Repository navigation
chore(deps): bump the github-actions group with 2 updates - #1850
Conversation
Bumps the github-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) Updates `github/codeql-action/analyze` from 4.37.8 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Looks good, straightforward version bump.
What was reviewed: the diff for .github/workflows/codeql.yml, confirming it only updates the pinned commit SHAs (and version comments) for github/codeql-action/init and github/codeql-action/analyze from v4.37.8 to v4.37.9. No other lines changed, and the new SHA matches the official v4.37.9 release tag.
Extended reasoning...
Overview
The only change is in .github/workflows/codeql.yml, a Dependabot-authored bump of the pinned commit SHA (with matching version comment) for the github/codeql-action/init and github/codeql-action/analyze steps from v4.37.8 to v4.37.9. No workflow permissions, triggers, secrets usage, or job structure changed.
Security risks
None identified. The action is still pinned to a full commit SHA (not a mutable tag), which is the secure pattern for third-party GitHub Actions, and the SHA corresponds to the genuine upstream v4.37.9 release of github/codeql-action per the PR description's changelog/commit links. There is no change to permissions, secrets, or workflow triggers that could introduce privilege escalation.
Level of scrutiny
This warrants only light scrutiny: it is a routine, automated dependency bump (Dependabot) to a CI-only workflow file, mechanical in nature, with no application code touched.
Other factors
The bug hunting system reported no findings, and my own diff review confirms the change is limited exactly to the two SHA/version-comment pairs described. No CODEOWNERS restrictions or prior unresolved review comments apply here.
wochinge
left a comment
There was a problem hiding this comment.
Reviewed as CODEOWNERS approval for the .github/ path: routine Dependabot patch bump of github/codeql-action (init + analyze) 4.37.8 → 4.37.9, pinned by commit SHA. Only version comments/SHAs change; no permissions, triggers, or secrets touched. All CI checks pass.
38c824f to
7edb53f
Compare
wochinge
left a comment
There was a problem hiding this comment.
Approved: SHA-pinned patch update to CodeQL Action v4.37.9; no workflow behavior or permission changes.
Bumps the github-actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze.
Updates
github/codeql-action/initfrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/analyzefrom 4.37.8 to 4.37.9Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions