Repository navigation
chore(deps): update grouped codeql actions to v4.38.0 - #4268
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
Conversation
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
|
Verified at a9c2013: all ten github/codeql-action references move from the v4.37.9 SHA to b96794f0, which is the peeled v4.38.0 tag (signed commit, published 2026-09-09), nothing is left on the old SHA anywhere in the tree, the pin registry is untouched because generated workflows do not carry it, the generator check and the 17 pinning tests pass, and CI is green. Two things before I approve. The commit is authored and signed off as Microsoft Corporation agentgovtoolkit@microsoft.com rather than a named person, so the DCO sign-off does not identify who attests; and the description says Copilot produced and submitted the change under authorization while the AI Assistance boxes (can explain every change, no autonomous submission without review, no AI review comments) and the CLA box are unticked. CONTRIBUTING.md:231-234 treats autonomous submissions as needing a named responsible human. Please tick the attestations under your own name and, if you can, re-sign the commit as yourself; then this is a straight approve. Minor: v4.38.2 and v4.38.3 exist if you want the latest line, but 4.38.0 is a fine stable pick. |
Related Issue
Replacement for #4084. Credit to Dependabot for the original grouped update, observed at head
3bf065b4e44c1f34ed460b2d57684df706d83b43. The original PR remains open pending coordinator authorization; this PR does not close it or enable merging. Maintainer review is required before merge.Summary
Update all ten CodeQL action references from
v4.37.9tov4.38.0across the same six surfaces as Dependabot's proposal, including emitted workflow YAML and copy-paste tutorials. Preserve full SHA pinning and existing events, permissions, inputs, conditions, runner selections, and shell commands.Release and provenance verification:
2026-09-09T14:04:03Z, over 29 days old at verification and compliant with the seven-day stability rule.v4.38.0has object4bd7200e1f146b1c937cae12d258b50f41a53cf8, which resolves to full commitb96794f015dfd88f77b49b1c93e0fa7110f94c63. Every reference uses that commit and the matching# v4.38.0annotation.reason: valid). The annotated tag itself is unsigned; these are separate provenance facts.2.27.0. All four action manifests useruns.using: node24, unchanged by this upgrade. The existingubuntu-latestrunners are compatible; no runtime opt-out, privilege expansion, or workflow redesign is introduced.Problem & Solution
The grouped Dependabot update needs a human-owned replacement for tracking and maintainer review. Updating only workflow files would leave generated CI configuration and tutorial examples stale and fail the existing synchronized-pinning regression test. This applies the same ten-reference upgrade on an independent branch based on current
main; the only additional edits are required documentation review metadata.Impact on Your Work
Keep the repository's CodeQL analysis, third-party SARIF uploads, and user-facing examples on one verified release without changing their security behavior. No public API, dependency manifest, package layout, or CI architecture changes.
Timeline
None. Maintainer approval and hosted CI verification take precedence over merging speed.
Alternatives Considered
Retaining the bot-owned PR would not provide the requested independent replacement. Updating only workflow YAML would violate the existing synchronization guard. Moving to a newer release, changing permissions, fixing unrelated baseline defects, or editing
pr-size.ymlwould exceed this scope.Changes
.github/workflows/ci.yml.github/workflows/codeql.ymlinit,autobuild, andanalyzeto the same verified SHA..github/workflows/scorecard.ymlagent-governance-python/agent-os/docs/tutorials/vscode-extension.mdagent-governance-typescript/agent-os-vscode/src/enterprise/integration/cicdIntegration.tsdocs/tutorials/25-security-hardening.mdType of Change
Package(s) Affected
Core & runtime:
Governance & security:
Platform & tooling:
CLI plugins:
Shared / other:
Testing
Hosted CI is pending at PR creation, not claimed passing. Local validation used Windows, Python 3.14, Node
v26.7.0, and checksum-verified actionlint1.7.12. Its Windows archive SHA-256 matched the upstream release digest6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9. Optional external shellcheck/pyflakes integrations were disabled; workflow shell content is unchanged.Unit Testing
No new repository test files were necessary: the existing pinning regression scans every tracked CodeQL reference, including generated-source templates and tutorials. Focused workflow/documentation regression tests cover the touched surfaces.
python -m pytest tests\ci\test_codeql_action_pinning.py tests\ci\test_extract_workflow_shell.py tests\ci\test_generate_workflows.py scripts\tests\test_docs_check_links.py scripts\tests\test_docs_check_frontmatter.py -qpython -m pytest tests\ci\ -q/bin/bash; one asserts POSIX path separators. Retrying with Git Bash directories prepended to PATH produced the same result. These test/source files are unchanged.Manual Testing
Session-artifact commands below use
A = C:\Users\rickygummadi\.copilot\session-state\42a13328-284c-4167-935f-7c4caac58c53\files; these focused verification harnesses are retained in the session, not added to the repository.python scripts\docs\check_links.pypython scripts\docs\check_frontmatter.py --strictpython scripts\docs\check_frontmatter.py --strict agent-governance-python\agent-os\docs\tutorials\vscode-extension.md docs\tutorials\25-security-hardening.mdpython scripts\docs\check_links.py agent-governance-python\agent-os\docs\tutorials\vscode-extension.md docs\tutorials\25-security-hardening.md#intellisense--snippetsTOC anchor in the legacy tutorial, independently confirmed present on unchangedorigin/main; deliberately not repaired in this action bump.actionlint.exe -shellcheck= -pyflakes= -ignore 'unknown permission scope "models"' -ignore 'undefined variable "pattern"' -ignore 'SC2016' -ignore 'SC2001' -ignore 'SC2129' -ignore 'SC2193' .github\workflows\ci.yml .github\workflows\codeql.yml .github\workflows\scorecard.ymlA\actionlint-1.7.12.C:\Program Files\Git\bin\bash.exe A\workflow-security-audit.shworkflow-securityCI job'spull_request_targetaudit, extracted fromci.yml.node A\verify-codeql-generator.mjsCICDIntegration.generateConfigwith a filesystem-backed test host; emitted workflow matches the updated template; baseline comparison confirms only SHA/version changed and the four other provider templates are identical. Not a TypeScript type-check or full extension build.actionlint.exe -shellcheck= -pyflakes= A\generator-workspace\.github\workflows\agent-os.ymlpython A\verify-codeql-surfaces.pygit diff --checknpm --prefix agent-governance-typescript\agent-os-vscode run compiletsc.npm --prefix agent-governance-typescript\agent-os-vscode install --ignore-scripts --no-package-lock --legacy-peer-deps --no-audit --no-fundETARGET, existing unpublishedtypescript@5.3.0.git show origin/main:agent-governance-typescript/agent-os-vscode/package.jsonconfirms the same pin on unchanged main;npm view typescript@5.3.0 versionreturnsE404. No manifest or lockfile was changed.npm install --prefix A\validation-tools --ignore-scripts --no-audit --no-fund --save-exact typescript@5.3.3 @types/node@20.0.0 @types/vscode@1.85.0 cspell@8.17.3EALLOWREMOTE. A separate compiler-only restore was also blocked. No feed/TLS/security-policy bypass attempted.cspell --versionpython scripts\ci\changed_lines.py --base origin/main --extensions '.md,.txt,.rst,.py,.ts,.js,.go,.rs,.cs,.yml,.yaml' --mode added-lines --output A\spell-check-added-lines.txt.Full extension compilation, type-checking, Electron-hosted tests, and cspell are not claimed passing. The affected source has only a verified template literal substitution. Baseline defects and unavailable tooling are disclosed rather than addressed with unrelated dependency or documentation edits.
Checklist
Attribution & Prior Art
Prior art / related projects (if any):
Dependabot's grouped proposal in #4084 supplies the intended upgrade. Upstream project: github/codeql-action, with release/provenance evidence above. This adds no copied implementation or new architectural pattern.
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
Authorized GitHub Copilot assistance performed upstream/discussion review, the six-file action bump, focused verification, and PR preparation. Human review and CLA status are not attested here; those checkboxes remain unchecked for the maintainer/author to verify.
IP, Patents, and Licensing