build(deps): Bump github/codeql-action/init from 4.37.0 to 4.37.1#189
build(deps): Bump github/codeql-action/init from 4.37.0 to 4.37.1#189dependabot[bot] wants to merge 2 commits into
Conversation
14c70eb to
beb77cd
Compare
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...7188fc3) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
beb77cd to
c9ab668
Compare
athena-omt
left a comment
There was a problem hiding this comment.
Request changes
.github/workflows/rg-security.yml updates CodeQL init to 4.37.1 (7188fc3…) but leaves analyze pinned to 4.37.0 (99df26d…). The current required CI job reusable rg-security caller smoke / rg-security fails with: Loaded a configuration file for version '4.37.1', but running version '4.37.0'.
Please update github/codeql-action/analyze to the compatible 4.37.1 pin (consistent with the workflow's CodeQL components), add contract coverage preventing mixed CodeQL action versions, then push and rerun CI. Targeted local workflow-contract tests pass (7/7), but they do not currently assert this compatibility.
Reviewed the exact head against current main; no existing review threads or prior reviews were present. Auto-merge is disabled and CI has no pending checks.
athena-omt
left a comment
There was a problem hiding this comment.
Review deferred — branch behind main
Reviewed current head d2dd0aeb2cb6f8d4357da507fa4822479c026dbc locally. It repairs the prior CodeQL-version blocker by aligning init, analyze, and upload-sarif to 7188fc363630916deb702c7fdcf4e481b751f97a, and adds a focused contract assertion. Local pnpm exec vitest run test/security-workflow.test.ts passed (3/3); all current reported checks, including the reusable rg-security smoke, are successful. No unresolved review threads were found.
GitHub currently reports mergeStateStatus: BEHIND against main (current main: dec98fc77ed2d80832e6d12a06a368449114f1a7), and auto-merge is disabled. Per review-freshness policy, do not approve this stale head. Required next owner: refresh the Dependabot branch onto current main, rerun CI, then request review of the resulting head.
Bumps github/codeql-action/init from 4.37.0 to 4.37.1.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
7188fc3Merge pull request #4020 from github/update-v4.37.1-9e7c07009c8b5f69Update changelog for v4.37.19e7c070Merge pull request #4014 from github/mbg/explicit-remote-prefix3492b7eChangeREMOTE_PATH_PREFIXtoremote=3654baaMerge remote-tracking branch 'origin/main' into mbg/explicit-remote-prefix2d682acMerge pull request #4017 from github/dependabot/github_actions/dot-github/wor...23f6a50Merge pull request #4009 from github/mbg/action-state/additions1ee3c75Merge pull request #4018 from github/dependabot/github_actions/dot-github/wor...e053684Merge pull request #4015 from github/dependabot/npm_and_yarn/npm-minor-fd2e83...6803c56Merge pull request #4019 from github/update-bundle/codeql-bundle-v2.26.1