Skip to content

build(deps): companion pin github/codeql-action v4.38.2 (PR #69) - #70

Merged
sumitake merged 1 commit into
mainfrom
cursor/companion-codeql-4.38.2-6061
Sep 28, 2026
Merged

sumitake merged 1 commit into
mainfrom
cursor/companion-codeql-4.38.2-6061

Conversation

@sumitake

@sumitake sumitake commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Companion for #69. Recreates the same CodeQL action pin bump on current main and updates the reviewed pin table so CI can go green.

Dependabot #69 only updates .github/workflows/codeql.yml (init / autobuild / analyze from b96794f… v4.38.0 to 2892aa5e… v4.38.2). CI on that branch is red because scripts/check_workflow_policy.py REVIEWED_ACTION_PINS still expects b96794f015dfd88f77b49b1c93e0fa7110f94c63 / v4.38.0 (repository-metadata SHA/comment mismatch). Dependabot cannot express that hardcoded pin-table update.

This branch is off current main (594f163). Nothing was pushed onto dependabot/**. Do not stack this on the Dependabot branch. After this lands, Ops should close #69 as superseded. Leave #69 open and red until then.

Summary

Pin github/codeql-action init/autobuild/analyze to 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 (# v4.38.2), matching Dependabot #69, and update REVIEWED_ACTION_PINS["github/codeql-action"] to the same SHA and comment. Changelog records the reviewed pin. No other workflow or action pins change. No tests/fixtures hardcoded the old SHA or v4.38.0.

Test plan

  • Diff matches build(deps): bump the actions-minor-patch group with 3 updates #69 for codeql.yml: three SHA/comment bumps only

  • REVIEWED_ACTION_PINS["github/codeql-action"] is ("2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2", "v4.38.2")

  • Peeled tag v4.38.2 is 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 (git ls-remote)

  • python3 scripts/check_workflow_policy.py .github/workflows reports workflow policy checks passed

  • python3 -m unittest tests.repository.test_workflow_policy -v — 42 tests, OK

  • python3 scripts/sanitize_public.py --tracked reports sanitization passed

  • GitHub Actions required PR checks green on tip 8f6891b (repository-metadata, container, shell, go, worker, sanitization, CodeQL, dependency-review). Non-required code-scanning AI findings failed with CAPIError: 400 The requested model is not supported — platform issue, not this pin.

  • python3 -m unittest discover -s tests -p 'test_*.py' — not re-run in full; application code unchanged

  • Relevant new tests were written FIRST and observed to fail (TDD) — N/A (pin bump only)

PUBLIC-SAFETY checklist

  • This PR contains no deployment identifiers
  • This PR contains no secrets
  • This PR contains no real logs, real configuration, or real runtime state
  • I ran python3 scripts/sanitize_public.py --tracked locally and it reported sanitization passed.
  • python3 scripts/check_repository_metadata.py — N/A (does not touch governance/repository metadata; workflow policy is covered by the checker above)

Additional context

v4.38.2 notes (from Dependabot #69): default CodeQL bundle 2.27.1. v4.38.1 (also in this range) adds experimental per-language bundle support.

Out of scope: any push onto dependabot/github_actions/actions-minor-patch-9b5af80777 or other dependabot/** refs. Do not merge or close #69 from this change.

Open in Web Open in Cursor 

Update REVIEWED_ACTION_PINS and the CodeQL workflow uses lines so
init, autobuild, and analyze match the reviewed SHA/comment for
Dependabot #69 (4.38.0 -> 4.38.2). Dependabot cannot express the
hardcoded pin-table update, so this companion lands off main
instead of dependabot/**.

Co-authored-by: John Osumi <sumitake@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: cf2df915-f71e-4984-8f14-97139b479725


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T01:27:42.190804Z 8f6891b PR opened
🔒 Security Review ✅ Completed 2026-09-28T01:29:12.918293Z 8f6891b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sumitake
sumitake merged commit dc10f9f into main Sep 28, 2026
19 of 20 checks passed
sumitake added a commit that referenced this pull request Sep 28, 2026
Bump markdownlint-cli2, prettier, typescript-eslint, and workers-types (companion to #68).

CoS AUTH + Verifier PASS at fbd939f. After #70; tip unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants