ci: review-pin codeql-action v4.37.9 and setup-buildx-action v4.3.0 - #47
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Companion for Dependabot GitHub Actions bumps.
check_workflow_policy.pyrejects Dependabot-only SHA edits unlessREVIEWED_ACTION_PINSand the trailing# <release>comments move in the same change.Verified against upstream tags:
github/codeql-actionv4.37.9^{}→cdf488f595d80d6e07e03d4674febd5ab45fa938(init, autobuild, and analyze stay on the same SHA)docker/setup-buildx-actionv4.3.0/v4→37fe631027851001ddb9b187196cc803df7f5f0eDependabot #46's container job already passed with the v4.3.0 pin, so this is not an untested major.
After merge, close
sumitake/GitHub-ActionRunner#45and#46as superseded.