Skip to content

chore(deps): update github/codeql-action digest to 2892aa5 - #221

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action (changelog) action digest 5595cca → 2892aa5

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.13%. Comparing base (cfeb1ef) to head (1968044).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #221   +/-   ##
=======================================
  Coverage   94.13%   94.13%           
=======================================
  Files          10       10           
  Lines         290      290           
  Branches      105      105           
=======================================
  Hits          273      273           
  Misses          1        1           
  Partials       16       16           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest, but the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). Skipping auto-merge — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep: skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (any change to .github/workflows/** is flagged for human approval). The change itself is a digest bump on github/codeql-action and CI is green, but policy requires a human review for workflow-file edits. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), which is out of scope for autopilot auto-merge regardless of CI state or labels. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if the change is wanted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Even though checks are green and the change is only a digest bump of github/codeql-action, my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to ff2f1c6 chore(deps): update github/codeql-action digest to db488dd Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 43cd070 to 7f63b36 Compare August 21, 2026 14:43
@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which is in the excluded paths for auto-merge. Skipping auto-merge; please review and merge manually if appropriate.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7f63b36 to e9a3057 Compare August 22, 2026 00:03

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (5595cca → db488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review — hard exclusion in scope.

PR #221 modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action). Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.

CI is green and the change is a routine CodeQL action digest update; human reviewer can merge after confirming the new digest matches an upstream release. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagged by DevSecOps autopilot: hard exclusion — touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope. Please review manually and merge when satisfied.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from e9a3057 to 7e75162 Compare August 26, 2026 00:05
@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to db488dd chore(deps): update github/codeql-action digest to cdf488f Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7e75162 to 5cff28d Compare August 26, 2026 16:09

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security (permissions, secrets, supply-chain). Not auto-merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Flagged for human approval — not auto-merged.

Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest 5595cca → cdf488f (scorecard workflow).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. Acceptable, but the autopilot does not auto-merge workflow changes per policy.

Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily Renovate sweep — flagged for human review.

This PR modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action), which falls under the hard-excluded CI/CD workflow paths. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.

No auto-merge performed. Please review the workflow edit and merge manually if approved.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 5cff28d to d2d111b Compare September 1, 2026 00:02

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot flagged this PR for human approval.

Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.

What this PR does: Updates the github/codeql-action digest from 5595cca → cdf488f (action digest bump).

CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change itself is a CodeQL action digest bump (5595cca → cdf488f) and looks safe, but workflow changes always need a human to confirm there's no permissions/secrets expansion. Please review and merge if you're comfortable. — tldr: green CI but excluded from auto-merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green. The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review. Please review and merge if you're comfortable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion for automated merge: workflow files execute with repository credentials, so an action digest bump there needs a human to confirm the new digest maps to the intended upstream tag. CI is fully green — this is a policy hold, not a quality problem. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged by the daily Renovate sweep). CI is fully green (CodeQL + Lint/Test/Build/Security + E2E + codecov), so the diff itself looks safe — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a digest bump of github/codeql-action (5595cca → cdf488f). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.

This PR updates github/codeql-action digest in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge. Not approving. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep — DevSecOps autopilot (TIM-353).

Hard exclusion: this PR modifies .github/workflows/scorecard.yml. Per the sweep policy, workflow-file changes require human approval and are never auto-merged. No labels present, so no risk-tier classification could be applied.

Action: awaiting-human. Please review and merge manually if appropriate.

---🤖 Generated by Renovate sweep autopilot at 2026-09-18T00:00:00Z

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to b96794f chore(deps): update github/codeql-action digest to 1c5b675 Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7345b0b to 19e6cde Compare September 18, 2026 21:40
@timoa

timoa commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Renovate daily sweep (TIM-356). Skipped: required checks CodeQL-Build and Lint, Test, Build & Security are FAILING. PR also touches .github/workflows/scorecard.yml (hard exclusion — no auto-merge either way). codeql-action digest bump only; please review the CodeQL job logs.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep: skipping. PR modifies .github/workflows/scorecard.yml (codeql-action digest bump). Hard exclusion — workflow-touching changes require human approval per DevSecOps policy. CI also shows Lint, Test, Build & Security FAILURE on 2026-09-18. Asking for a human to review and merge manually if desired.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps sweep (TIM-360): auto-merge skipped. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (.github/workflows/**). Also CI: Lint, Test, Build & Security FAILURE. Required: human review and approval.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate autopilot: hard exclusion triggered. Diff touches .github/workflows/scorecard.yml (github/codeql-action digest bump). Per DevSecOps policy, any PR modifying .github/workflows/** is never auto-merged. Requesting human review and approval before merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate digest bump of github/codeql-action modifies . Hard exclusion: workflow-file changes require human review and are not eligible for auto-merge. Also, the Lint, Test, Build & Security check is currently failing. Please triage and merge manually once approved.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate digest bump of github/codeql-action modifies .github/workflows/scorecard.yml. Hard exclusion: workflow-file changes require human review and are not eligible for auto-merge. Also, the Lint, Test, Build & Security check is currently failing. Please triage and merge manually once approved.

@timoa

timoa commented Sep 24, 2026

Copy link
Copy Markdown
Owner

DevSecOps daily sweep (2026-09-24): touches .github/workflows/scorecard.yml (hard exclusion) and Lint, Test, Build & Security FAILURE. Skipping. Needs human review of workflow diff.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to 1c5b675 chore(deps): update github/codeql-action digest to 2892aa5 Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 19e6cde to 189920c Compare September 24, 2026 23:05

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this PR as awaiting-human review.

Reason: PR touches .github/workflows/** (hard exclusion list). Renovate bumps to GitHub Actions or third-party action versions can change supply-chain trust boundaries (digest pinning, action permissions, with: credentials). Human approval required before merge.

No auto-merge. No approve from autopilot.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hard exclusion: this PR touches .github/workflows/scorecard.yml (CI/workflow config). Per the DevSecOps guard in TIM-376, PRs that modify .github/workflows/** are never auto-merged. Needs human review/approval before merge.

Diff summary: bumps github/codeql-action digest (5595cca → 2892aa5) in scorecard.yml only.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚧 Awaiting human approval. This PR updates github/codeql-action via .github/workflows/scorecard.yml, which falls under the hard exclusion for .github/workflows/**. Per the Renovate autopilot policy, this diff cannot be auto-merged. Please review the action digest change (5595cca → 2892aa5) and merge manually once approved. CI is also reporting a Lint, Test, Build & Security failure that will need attention.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (TIM-380) reviewed this PR. Touches .github/workflows/scorecard.yml — automated workflow changes are excluded from auto-merge per DevSecOps policy and require human approval. Status: awaiting-human. Please review and merge manually when satisfied.

CI: CodeQL green; Lint, Test, Build & Security failing — likely unrelated dependency-related lint breakage (see repo-wide trend). No action recommended here beyond human review of the workflow file.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hard exclusion: this PR modifies .github/workflows/scorecard.yml (codeql-action digest bump). DevSecOps autopilot does not auto-merge changes to .github/workflows/** per policy. CI also shows Lint, Test, Build & Security failure. Please have a human reviewer approve, fix the CI gate, and re-run.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate github/codeql-action digest bump. Files: .github/workflows/scorecard.yml. Hard exclusion triggered — autopilot never auto-merges changes to .github/workflows/. CI also FAILURE on 'Lint, Test, Build & Security'. Required human review + workflow-file guard. Skipping.

@timoa

timoa commented Oct 5, 2026

Copy link
Copy Markdown
Owner

DevSecOps daily sweep (TIM-397): hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow). Workflow-file edits are out of scope for auto-merge. Please review and merge manually if appropriate.

@timoa

timoa commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Awaiting human approval: this PR modifies .github/workflows/scorecard.yml (github/codeql-action digest bump). Workflow changes are excluded from auto-merge per DevSecOps policy. Please review and merge manually if acceptable. — DevSecOps autopilot (TIM-400)

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep: hard exclusion — this PR modifies .github/workflows/scorecard.yml (github/codeql-action bump to digest 2892aa5). Per the daily Renovate sweep policy, workflow-file changes require human approval before merge. Also flagging that 'Lint, Test, Build & Security' check is currently FAILURE. Please review the workflow impact, confirm the new codeql-action digest is safe, and approve manually. No auto-merge.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch 7 times, most recently from efdbf46 to 92b4e19 Compare October 7, 2026 04:59
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 92b4e19 to 1968044 Compare October 7, 2026 05:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant