ci: bump github/codeql-action/init from 4.37.3 to 4.37.6 - #604
ci: bump github/codeql-action/init from 4.37.3 to 4.37.6#604dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.3 to 4.37.6. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...5595cca) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
wbreza
left a comment
There was a problem hiding this comment.
Bump is correctly pinned, but merging it alone red-fails the CodeQL workflow.
What stood out
- Pin is authentic — the new SHA dereferences exactly to the
v4.37.6annotated tag, and the previous SHA tov4.37.3, so the version claim in the title is accurate. - Sibling steps left behind —
autobuildandanalyzein this same workflow still point at the v4.37.3 SHA, and CodeQL enforces strict version equality between them. - Already reproduced on this branch — the
Analyzecheck on this head SHA completed withconclusion: failure.
Top issues
- [F-001] CodeQL sub-actions left at mismatched versions, taking the scan down —
.github/workflows/codeql.yml:40
Improvement opportunities
- [O-001] Group CodeQL action updates so sibling sub-actions bump together (Recommended) —
.github/workflows/codeql.yml:40
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4 | ||
| uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 |
There was a problem hiding this comment.
[F-001] This bump moves init to v4.37.6, but autobuild (line 45) and analyze (line 48) in this same workflow still point at e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 (v4.37.3).
init stamps its own version into the config it writes to RUNNER_TEMP, and the sibling steps enforce strict equality on that value — any difference, including a same-major patch delta, hard-errors rather than warning.
The Analyze check on this head SHA (90053ea) already completed with conclusion: failure:
##[error]We were unable to automatically build your code. Please replace the call to the autobuild action with your custom build steps. Loaded a configuration file for version '4.37.6', but running version '4.37.3'
Merging this PR on its own takes the CodeQL security scan down on main. Land it together with #605 (analyze) and #607 (autobuild) so all three sub-actions reach 5595ccaf912efad79be6eef63a5619ff05969be3 at once.
The pin itself is correct — 5595ccaf912efad79be6eef63a5619ff05969be3 dereferences exactly to the v4.37.6 annotated tag. The only defect is the co-merge requirement.
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4 | ||
| uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 |
There was a problem hiding this comment.
[O-001] (Recommended — optional, not required to merge)
Dependabot tracks each uses: path as a separate dependency, so init, autobuild, and analyze arrive as three independent PRs (#604, #607, #605). Whichever lands first leaves the workflow in a mismatched, failing state — which is what happened here.
A group rule in .github/dependabot.yml makes all three arrive in a single PR and prevents the split from recurring:
groups:
codeql-action:
patterns:
- "github/codeql-action*"While editing those lines, the three CodeQL pins carry major-only # v4 comments, whereas 82 of the 86 action pins elsewhere in this repo record the precise version (for example # v7.0.1 in ci.yml). Tightening them to # v4.37.6 would match the dominant convention.
|
Superseded by #617. |
Bumps github/codeql-action/init from 4.37.3 to 4.37.6.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
5595ccaMerge pull request #4071 from github/update-v4.37.6-6a9359a1bec9c757Add change note for PR 407045c8742Update changelog for v4.37.66a9359aMerge pull request #4070 from github/mbg/remote-address/change-file-default065cdc0ChangeDEFAULT_CONFIG_FILE_NAMEf99dd5aMerge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.21804b21Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a13020a2fRebuild93c3a5aUpdate changelog and version after v4.37.5d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)