You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeQL扫描Java Maven仓库失败:mvn命令未找到求助

Fix CodeQL Maven Build Failure on GitHub Actions

Root Cause

The ubuntu-latest GitHub Actions runner doesn't include Maven pre-installed. The autobuild script detects your pom.xml but fails to execute mvn because the command isn't available. Skipping autobuild skips compilation entirely, leaving CodeQL with no bytecode to analyze.

Corrected Workflow Configuration

Update your codeql.yml to replace the Autobuild step with manual build commands that install Maven and compile your code:

name: "CodeQL"

on:
  push:
    branches: [ "master" ]
  pull_request:
    branches: [ "master" ]

jobs:
  analyze:
    name: Analyze
    runs-on: [ubuntu-latest]
    permissions:
      actions: read
      contents: read
      security-events: write

    strategy:
      fail-fast: false
      matrix:
        language: [ 'java' ]

    steps:
    - name: Checkout repository
      uses: actions/checkout@v3

    - name: Initialize CodeQL
      uses: github/codeql-action/init@v2
      with:
        languages: ${{ matrix.language }}

    # Replace Autobuild with manual Maven installation and build
    - name: Install Maven and build project
      run: |
        sudo apt update
        sudo apt install -y maven
        mvn clean package -DskipTests -B -V

    - name: Perform CodeQL Analysis
      uses: github/codeql-action/analyze@v2
      with:
        category: "/language:${{matrix.language}}"

Critical Details

  • Maven Installation: Always run sudo apt update before installing Maven to refresh the package index—this is likely why your earlier manual install attempt failed.
  • Pom.xml Validation: Ensure your pom.xml is in the repository root and correctly maps to your source structure (src/com/org/proj/).
  • Build Flags: -DskipTests skips test execution to speed up CI runs; remove it if you want tests to run. -B enables batch mode (CI-friendly) and -V prints version info for debugging.

Verification Steps

After pushing the updated workflow:

  1. Confirm Maven installs without errors in the Actions log.
  2. Check that mvn clean package completes successfully and generates bytecode.
  3. Verify CodeQL analysis runs and detects your compiled Java code.

内容的提问来源于stack exchange,提问作者Dániel Kőcs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 22:23:08