Skip to content

build(deps): bump github/codeql-action from 4.37.9 to 4.38.0 - #57

Merged
sumitake merged 3 commits into
mainfrom
cursor/codeql-action-v4.38.0-b3ec
Sep 14, 2026
Merged

sumitake merged 3 commits into
mainfrom
cursor/codeql-action-v4.38.0-b3ec

Conversation

@sumitake

@sumitake sumitake commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

Companion for #56. Recreates the same CodeQL action pin bump on current main so CI can go green.

Dependabot #56 only updates .github/workflows/codeql.yml (init / autobuild / analyze from cdf488f… v4.37.9 to b96794f… v4.38.0). Its tip is 1 commit behind main and CI is red for unrelated reasons (shell bats test 148 flake; repository-metadata SPDX check). This PR applies that same pin-only change on current main and does not touch other workflows.

repository-metadata on the first tip failed because REVIEWED_ACTION_PINS still expected cdf488f… / v4.37.9. The reviewed pin table in scripts/check_workflow_policy.py now matches b96794f015dfd88f77b49b1c93e0fa7110f94c63 / v4.38.0. No tests hardcoded the old SHA.

Ops can close #56 after this lands.

Summary

Pin github/codeql-action init/autobuild/analyze to b96794f015dfd88f77b49b1c93e0fa7110f94c63 (# v4.38.0), matching Dependabot #56, and update the reviewed pin table so workflow policy accepts it.

Test plan

  • Diff matches build(deps): bump the actions-minor-patch group with 3 updates #56 for codeql.yml: three SHA/comment bumps only

  • REVIEWED_ACTION_PINS["github/codeql-action"] is ("b96794f015dfd88f77b49b1c93e0fa7110f94c63", "v4.38.0")

  • python3 scripts/check_workflow_policy.py .github/workflows reports workflow policy checks passed

  • python3 -m unittest tests.repository.test_workflow_policy -v — 41 tests, OK

  • GitHub Actions CI on this PR (CodeQL + existing required checks)

  • python3 -m unittest discover -s tests -p 'test_*.py' — not re-run in full; application code unchanged

  • Relevant new tests were written FIRST and observed to fail (TDD) — N/A (pin bump only)

PUBLIC-SAFETY checklist

  • This PR contains no deployment identifiers
  • This PR contains no secrets
  • This PR contains no real logs, real configuration, or real runtime state
  • python3 scripts/sanitize_public.py --tracked reported sanitization passed
  • python3 scripts/check_repository_metadata.py — N/A (does not touch governance/repository metadata)

Additional context

v4.38.0 notes (from Dependabot #56): toolcache unused-bundle cleanup on GitHub-hosted runners, Linux Arm64 CodeQL bundle support, default bundle 2.27.0.

Open in Web Open in Cursor 

Companion to Dependabot #56: pin init/autobuild/analyze to
b96794f015dfd88f77b49b1c93e0fa7110f94c63 (v4.38.0) on current main.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 911b1798-919f-4f64-b77b-eaa8816e1715


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T16:52:53.382846Z c6f3da1 New commits
🔒 Security Review ✅ Completed 2026-09-14T16:54:01.688103Z c6f3da1 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eaf4c00bb3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Update the reviewed pin table with this workflow bump

On every CI run for this commit, the repository-metadata job invokes python3 scripts/check_workflow_policy.py .github/workflows from .github/workflows/ci.yml, but REVIEWED_ACTION_PINS still permits only CodeQL v4.37.9 at cdf488f…. The checker therefore rejects each of these new v4.38.0 references and exits 1, so the required CI job cannot pass until the table in scripts/check_workflow_policy.py is updated alongside the workflow.

Useful? React with 👍 / 👎.

cursoragent and others added 2 commits September 14, 2026 16:33
Update REVIEWED_ACTION_PINS so check_workflow_policy.py accepts the
same CodeQL SHA/release already used in codeql.yml.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@sumitake
sumitake merged commit 37020c7 into main Sep 14, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants