From 366c92a288cafbf5a9fbb0c09afeb978e6f2ba9b Mon Sep 17 00:00:00 2001 From: "Xingdi (Eric) Yuan" <4028684+xingdi-eric-yuan@users.noreply.github.com> Date: Mon, 28 Sep 2026 21:45:25 -0400 Subject: [PATCH 1/2] Update CodeQL stages together and group Dependabot bumps Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/dependabot.yml | 5 +++++ .github/workflows/codeql.yml | 4 ++-- tests/github/workflows/test_codeql.py | 20 ++++++++++++++++++++ 3 files changed, 27 insertions(+), 2 deletions(-) create mode 100644 tests/github/workflows/test_codeql.py diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f93eae3..e65251c 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -11,5 +11,10 @@ updates: schedule: interval: "weekly" open-pull-requests-limit: 5 + groups: + # CodeQL stages share versioned configuration and must move together. + codeql: + patterns: + - "github/codeql-action/*" cooldown: default-days: 7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0596ef7..f9a0301 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,9 +24,9 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: languages: python - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 diff --git a/tests/github/workflows/test_codeql.py b/tests/github/workflows/test_codeql.py new file mode 100644 index 0000000..ffeb717 --- /dev/null +++ b/tests/github/workflows/test_codeql.py @@ -0,0 +1,20 @@ +"""Keep CodeQL stages on one immutable action revision.""" + +import re + + +def test_codeql_action_pins_are_synchronized(repo_root): + workflow = (repo_root / ".github/workflows/codeql.yml").read_text(encoding="utf-8") + actions = re.findall( + r"""^\s*(?:-\s*)?uses:\s*['"]?(github/codeql-action/[\w-]+)@([^\s'"]+)""", + workflow, + re.MULTILINE, + ) + assert {"github/codeql-action/init", "github/codeql-action/analyze"} <= { + name for name, _ in actions + } + pins = {pin for _, pin in actions} + assert all(re.fullmatch(r"[0-9a-f]{40}", pin) for pin in pins), \ + "Pin every CodeQL action to a full commit SHA" + assert len(pins) == 1, \ + "CodeQL stages share versioned configuration; update all pins together" From 0e9995e2e048dafbd7979fc0b78172b3d260c27c Mon Sep 17 00:00:00 2001 From: "Xingdi (Eric) Yuan" <4028684+xingdi-eric-yuan@users.noreply.github.com> Date: Mon, 28 Sep 2026 21:59:03 -0400 Subject: [PATCH 2/2] Allow Windows CI time to finish the real-Git test suite Keep the Linux timeout at ten minutes and give Windows fifteen minutes after the existing suite hit the ten-minute job limit. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/workflows/tests.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 2f4a2bc..105c8bf 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -32,7 +32,7 @@ jobs: pytest: name: pytest (${{ matrix.os }}, Python 3.12) runs-on: ${{ matrix.os }} - timeout-minutes: 10 + timeout-minutes: ${{ matrix.os == 'windows-latest' && 15 || 10 }} strategy: matrix: os: [ubuntu-latest, windows-latest]