This isn't going to become a taint step, the workaround is the permanent solution
codeql_pack
pkg.bzl