build(deps): bump github/codeql-action from 4.37.9 to 4.38.0 - #57
Conversation
Companion to Dependabot #56: pin init/autobuild/analyze to b96794f015dfd88f77b49b1c93e0fa7110f94c63 (v4.38.0) on current main. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eaf4c00bb3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| persist-credentials: false | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 | ||
| uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 |
There was a problem hiding this comment.
Update the reviewed pin table with this workflow bump
On every CI run for this commit, the repository-metadata job invokes python3 scripts/check_workflow_policy.py .github/workflows from .github/workflows/ci.yml, but REVIEWED_ACTION_PINS still permits only CodeQL v4.37.9 at cdf488f…. The checker therefore rejects each of these new v4.38.0 references and exits 1, so the required CI job cannot pass until the table in scripts/check_workflow_policy.py is updated alongside the workflow.
Useful? React with 👍 / 👎.
Update REVIEWED_ACTION_PINS so check_workflow_policy.py accepts the same CodeQL SHA/release already used in codeql.yml. Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
Companion for #56. Recreates the same CodeQL action pin bump on current
mainso CI can go green.Dependabot #56 only updates
.github/workflows/codeql.yml(init/autobuild/analyzefromcdf488f…v4.37.9 tob96794f…v4.38.0). Its tip is 1 commit behindmainand CI is red for unrelated reasons (shell bats test 148 flake; repository-metadata SPDX check). This PR applies that same pin-only change on currentmainand does not touch other workflows.repository-metadataon the first tip failed becauseREVIEWED_ACTION_PINSstill expectedcdf488f…/v4.37.9. The reviewed pin table inscripts/check_workflow_policy.pynow matchesb96794f015dfd88f77b49b1c93e0fa7110f94c63/v4.38.0. No tests hardcoded the old SHA.Ops can close #56 after this lands.
Summary
Pin
github/codeql-actioninit/autobuild/analyze tob96794f015dfd88f77b49b1c93e0fa7110f94c63(# v4.38.0), matching Dependabot #56, and update the reviewed pin table so workflow policy accepts it.Test plan
Diff matches build(deps): bump the actions-minor-patch group with 3 updates #56 for
codeql.yml: three SHA/comment bumps onlyREVIEWED_ACTION_PINS["github/codeql-action"]is("b96794f015dfd88f77b49b1c93e0fa7110f94c63", "v4.38.0")python3 scripts/check_workflow_policy.py .github/workflowsreportsworkflow policy checks passedpython3 -m unittest tests.repository.test_workflow_policy -v— 41 tests, OKGitHub Actions CI on this PR (CodeQL + existing required checks)
python3 -m unittest discover -s tests -p 'test_*.py'— not re-run in full; application code unchangedRelevant new tests were written FIRST and observed to fail (TDD) — N/A (pin bump only)
PUBLIC-SAFETY checklist
python3 scripts/sanitize_public.py --trackedreportedsanitization passedpython3 scripts/check_repository_metadata.py— N/A (does not touch governance/repository metadata)Additional context
v4.38.0 notes (from Dependabot #56): toolcache unused-bundle cleanup on GitHub-hosted runners, Linux Arm64 CodeQL bundle support, default bundle 2.27.0.