Bump github/codeql-action from 4.37.4 to 4.38.0 - #37
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.4 to 4.38.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.4...v4.38.0) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
jordigilh
left a comment
There was a problem hiding this comment.
Reviewed in depth; no outstanding important findings.
jordigilh
left a comment
There was a problem hiding this comment.
Second review summary
Substantive findings are posted inline below. The existing approval is not execution evidence for the changed reusable workflow.
Verdict: Blocked pending evidence
| - name: Upload SARIF to GitHub Code Scanning | ||
| if: always() && inputs.upload-sarif | ||
| uses: github/codeql-action/upload-sarif@v4.37.4 | ||
| uses: github/codeql-action/upload-sarif@v4.38.0 |
There was a problem hiding this comment.
There is no representative caller run for this changed upload-sarif path at the PR head. Please validate successful scans, detected secrets, SARIF upload, artifact fallback, and restricted-token behavior before treating the reusable workflow as ready.
| - name: Upload SARIF to GitHub Code Scanning | ||
| if: always() && inputs.upload-sarif | ||
| uses: github/codeql-action/upload-sarif@v4.37.4 | ||
| uses: github/codeql-action/upload-sarif@v4.38.0 |
There was a problem hiding this comment.
This third-party action remains tag-pinned while the job has security-events: write. Please pin the action to a verified commit SHA and retain the version in a comment.
| @@ -107,7 +107,7 @@ jobs: | |||
|
|
|||
| - name: Upload SARIF to GitHub Code Scanning | |||
| if: always() && inputs.upload-sarif | |||
There was a problem hiding this comment.
continue-on-error allows SARIF upload failure to produce a green workflow without code-scanning results or PR annotations. Please surface the failure, or explicitly gate the upload on token capability and report the skipped state.
|
Superseded by #38. |
Bumps github/codeql-action from 4.37.4 to 4.38.0.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
Commits
b96794fMerge pull request #4131 from github/update-v4.38.0-7e08580a902d5093Update changelog for v4.38.07e08580Merge pull request #4130 from github/henrymercer/workflow-runner-sizingbfcc52bRun slow macOS checks on larger runners8c251e7Merge pull request #4129 from github/update-bundle/codeql-bundle-v2.27.00b7ca40Add changelog note40484b3Update default bundle to codeql-bundle-v2.27.0977e6ceMerge pull request #4124 from github/henrymercer/toolcache-bundle-cleanup40a6b38Address toolcache cleanup review feedbackdeece8fApply suggestion from@henrymercerDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)