chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.6 - #922
chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.6#922dependabot[bot] wants to merge 5 commits into
Conversation
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.6. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.0...5595cca) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
OpenCode Review Overview
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
|
|
CI RCA and root fix at exact head First failing boundary:
Remedy: align Proof before publication:
Fresh hosted exact-head checks remain authoritative; no approval claim is made. |
|
@opencode-agent review Evaluate exact current head |
|
Exact-head source review note for |
seonghobae
left a comment
There was a problem hiding this comment.
Independent exact-head review for Dependabot-authored 0ec1895e110e2e9d9ebbed92684acfab94d947f7 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.
Reviewed the complete two-workflow patch. It updates only full-SHA github/codeql-action/{init,analyze,upload-sarif} references from 4.37.0/4.37.5 to upstream 4.37.6 commit 5595ccaf912efad79be6eef63a5619ff05969be3; triggers, permissions, checkout refs, language/build matrices, categories, upload policy, and fail-closed behavior remain unchanged. The modified CodeQL PR workflow and all seven directly triggered exact-head security/supply-chain workflows are terminal-success, with no inline thread.
Approved as a non-author source review. This approval does not bypass any remaining last-push, automated-review, required-context, or protected-branch condition.
|
Exact-current-head automated review request for A qualifying non-author human approval is now anchored to this Dependabot-authored head. Independently review the exact two-workflow patch updating only full-SHA CodeQL init/analyze/upload-sarif pins to official 4.37.6 while preserving triggers, permissions, checkout identity, language/build matrices, categories, and upload behavior. All eight exact-head hosted workflows are terminal-success and no thread exists. Keep the exact head unchanged. Do not synthesize author approval, update the branch, merge, release, or bypass protection. @opencode-agent review |
Rate Limit Exceeded
|
CWE-829: init, analyze, and upload-sarif must share one immutable SHA so a Dependabot split cannot execute a second unreviewed control sphere.
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
|
Closing as superseded by the broader single-version CodeQL action update in #918. #918 already carries the same CodeQL 4.37.6 init migration and the shared #918 is intentionally Draft because its current branch also contains unrelated trusted-uv materializer changes. Rebuild the canonical update there from protected |
Pull request was closed
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github/codeql-action/init from 4.37.0 to 4.37.6.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
5595ccaMerge pull request #4071 from github/update-v4.37.6-6a9359a1bec9c757Add change note for PR 407045c8742Update changelog for v4.37.66a9359aMerge pull request #4070 from github/mbg/remote-address/change-file-default065cdc0ChangeDEFAULT_CONFIG_FILE_NAMEf99dd5aMerge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.21804b21Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a13020a2fRebuild93c3a5aUpdate changelog and version after v4.37.5d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)