Skip to content

chore(deps): update grouped codeql actions to v4.38.0 - #4268

Open
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-codeql-action-update
Open

Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-codeql-action-update

Conversation

@Ricky-G

@Ricky-G Ricky Gummadi (Ricky-G) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Related Issue

Replacement for #4084. Credit to Dependabot for the original grouped update, observed at head 3bf065b4e44c1f34ed460b2d57684df706d83b43. The original PR remains open pending coordinator authorization; this PR does not close it or enable merging. Maintainer review is required before merge.

If no related issue is linked above, you must complete "Problem & Solution", "Impact on Your Work", and "Alternatives Considered" below.

Summary

Update all ten CodeQL action references from v4.37.9 to v4.38.0 across the same six surfaces as Dependabot's proposal, including emitted workflow YAML and copy-paste tutorials. Preserve full SHA pinning and existing events, permissions, inputs, conditions, runner selections, and shell commands.

Release and provenance verification:

  • Upstream release: published 2026-09-09T14:04:03Z, over 29 days old at verification and compliant with the seven-day stability rule.
  • Annotated tag v4.38.0 has object 4bd7200e1f146b1c937cae12d258b50f41a53cf8, which resolves to full commit b96794f015dfd88f77b49b1c93e0fa7110f94c63. Every reference uses that commit and the matching # v4.38.0 annotation.
  • GitHub's commit API reports the target commit signature as verified (reason: valid). The annotated tag itself is unsigned; these are separate provenance facts.
  • Release notes describe hosted-runner toolcache cleanup, Linux Arm64 bundle support, and the default CodeQL bundle update to 2.27.0. All four action manifests use runs.using: node24, unchanged by this upgrade. The existing ubuntu-latest runners are compatible; no runtime opt-out, privilege expansion, or workflow redesign is introduced.
  • Original issue comments, reviews, inline comments, complete paginated timeline, and resolved/open review threads were read: three issue comments, no submitted reviews, no inline comments, and no review threads. No duplicate replacement was found.

Problem & Solution

The grouped Dependabot update needs a human-owned replacement for tracking and maintainer review. Updating only workflow files would leave generated CI configuration and tutorial examples stale and fail the existing synchronized-pinning regression test. This applies the same ten-reference upgrade on an independent branch based on current main; the only additional edits are required documentation review metadata.

Impact on Your Work

Keep the repository's CodeQL analysis, third-party SARIF uploads, and user-facing examples on one verified release without changing their security behavior. No public API, dependency manifest, package layout, or CI architecture changes.

Timeline

None. Maintainer approval and hosted CI verification take precedence over merging speed.

Alternatives Considered

Retaining the bot-owned PR would not provide the requested independent replacement. Updating only workflow YAML would violate the existing synchronization guard. Moving to a newer release, changing permissions, fixing unrelated baseline defects, or editing pr-size.yml would exceed this scope.

Changes

File Change
.github/workflows/ci.yml Update the BinSkim SARIF upload pin; preserve conditions, inputs, and permissions.
.github/workflows/codeql.yml Update init, autobuild, and analyze to the same verified SHA.
.github/workflows/scorecard.yml Update SARIF upload without changing Scorecard's read-only workflow permissions or job-scoped writes.
agent-governance-python/agent-os/docs/tutorials/vscode-extension.md Update the example upload pin and add required title/review-date/owner frontmatter. Leave the pre-existing TOC defect unchanged.
agent-governance-typescript/agent-os-vscode/src/enterprise/integration/cicdIntegration.ts Update the emitted GitHub Actions upload pin; all other provider templates remain identical.
docs/tutorials/25-security-hardening.md Update three CodeQL references and the documentation review date.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

Core & runtime:

  • agent-governance-toolkit-core
  • agent-primitives
  • agent-os
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-compliance

Governance & security:

  • agent-mcp-governance
  • agent-rag-governance
  • agent-sandbox
  • agent-discovery
  • agt-policies
  • policy-engine

Platform & tooling:

  • agent-hypervisor
  • agent-lightning
  • agent-marketplace
  • agent-governance-toolkit-cli
  • agent-governance-toolkit-integrations
  • agent-governance-toolkit-protocols
  • agentmesh-integrations (framework integrations)

CLI plugins:

  • agent-governance CLI plugins (copilot-cli / claude-code / opencode / antigravity-cli)

Shared / other:

  • schemas
  • action (GitHub Action)
  • examples
  • docs / root

Testing

Hosted CI is pending at PR creation, not claimed passing. Local validation used Windows, Python 3.14, Node v26.7.0, and checksum-verified actionlint 1.7.12. Its Windows archive SHA-256 matched the upstream release digest 6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9. Optional external shellcheck/pyflakes integrations were disabled; workflow shell content is unchanged.

Unit Testing

No new repository test files were necessary: the existing pinning regression scans every tracked CodeQL reference, including generated-source templates and tutorials. Focused workflow/documentation regression tests cover the touched surfaces.

Exact command Result
python -m pytest tests\ci\test_codeql_action_pinning.py tests\ci\test_extract_workflow_shell.py tests\ci\test_generate_workflows.py scripts\tests\test_docs_check_links.py scripts\tests\test_docs_check_frontmatter.py -q PASS: 71 tests.
python -m pytest tests\ci\ -q 99 passed, 6 skipped, 4 failed due to existing Windows limitations: three tests invoke unavailable WSL /bin/bash; one asserts POSIX path separators. Retrying with Git Bash directories prepended to PATH produced the same result. These test/source files are unchanged.

Manual Testing

Session-artifact commands below use A = C:\Users\rickygummadi\.copilot\session-state\42a13328-284c-4167-935f-7c4caac58c53\files; these focused verification harnesses are retained in the session, not added to the repository.

Command Result
python scripts\docs\check_links.py PASS: 307 files, 2,852 links, zero new broken links.
python scripts\docs\check_frontmatter.py --strict PASS: 294 files, zero findings.
python scripts\docs\check_frontmatter.py --strict agent-governance-python\agent-os\docs\tutorials\vscode-extension.md docs\tutorials\25-security-hardening.md PASS: both edited pages.
python scripts\docs\check_links.py agent-governance-python\agent-os\docs\tutorials\vscode-extension.md docs\tutorials\25-security-hardening.md FAIL, baseline: one existing #intellisense--snippets TOC anchor in the legacy tutorial, independently confirmed present on unchanged origin/main; deliberately not repaired in this action bump.
actionlint.exe -shellcheck= -pyflakes= -ignore 'unknown permission scope "models"' -ignore 'undefined variable "pattern"' -ignore 'SC2016' -ignore 'SC2001' -ignore 'SC2129' -ignore 'SC2193' .github\workflows\ci.yml .github\workflows\codeql.yml .github\workflows\scorecard.yml PASS: all three modified workflows, using the executable under A\actionlint-1.7.12.
C:\Program Files\Git\bin\bash.exe A\workflow-security-audit.sh PASS: unmodified workflow-security CI job's pull_request_target audit, extracted from ci.yml.
node A\verify-codeql-generator.mjs PASS: native TypeScript syntax stripping and execution of the actual CICDIntegration.generateConfig with a filesystem-backed test host; emitted workflow matches the updated template; baseline comparison confirms only SHA/version changed and the four other provider templates are identical. Not a TypeScript type-check or full extension build.
actionlint.exe -shellcheck= -pyflakes= A\generator-workspace\.github\workflows\agent-os.yml PASS: actual generated workflow. The three CodeQL-bearing tutorial YAML examples also pass the same lint invocation.
python A\verify-codeql-surfaces.py PASS: exact six-file scope, ten synchronized full-SHA references, and unchanged workflow semantics; only additional edits are documentation metadata.
git diff --check PASS.
npm --prefix agent-governance-typescript\agent-os-vscode run compile BLOCKED: no installed tsc.
npm --prefix agent-governance-typescript\agent-os-vscode install --ignore-scripts --no-package-lock --legacy-peer-deps --no-audit --no-fund BLOCKED: ETARGET, existing unpublished typescript@5.3.0. git show origin/main:agent-governance-typescript/agent-os-vscode/package.json confirms the same pin on unchanged main; npm view typescript@5.3.0 version returns E404. No manifest or lockfile was changed.
npm install --prefix A\validation-tools --ignore-scripts --no-audit --no-fund --save-exact typescript@5.3.3 @types/node@20.0.0 @types/vscode@1.85.0 cspell@8.17.3 BLOCKED: corporate feed EALLOWREMOTE. A separate compiler-only restore was also blocked. No feed/TLS/security-policy bypass attempted.
cspell --version UNAVAILABLE: tool missing; changed-line spelling gate could not run because the permitted restore was blocked. Changed lines were extracted with python scripts\ci\changed_lines.py --base origin/main --extensions '.md,.txt,.rst,.py,.ts,.js,.go,.rs,.cs,.yml,.yaml' --mode added-lines --output A\spell-check-added-lines.txt.

Full extension compilation, type-checking, Electron-hosted tests, and cspell are not claimed passing. The affected source has only a verified template literal substitution. Baseline defects and unavailable tooling are disclosed rather than addressed with unrelated dependency or documentation edits.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):

Dependabot's grouped proposal in #4084 supplies the intended upgrade. Upstream project: github/codeql-action, with release/provenance evidence above. This adds no copied implementation or new architectural pattern.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:

Authorized GitHub Copilot assistance performed upstream/discussion review, the six-file action bump, focused verification, and PR preparation. Human review and CLA status are not attested here; those checkboxes remain unchecked for the maintainer/author to verify.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/github/codeql-action/upload-sarif b96794f015dfd88f77b49b1c93e0fa7110f94c63 UnknownUnknown

Scanned Files

  • .github/workflows/scorecard.yml

@github-actions github-actions Bot added the size/S Small PR (< 50 lines) label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Verified at a9c2013: all ten github/codeql-action references move from the v4.37.9 SHA to b96794f0, which is the peeled v4.38.0 tag (signed commit, published 2026-09-09), nothing is left on the old SHA anywhere in the tree, the pin registry is untouched because generated workflows do not carry it, the generator check and the 17 pinning tests pass, and CI is green. Two things before I approve. The commit is authored and signed off as Microsoft Corporation agentgovtoolkit@microsoft.com rather than a named person, so the DCO sign-off does not identify who attests; and the description says Copilot produced and submitted the change under authorization while the AI Assistance boxes (can explain every change, no autonomous submission without review, no AI review comments) and the CLA box are unticked. CONTRIBUTING.md:231-234 treats autonomous submissions as needing a named responsible human. Please tick the attestations under your own name and, if you can, re-sign the commit as yourself; then this is a straight approve. Minor: v4.38.2 and v4.38.3 exist if you want the latest line, but 4.38.0 is a fine stable pick.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation scripts/ci/cd size/S Small PR (< 50 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants