CodeQL analysis failed: no buildable languages detected in PR
Fixes CodeQL failing with 'no buildable languages detected' on a PR. Use when the code-scanning check errors instead of reporting findings. Pins the language list explicitly, replaces autobuild with the project's real build steps for compiled languages, or skips analysis for docs-only PRs. Trigger: 'no buildable languages' in the CodeQL job log.
TL;DR
Tell CodeQL exactly which languages to analyze instead of letting it guess, and give compiled languages a real build: replace the autobuild step with your project's normal build commands between the init and analyze steps. If the PR only touches docs or config, exclude those paths so the check stops erroring on non-code changes.
The error
Error: No buildable languages were detected. Please check that your repository contains code in a supported language.Fix it
- Read the init step log to see what CodeQL tried to detect.
Expected: the detected-language list is empty or lists the wrong languages - that is the whole problem.
- Pin the languages explicitly in the workflow's init step using the
languagematrix with the languages your repo actually contains (for example javascript-typescript and python).
Expected: the init log reports exactly the languages you pinned.
- Give compiled languages a real build. Replace the autobuild step with your project's own build commands (the same compile or test build developers run) placed between the init and analyze steps.
Expected: the build runs under observation, extraction succeeds, and analyze produces findings instead of the error.
- For PRs that only touch docs or config, add those paths to
paths-ignorein the CodeQL config so the check does not error on non-code changes.
Expected: docs-only PRs skip analysis cleanly instead of failing.
- Re-run the workflow.
Expected: "Analysis complete" with findings (or zero findings) rather than the detection error.
Use this when
- CodeQL errors with "no buildable languages detected" on a PR
- The code-scanning check fails on PRs that do not change code
- Autobuild cannot build your project and you need analysis anyway
Not for this skill when
- CodeQL completes and reports vulnerabilities - triage the findings instead of touching the setup
- Analysis fails with out-of-memory - bump the runner size, the detection is fine
- You are scanning a language CodeQL does not support - pick a different scanner for that language
Variant phrasings
- codeql no buildable languages detected
- codeql autobuild failed
- github code scanning no languages detected
- codeql init no languages found
Why it happens
CodeQL's autobuild guesses your build system, and on polyglot repos, custom build setups, or docs-only PRs it guesses wrong or finds nothing to build. For compiled languages the analysis needs an observed compilation to extract anything, so "nothing to build" becomes "nothing detected" and the job errors instead of reporting zero findings.
Edge cases
- A failing autobuild is the most common real cause - custom build steps fix the majority of compiled-language repos
- Matrix builds need the language list set per job, not just once at the top
- Interpreted languages do not need a build step at all - a build-mode of none is valid for them
- PRs that only rename files can still trigger the error; paths-ignore covers those too
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_BWq9DOFvdvSfcTBg3N2RMg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.