Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
persist-credentials: false

- name: Initialize CodeQL
uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v4.37.1
uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

refs="$(rg -o 'github/codeql-action/[^@[:space:]]+@[0-9a-f]{40}' .github/workflows/codeql.yml \
  | sed 's/.*`@//`' | sort -u)"

test "$(printf '%s\n' "$refs" | sed '/^$/d' | wc -l)" -eq 1

Repository: Xquik-dev/x-twitter-scraper-csharp

Length of output: 172


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- workflow references ---'
cat -n .github/workflows/codeql.yml | sed -n '20,42p'

printf '%s\n' '--- referenced CodeQL action pins ---'
rg -n 'github/codeql-action/[^@[:space:]]+@[0-9a-f]{40}' .github/workflows/codeql.yml

printf '%s\n' '--- pin existence and tag resolution ---'
python3 - <<'PY'
import json
import urllib.request

pins = {
    "e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81": "v4.37.3",
    "7188fc363630916deb702c7fdcf4e481b751f97a": "v4.37.1",
}
base = "https://api.github.com/repos/github/codeql-action"

def get(path):
    req = urllib.request.Request(
        base + path,
        headers={"Accept": "application/vnd.github+json", "User-Agent": "review-verifier"},
    )
    with urllib.request.urlopen(req) as response:
        return json.load(response)

for sha, tag in pins.items():
    try:
        commit = get(f"/commits/{sha}")["sha"]
        print(f"pin {sha}: commit={commit}")
    except Exception as exc:
        print(f"pin {sha}: ERROR {exc}")
    try:
        ref = get(f"/git/ref/tags/{tag}")
        obj = ref["object"]
        print(f"tag {tag}: type={obj['type']} object={obj['sha']}")
        if obj["type"] == "tag":
            tag_obj = get(f"/git/tags/{obj['sha']}")
            print(f"tag {tag}: dereferenced_commit={tag_obj['object']['sha']}")
        elif obj["type"] == "commit":
            print(f"tag {tag}: dereferenced_commit={obj['sha']}")
    except Exception as exc:
        print(f"tag {tag}: ERROR {exc}")
PY

Repository: Xquik-dev/x-twitter-scraper-csharp

Length of output: 1842


🏁 Script executed:

#!/bin/bash
set -euo pipefail

api='https://api.github.com/repos/github/codeql-action'

for path in \
  'commits/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81' \
  'commits/7188fc363630916deb702c7fdcf4e481b751f97a' \
  'git/ref/tags/v4.37.3' \
  'git/ref/tags/v4.37.1'
do
  printf '%s\n' "--- $path ---"
  curl -ksSfL \
    -H 'Accept: application/vnd.github+json' \
    -H 'User-Agent: review-verifier' \
    "$api/$path" |
    jq -c '{sha: (.sha // null), object: (.object // null), message: (.message // null)}'
done

Repository: Xquik-dev/x-twitter-scraper-csharp

Length of output: 331


🌐 Web query:

github codeql-action mixed versions init analyze unsupported workflow v4.37.3 v4.37.1

💡 Result:

Mixing different versions of the CodeQL Action within a single GitHub Actions workflow is unsupported and can cause unpredictable results [1][2][3]. GitHub has implemented validation mechanisms to address this issue: - A warning is emitted from the codeql-action/init step if the workflow detects that different versions of the CodeQL Action are being used [1][2]. - An error is thrown by subsequent CodeQL Action steps if they attempt to load a configuration file generated by a different version of the init step [1][2][3]. If you are encountering errors related to version mismatches while using v4.37.1 or v4.37.3, ensure that every reference to the CodeQL Action in your workflow file (e.g., init, analyze, upload-sarif) uses the exact same version tag or reference [4]. It is recommended to use a major version tag (e.g., v4) to ensure all steps consistently use the latest release within that major version [4]. If you must pin to a specific version, verify that all steps in the workflow file are updated to that same version [4]. These checks were introduced in earlier versions of the CodeQL Action (specifically via pull requests #3099 and #3100) to ensure consistency and prevent configuration errors [1][3]. The versions you mentioned (v4.37.1 and v4.37.3) include these validation features [5][6].

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

python3 - <<'PY'
import json
import ssl
import urllib.request

base = "https://api.github.com/repos/github/codeql-action"
pins = {
    "e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81": "v4.37.3",
    "7188fc363630916deb702c7fdcf4e481b751f97a": "v4.37.1",
}
context = ssl._create_unverified_context()

def get(path):
    request = urllib.request.Request(
        base + path,
        headers={
            "Accept": "application/vnd.github+json",
            "User-Agent": "review-verifier",
        },
    )
    with urllib.request.urlopen(request, context=context) as response:
        return json.load(response)

for pin, tag in pins.items():
    commit = get(f"/commits/{pin}")["sha"]
    ref = get(f"/git/ref/tags/{tag}")["object"]
    if ref["type"] == "tag":
        resolved = get(f"/git/tags/{ref['sha']}")["object"]["sha"]
    else:
        resolved = ref["sha"]
    print(json.dumps({
        "pin": pin,
        "pin_commit": commit,
        "tag": tag,
        "tag_object_type": ref["type"],
        "tag_resolved_commit": resolved,
        "matches": commit.lower() == resolved.lower(),
    }))
PY

Repository: Xquik-dev/x-twitter-scraper-csharp

Length of output: 1003


Use one CodeQL Action pin for all steps.

Line 36 uses v4.37.1, while Line 29 uses v4.37.3. Mixed CodeQL Action versions are unsupported and can cause configuration-loading errors. Set analyze to the same pin as init.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/codeql.yml at line 29, Update the CodeQL workflow’s
analyze step to use the same pinned CodeQL Action revision as the init step at
github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81, replacing
its older v4.37.1 pin while leaving the existing init configuration unchanged.

with:
languages: csharp
build-mode: none
Expand Down
Loading