Repository navigation
chore(deps): Bump github/codeql-action/init from 4.37.3 to 4.37.6 - #309
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b0de4ebf26
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3 | ||
| uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5 |
There was a problem hiding this comment.
Keep CodeQL actions on one version
In this workflow, the init step now writes CodeQL action state as version 4.37.5, but the later Perform CodeQL analysis step still runs github/codeql-action/analyze@e4fba... # v4.37.3 on line 53. The CodeQL action persists version: getActionVersion() during init and getConfig throws when the loaded config version differs from the running action version (https://raw.githubusercontent.com/github/codeql-action/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81/src/config-utils.ts), so every push/PR/scheduled CodeQL run reaches analyze and fails instead of uploading results. Please bump the analyze action to the same 4.37.5 revision as well.
Useful? React with 👍 / 👎.
|
@dependabot rebase |
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.3 to 4.37.6. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...5595cca) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
b0de4eb to
1bd1db3
Compare
|
この更新は #317 で main に取り込まれました。init / analyze / upload-sarif は版が一致している必要があり、個別 PR では |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…ru127#306) dependabot の PR は rebase 後も validate が落ち続けていた。失敗箇所は binary/source drift gate で、Go 依存を上げると同梱バイナリがソースから byte 単位で再現できなくなるため。dependabot は go.mod / go.sum しか 更新しないので、bump 単体では構造的に通らない。 CHANGELOG に前例がある形 (「Go 側の 2 件は bump と同じ変更で 4 プラットフォームのバイナリを再生成」) に従い、bump とバイナリ再生成を 同じ変更にまとめる。 - modernc.org/sqlite 1.55.0 -> 1.56.0 (modernc.org/libc 1.74.1 -> 1.74.4、mattn/go-isatty 0.0.20 -> 0.0.24 を伴う) - github.com/santhosh-tekuri/jsonschema/v6 6.0.2 -> 6.0.3 検証: - go mod verify -> all modules verified - go test ./... 全 PASS - check-binary-source-drift.sh -> OK (4 プラットフォーム再ビルド) - validate-plugin.sh 139 合格 0 失敗 / check-consistency.sh 25/25 - VERSION / plugin.json / .github/workflows 非接触 CodeQL action の 3 件 (Chachamaru127#307 Chachamaru127#308 Chachamaru127#309) はこの PR に含めない。 .github/workflows/ は AI 編集が deny のため。3 件は同一 SHA への更新で 揃えないと "Loaded a configuration file for version X, but running version Y" で必ず壊れるため、operator が 3 件同時に merge する必要がある。 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZBxNEtYJbtHkZcsAn8nsv
…ru127#308, Chachamaru127#309) dependabot は init / analyze / upload-sarif を 3 つの別 PR に割ったが、 CodeQL はこの 3 つの版が一致している必要がある。1 つだけ merge すると 必ず壊れる: Loaded a configuration file for version '4.37.3', but running version '4.37.6' これは rebase 後の Chachamaru127#307 / Chachamaru127#309 で実際に出ていたエラーで、PR の中身では なく分割されたこと自体が原因。個別 PR は構造上 CI を通せないため、 branch protection が merge を拒否していた。--admin による強制 merge は ゲートの迂回になるので採らず、3 件を 1 ブランチに統合して CI を正当に 通す形にした。 変更は 3 行の SHA 差し替えのみ。ロジック・step 構成・権限は不変: - .github/workflows/codeql.yml: init / analyze - .github/workflows/scorecard.yml: upload-sarif - e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 (v4.37.3) -> 5595ccaf912efad79be6eef63a5619ff05969be3 (v4.37.6) .github/workflows/ は CLAUDE.md と workflow-test-wiring.md で operator 手動のみと定めている領域。今回は個別 PR が構造的に merge 不能である旨を 提示したうえで operator の明示承認を得て実施した (2026-08-14)。検査の 削除・弱体化は含まない (SHA の更新のみ)。 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZBxNEtYJbtHkZcsAn8nsv
Bumps github/codeql-action/init from 4.37.3 to 4.37.6.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
5595ccaMerge pull request #4071 from github/update-v4.37.6-6a9359a1bec9c757Add change note for PR 407045c8742Update changelog for v4.37.66a9359aMerge pull request #4070 from github/mbg/remote-address/change-file-default065cdc0ChangeDEFAULT_CONFIG_FILE_NAMEf99dd5aMerge pull request #4066 from github/dependabot/npm_and_yarn/js-yaml-5.2.21804b21Merge pull request #4068 from github/mergeback/v4.37.5-to-main-d1ba80a13020a2fRebuild93c3a5aUpdate changelog and version after v4.37.5d1ba80aMerge pull request #4067 from github/update-v4.37.5-1cd4d01d5