fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) - #112
Conversation
v4.38.1 (tag AND commit SHA 1c5b675) fails GitHub workflow-startup validation estate-wide (startup_failure, zero jobs). Investigation: nexia-list#100. Rollback to v4.38.0 commit b96794f015dfd88f77b49b1c93e0fa7110f94c63; actions.lock re-keyed where present; dependabot held unconditionally. Canonical: standards#973.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (34)
🔇 Additional comments (2)
📝 SummarySummary by CodeRabbit
WalkthroughThe CodeQL workflow now uses the v4.38.0 commit for its ChangesCodeQL action version control
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix · Severity of issue fixed: High Merge Risk: ⚪ Minimal · up to The workflow is pinned to CodeQL v4.38.0 and Dependabot is held from reintroducing the failing update. No actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the action pin, Comment |
Summary
Estate-wide incident:
github/codeql-actionv4.38.1 fails GitHub workflow startup on every repo that took it — CodeQL/Hypatia runs die withstartup_failure, zero jobs dispatched, no error text via the API. Full investigation + evidence chain: nexia-list#100.Changes
codeql-action/*refs (tag@v4.38.1or SHA1c5b675…) re-pinned to the v4.38.0 commitb96794f015dfd88f77b49b1c93e0fa7110f94c63(green on deed-ecosystem; satisfies SHA-pin policy).actions.lockre-keyed where present (dependabot bumpsuses:without regenerating the lock → governance linter failure).dependabot.yml: full hold ongithub/codeql-action— scopedversions:ignores do NOT hold on this path (nexia-list#101 re-raised the bump in SHA form within an hour, copying the inline warning comment verbatim while swapping the SHA).Canonical fix at the estate origin: standards#973. Batch-mates: nexia-list#100 (merged), hypatia#828, vexometer#90, rsr-template-repo#191, empty-linter#99, modshells#119, plasma-parser-writer#98, robodog-defensive-systems-lab#145, twingate-helm-deploy#138, wokelang#147, laniakea#91, maa-framework#198, methodologies#92, rpa-elysium#134, scripts#136, universal-chat-extractor#165, verisimdb#280. Lift the hold once upstream clears 4.38.1 or a canary verifies green.