chore(deps): bump the github-actions group across 1 directory with 2 updates - #3521
dependabot[bot] wants to merge 1 commit into
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Codex review: needs maintainer review before merge. Reviewed September 15, 2026, 12:12 PM ET / 16:12 UTC (Revision 19). ClawSweeper reviewWhat this changesUpdates ClawHub’s CodeQL initialization and analysis actions from v4.37.7 to v4.38.0 while retaining full commit pins. Merge readiness✅ Ready for maintainer review This update remains useful: current main retains the older CodeQL pin, and no replacement PR was found. No blocking findings emerged from the workflow, upstream compatibility, or supply-chain review. Priority: P3 Review scores
Verification
How this fits togetherCodeQL Light scans selected ClawHub source and workflow files through five security profiles. GitHub Actions initializes the analyzer, runs the configured queries, and uploads results to GitHub code scanning. flowchart LR
A[Repository changes or scheduled run] --> B[Workflow filters]
B --> C[Five security profiles]
C --> D[Initialize CodeQL]
D --> E[Analyze selected source]
E --> F[GitHub code scanning results]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep both CodeQL actions synchronized on the verified release commit within the existing five-profile workflow. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates a CI dependency and does not report a product bug. Is this the best way to solve the issue? Yes—updating both immutable pins is the narrowest maintenance path. Retaining the old release misses the update, while floating tags would weaken reproducibility; neither is preferable. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 91aecdc22c53. LabelsLabel justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (18 earlier review cycles; latest 8 shown)
|
7f61dfb to
5669a8c
Compare
This comment has been minimized.
This comment has been minimized.
5669a8c to
e602a94
Compare
e602a94 to
1cc9508
Compare
1cc9508 to
5983ae0
Compare
5983ae0 to
325f9cb
Compare
7d8677d to
133ed1d
Compare
This comment has been minimized.
This comment has been minimized.
133ed1d to
cbc1e20
Compare
cbc1e20 to
93d0474
Compare
93d0474 to
df0b470
Compare
df0b470 to
3c888a9
Compare
This comment has been minimized.
This comment has been minimized.
3c888a9 to
9f0a270
Compare
9f0a270 to
ddb47da
Compare
|
Found 2 test failures on Blacksmith runners: Failures
|
…updates Bumps the github-actions group with 2 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.7 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...b96794f) Updates `github/codeql-action/analyze` from 4.37.7 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...b96794f) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
ddb47da to
6f7bd76
Compare
Bumps the github-actions group with 2 updates in the / directory: github/codeql-action/init and github/codeql-action/analyze.
Updates
github/codeql-action/initfrom 4.37.7 to 4.38.0Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
b96794fMerge pull request #4131 from github/update-v4.38.0-7e08580a902d5093Update changelog for v4.38.07e08580Merge pull request #4130 from github/henrymercer/workflow-runner-sizingbfcc52bRun slow macOS checks on larger runners8c251e7Merge pull request #4129 from github/update-bundle/codeql-bundle-v2.27.00b7ca40Add changelog note40484b3Update default bundle to codeql-bundle-v2.27.0977e6ceMerge pull request #4124 from github/henrymercer/toolcache-bundle-cleanup40a6b38Address toolcache cleanup review feedbackdeece8fApply suggestion from@henrymercerUpdates
github/codeql-action/analyzefrom 4.37.7 to 4.38.0Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
b96794fMerge pull request #4131 from github/update-v4.38.0-7e08580a902d5093Update changelog for v4.38.07e08580Merge pull request #4130 from github/henrymercer/workflow-runner-sizingbfcc52bRun slow macOS checks on larger runners8c251e7Merge pull request #4129 from github/update-bundle/codeql-bundle-v2.27.00b7ca40Add changelog note40484b3Update default bundle to codeql-bundle-v2.27.0977e6ceMerge pull request #4124 from github/henrymercer/toolcache-bundle-cleanup40a6b38Address toolcache cleanup review feedbackdeece8fApply suggestion from@henrymercer