f (the previous main tip)
to df983ea1 (the new merge-ours commit). The vendored tree content is
byte-identical to 7c6c629f; only the commit graph is different.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@msukkari

Copy link
Copy Markdown
ContributorAuthor

Bumped vendor/zoekt to df983ea1 to fix the fork-ancestry issue that made GitHub report sourcebot-dev/zoekt as 108 commits behind sourcegraph/zoekt:main.

Root cause:sourcebot-dev/zoekt#10 was squash-merged, which collapsed the merge commit into a single-parent commit. The upstream content was present in the tree but upstream/main was no longer an ancestor of origin/main, so GitHub's fork-comparison view kept flagging the fork as behind.

Fix: ran git merge -s ours upstream/main on zoekt@main. This records upstream/main as a second parent of main without modifying any files. The zoekt tree at df983ea1 is byte-identical to 7c6c629f — only the commit graph changed. sourcebot-dev/zoekt now shows 0 commits behind sourcegraph/zoekt:main.

Impact on this PR: none functionally — the vendored content didn't change. The submodule pointer is now on the canonical main tip of the fork.

@msukkari
msukkari merged commit 48ad44d into mainApr 21, 2026
8 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Apr 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari