Skip to content

ci: bump remaining GitHub Action pins from Dependabot - #20

Merged
sumitake merged 1 commit into
mainfrom
dev/grok/dependabot-actions-batch
Aug 28, 2026
Merged

ci: bump remaining GitHub Action pins from Dependabot#20
sumitake merged 1 commit into
mainfrom
dev/grok/dependabot-actions-batch

Conversation

@sumitake

Copy link
Copy Markdown
Owner

Supersedes open Dependabot PRs:

#2 could not merge on its own: Dependabot updated only init, leaving analyze on v3 (Loaded a configuration file for version '4.x', but running version '3.x').

Each SHA was verified against the corresponding upstream tag object.

Supersedes Dependabot PRs #7, #6, #5, #3, and #2.

CodeQL init and analyze are pinned together to v4.37.8. Dependabot
only bumped init, which fails with a version mismatch at analyze time.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: bfb8adde-cc3b-4ec6-8578-b3e3540ebd0b


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant