Skip to content

Check collaborator permissions for workflow_run events - #1590

Merged
ashwin-ant merged 1 commit into
mainfrom
fix/workflow-run-permission-gate
Aug 4, 2026
Merged

Check collaborator permissions for workflow_run events#1590
ashwin-ant merged 1 commit into
mainfrom
fix/workflow-run-permission-gate

Conversation

@ashwin-ant

Copy link
Copy Markdown
Collaborator

Summary

  • The write-permission check in run.ts only ran for entity events (issues, PRs, comments, reviews), so workflow_run-triggered runs skipped it entirely and went straight into agent mode. This applies the same collaborator permission check to workflow_run events, so behavior matches what docs/security.md describes.
  • For workflow_run, both the workflow actor and the actor that started the upstream run (payload.workflow_run.actor.login) are checked when they differ. allowed_non_write_users, github_token, and [bot] actors behave exactly as they do for entity events.
  • workflow_dispatch, repository_dispatch, and schedule are unchanged — GitHub already requires write access to dispatch, and schedules have no external actor.
  • checkWritePermissions now accepts any GitHubContext; entity-context behavior is unchanged (single actor).
  • Docs updated to describe the workflow_run check and the allowed_non_write_users opt-in.

Behavior change to be aware of

Workflows that run this action on workflow_run where the upstream run was started by someone without write access (e.g. CI on a pull request from an outside contributor's fork — see examples/ci-failure-auto-fix.yml / examples/test-failure-analysis.yml) will now stop with "Actor does not have write permissions to the repository" instead of proceeding. Repos that want the previous behavior for those contributors can add them via allowed_non_write_users (with github_token: ${{ secrets.GITHUB_TOKEN }}).

Test plan

  • bun test (814 pass) — new cases for read-only run actor rejected, write/admin allowed, differing workflow vs run actor both checked, allowed_non_write_users with/without github_token, [bot] run actor
  • bun run typecheck
  • bun run format:check

The write-permission gate previously only ran for issue/PR entity
events. Apply it to workflow_run events as well, checking both the
workflow actor and the actor recorded on the upstream run when they
differ. allowed_non_write_users and the github_token override behave
the same as for entity events. Document the behavior for workflow_run
pipelines.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

This review may be incomplete: some analysis steps could not run due to a temporary API capacity limit.

@ashwin-ant
ashwin-ant merged commit acb0385 into main Aug 4, 2026
39 checks passed
@ashwin-ant
ashwin-ant deleted the fix/workflow-run-permission-gate branch August 4, 2026 17:05
TonyRL added a commit to DIYgod/RSSHub that referenced this pull request Aug 5, 2026
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Aug 10, 2026
Bumps the github-actions group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.183` | `1.0.187` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.4` | `4.37.6` |
| [graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm) | `1.6.3` | `1.6.4` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.4` | `4.37.6` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.4` | `4.37.6` |
Updates `anthropics/claude-code-action` from 1.0.183 to 1.0.187
Release notes

*Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).*

> v1.0.187
> --------
>
> What's Changed
> --------------
>
> * Redact common credential patterns from published run output by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1595](https://redirect.github.com/anthropics/claude-code-action/pull/1595)
> * Scope the config snapshot to files inside the working tree by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1596](https://redirect.github.com/anthropics/claude-code-action/pull/1596)
> * Run checkout auth cleanup when API commit signing is enabled by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1597](https://redirect.github.com/anthropics/claude-code-action/pull/1597)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.187>
>
> v1.0.186
> --------
>
> What's Changed
> --------------
>
> * Invoke the formatter directly from the format hook by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1594](https://redirect.github.com/anthropics/claude-code-action/pull/1594)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.186>
>
> v1.0.185
> --------
>
> What's Changed
> --------------
>
> * Derive trigger timestamps for issues and pull\_request events by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1592](https://redirect.github.com/anthropics/claude-code-action/pull/1592)
> * Pin bun config for MCP server processes by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1589](https://redirect.github.com/anthropics/claude-code-action/pull/1589)
> * Match downloaded images to their source URLs by asset identifier by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1588](https://redirect.github.com/anthropics/claude-code-action/pull/1588)
> * Check collaborator permissions for workflow\_run events by [`@​ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1590](https://redirect.github.com/anthropics/claude-code-action/pull/1590)
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.185>
>
> v1.0.184
> --------
>
> **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.184>


Commits

* [`1623c36`](anthropics/claude-code-action@1623c36) chore: bump Claude Code to 2.1.224 and Agent SDK to 0.3.224
* [`96e281f`](anthropics/claude-code-action@96e281f) Run checkout auth cleanup when API commit signing is enabled ([#1597](https://redirect.github.com/anthropics/claude-code-action/issues/1597))
* [`e1fc925`](anthropics/claude-code-action@e1fc925) Scope the config snapshot to files inside the working tree ([#1596](https://redirect.github.com/anthropics/claude-code-action/issues/1596))
* [`0aee57a`](anthropics/claude-code-action@0aee57a) Redact common credential patterns from published run output ([#1595](https://redirect.github.com/anthropics/claude-code-action/issues/1595))
* [`c038e4d`](anthropics/claude-code-action@c038e4d) chore: bump Claude Code to 2.1.223 and Agent SDK to 0.3.223
* [`4c04887`](anthropics/claude-code-action@4c04887) Invoke the formatter directly from the format hook ([#1594](https://redirect.github.com/anthropics/claude-code-action/issues/1594))
* [`9db594c`](anthropics/claude-code-action@9db594c) chore: bump Claude Code to 2.1.222 and Agent SDK to 0.3.222
* [`acb0385`](anthropics/claude-code-action@acb0385) Check collaborator permissions for workflow\_run events ([#1590](https://redirect.github.com/anthropics/claude-code-action/issues/1590))
* [`b80a0f0`](anthropics/claude-code-action@b80a0f0) Match downloaded images to their source URLs by asset identifier ([#1588](https://redirect.github.com/anthropics/claude-code-action/issues/1588))
* [`6fb6bb6`](anthropics/claude-code-action@6fb6bb6) Pin bun config for MCP server processes ([#1589](https://redirect.github.com/anthropics/claude-code-action/issues/1589))
* Additional commits viewable in [compare view](anthropics/claude-code-action@be7b93b...1623c36)
  
Updates `github/codeql-action/upload-sarif` from 4.37.4 to 4.37.6
Release notes

*Sourced from [github/codeql-action/upload-sarif's releases](https://github.com/github/codeql-action/releases).*

> v4.37.6
> -------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> v4.37.5
> -------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)


Changelog

*Sourced from [github/codeql-action/upload-sarif's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.37.6 - 04 Aug 2026
> --------------------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> 4.37.5 - 03 Aug 2026
> --------------------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)
>
> 4.37.4 - 29 Jul 2026
> --------------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
> * Update default CodeQL bundle version to [2.26.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2). [#4051](https://redirect.github.com/github/codeql-action/pull/4051)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)

... (truncated)


Commits

* [`5595cca`](github/codeql-action@5595cca) Merge pull request [#4071](https://redirect.github.com/github/codeql-action/issues/4071) from github/update-v4.37.6-6a9359a1b
* [`ec9c757`](github/codeql-action@ec9c757) Add change note for PR 4070
* [`45c8742`](github/codeql-action@45c8742) Update changelog for v4.37.6
* [`6a9359a`](github/codeql-action@6a9359a) Merge pull request [#4070](https://redirect.github.com/github/codeql-action/issues/4070) from github/mbg/remote-address/change-file-default
* [`065cdc0`](github/codeql-action@065cdc0) Change `DEFAULT_CONFIG_FILE_NAME`
* [`f99dd5a`](github/codeql-action@f99dd5a) Merge pull request [#4066](https://redirect.github.com/github/codeql-action/issues/4066) from github/dependabot/npm\_and\_yarn/js-yaml-5.2.2
* [`1804b21`](github/codeql-action@1804b21) Merge pull request [#4068](https://redirect.github.com/github/codeql-action/issues/4068) from github/mergeback/v4.37.5-to-main-d1ba80a1
* [`3020a2f`](github/codeql-action@3020a2f) Rebuild
* [`93c3a5a`](github/codeql-action@93c3a5a) Update changelog and version after v4.37.5
* [`d1ba80a`](github/codeql-action@d1ba80a) Merge pull request [#4067](https://redirect.github.com/github/codeql-action/issues/4067) from github/update-v4.37.5-1cd4d01d5
* Additional commits viewable in [compare view](github/codeql-action@f205ea1...5595cca)
  
Updates `graalvm/setup-graalvm` from 1.6.3 to 1.6.4
Release notes

*Sourced from [graalvm/setup-graalvm's releases](https://github.com/graalvm/setup-graalvm/releases).*

> v1.6.4
> ------
>
> What's Changed
> --------------
>
> * Bump js-yaml from 5.2.0 to 5.2.2 by [`@​dependabot`](https://github.com/dependabot)[bot] in [graalvm/setup-graalvm#230](https://redirect.github.com/graalvm/setup-graalvm/pull/230)
> * Bump the "all" group with 2 updates across multiple ecosystems by [`@​dependabot`](https://github.com/dependabot)[bot] in [graalvm/setup-graalvm#232](https://redirect.github.com/graalvm/setup-graalvm/pull/232)
>
> **Full Changelog**: <graalvm/setup-graalvm@v1.6.3...v1.6.4>


Commits

* [`5298d94`](graalvm/setup-graalvm@5298d94) Bump version to `1.6.4`.
* [`fdb7cac`](graalvm/setup-graalvm@fdb7cac) Stay on typescript `6.0.3`.
* [`ecfa7c7`](graalvm/setup-graalvm@ecfa7c7) Bump the all group with 3 updates
* [`4b14c74`](graalvm/setup-graalvm@4b14c74) Drop build jobs of outdated `22.3.3`.
* [`1f08baa`](graalvm/setup-graalvm@1f08baa) Drop `native-image` gu component.
* [`fe57852`](graalvm/setup-graalvm@fe57852) Update dependencies.
* [`785f14e`](graalvm/setup-graalvm@785f14e) Use `17.0.20` instead of `17.0.8`.
* [`33fc590`](graalvm/setup-graalvm@33fc590) Bump js-yaml from 5.2.0 to 5.2.2
* See full diff in [compare view](graalvm/setup-graalvm@0def53c...5298d94)
  
Updates `github/codeql-action/init` from 4.37.4 to 4.37.6
Release notes

*Sourced from [github/codeql-action/init's releases](https://github.com/github/codeql-action/releases).*

> v4.37.6
> -------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> v4.37.5
> -------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)


Changelog

*Sourced from [github/codeql-action/init's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.37.6 - 04 Aug 2026
> --------------------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> 4.37.5 - 03 Aug 2026
> --------------------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)
>
> 4.37.4 - 29 Jul 2026
> --------------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
> * Update default CodeQL bundle version to [2.26.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2). [#4051](https://redirect.github.com/github/codeql-action/pull/4051)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)

... (truncated)


Commits

* [`5595cca`](github/codeql-action@5595cca) Merge pull request [#4071](https://redirect.github.com/github/codeql-action/issues/4071) from github/update-v4.37.6-6a9359a1b
* [`ec9c757`](github/codeql-action@ec9c757) Add change note for PR 4070
* [`45c8742`](github/codeql-action@45c8742) Update changelog for v4.37.6
* [`6a9359a`](github/codeql-action@6a9359a) Merge pull request [#4070](https://redirect.github.com/github/codeql-action/issues/4070) from github/mbg/remote-address/change-file-default
* [`065cdc0`](github/codeql-action@065cdc0) Change `DEFAULT_CONFIG_FILE_NAME`
* [`f99dd5a`](github/codeql-action@f99dd5a) Merge pull request [#4066](https://redirect.github.com/github/codeql-action/issues/4066) from github/dependabot/npm\_and\_yarn/js-yaml-5.2.2
* [`1804b21`](github/codeql-action@1804b21) Merge pull request [#4068](https://redirect.github.com/github/codeql-action/issues/4068) from github/mergeback/v4.37.5-to-main-d1ba80a1
* [`3020a2f`](github/codeql-action@3020a2f) Rebuild
* [`93c3a5a`](github/codeql-action@93c3a5a) Update changelog and version after v4.37.5
* [`d1ba80a`](github/codeql-action@d1ba80a) Merge pull request [#4067](https://redirect.github.com/github/codeql-action/issues/4067) from github/update-v4.37.5-1cd4d01d5
* Additional commits viewable in [compare view](github/codeql-action@f205ea1...5595cca)
  
Updates `github/codeql-action/analyze` from 4.37.4 to 4.37.6
Release notes

*Sourced from [github/codeql-action/analyze's releases](https://github.com/github/codeql-action/releases).*

> v4.37.6
> -------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> v4.37.5
> -------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)


Changelog

*Sourced from [github/codeql-action/analyze's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*

> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> No user facing changes.
>
> 4.37.6 - 04 Aug 2026
> --------------------
>
> * Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://redirect.github.com/github/codeql-action/pull/4070)
>
> 4.37.5 - 03 Aug 2026
> --------------------
>
> * Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://redirect.github.com/github/codeql-action/pull/4061)
>
> 4.37.4 - 29 Jul 2026
> --------------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
> * Update default CodeQL bundle version to [2.26.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2). [#4051](https://redirect.github.com/github/codeql-action/pull/4051)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)

... (truncated)


Commits

* [`5595cca`](github/codeql-action@5595cca) Merge pull request [#4071](https://redirect.github.com/github/codeql-action/issues/4071) from github/update-v4.37.6-6a9359a1b
* [`ec9c757`](github/codeql-action@ec9c757) Add change note for PR 4070
* [`45c8742`](github/codeql-action@45c8742) Update changelog for v4.37.6
* [`6a9359a`](github/codeql-action@6a9359a) Merge pull request [#4070](https://redirect.github.com/github/codeql-action/issues/4070) from github/mbg/remote-address/change-file-default
* [`065cdc0`](github/codeql-action@065cdc0) Change `DEFAULT_CONFIG_FILE_NAME`
* [`f99dd5a`](github/codeql-action@f99dd5a) Merge pull request [#4066](https://redirect.github.com/github/codeql-action/issues/4066) from github/dependabot/npm\_and\_yarn/js-yaml-5.2.2
* [`1804b21`](github/codeql-action@1804b21) Merge pull request [#4068](https://redirect.github.com/github/codeql-action/issues/4068) from github/mergeback/v4.37.5-to-main-d1ba80a1
* [`3020a2f`](github/codeql-action@3020a2f) Rebuild
* [`93c3a5a`](github/codeql-action@93c3a5a) Update changelog and version after v4.37.5
* [`d1ba80a`](github/codeql-action@d1ba80a) Merge pull request [#4067](https://redirect.github.com/github/codeql-action/issues/4067) from github/update-v4.37.5-1cd4d01d5
* Additional commits viewable in [compare view](github/codeql-action@f205ea1...5595cca)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore  major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore  minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore  ` will remove the ignore condition of the specified dependency and ignore conditions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants