chore(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 - #16
Merged
CodeSigils merged 1 commit intoJul 13, 2026
Conversation
CodeSigils
approved these changes
Jul 13, 2026
CodeSigils
left a comment
Owner
There was a problem hiding this comment.
Review: github/codeql-action/analyze 4.36.3 → 4.37.0
Changes
Updates codeql-action/analyze SHA from 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a to 99df26d4f13ea111d4ec1a7dddef6063f76b97e9 (v4.36.3 → v4.37.0).
Analysis
Identical to PR #15 — same SHA pin, same action version, same risk profile.
- Routine minor bump
- Sole change: SHA pin in
.github/workflows/codeql.yml:46 - Author Attribution Guard ✅
- lint ✅
- build/release ⏭️ (expected)
- CodeQL analyze failure on PR
⚠️ pre-existing — not caused by this change
Combined note
PRs #15 and #16 update two steps of the same action to the same version. Since both SHAs now point to v4.37.0, they share the same source tree. Minor version bump is well-tested upstream.
Verdict
Approved. Merge at your convenience.
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@54f647b...99df26d) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
CodeSigils
force-pushed
the
dependabot/github_actions/github/codeql-action/analyze-4.37.0
branch
from
July 13, 2026 08:08
e3ded37 to
28b27b6
Compare
CodeSigils
deleted the
dependabot/github_actions/github/codeql-action/analyze-4.37.0
branch
July 13, 2026 08:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github/codeql-action/analyze from 4.36.3 to 4.37.0.
Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
99df26dMerge pull request #3996 from github/update-v4.37.0-c7c896d7131c2707Add changenote for #397372df218Update changelog for v4.37.0c7c896dMerge pull request #3995 from github/update-bundle/codeql-bundle-v2.26.03f34ff0Add changelog note43bec09Update default bundle to codeql-bundle-v2.26.0f58f0d1Merge pull request #3973 from github/mbg/repo-props/config-file-shorthands7dc37cbMerge remote-tracking branch 'origin/main' into mbg/repo-props/config-file-sh...8e22350ThreadActionStatetoinitConfig69c9e8cMark somestatus-reportimports astype-only to avoid circular dependenciesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)