Skip to content

fix(ci): bump codeql-action/init and /analyze together to v4 #72

Description

@aparragithub

Problem

.github/workflows/codeql.yml pins two sub-actions from the same github/codeql-action release:

  • github/codeql-action/init@4187e74d05793876e9989daffde9c3e66b4acd07 # v3 (line 25)
  • github/codeql-action/analyze@4187e74d05793876e9989daffde9c3e66b4acd07 # v3 (line 31)

Dependabot PR #65 bumps only init to v4.37.3, leaving analyze on v3. The CodeQL Action requires init and analyze to come from the same release, so merging #65 as-is would split the versions and break the CodeQL / analyze job — which is one of the checks that gates merges to main.

Scope

Notes

v4.37.3 and v4 both resolve to commit e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81, and analyze/action.yml is present at that commit, so one pinned SHA covers both sub-actions.

The v4 line raises the minimum required CodeQL bundle to 2.19.4 and deprecates the undocumented CODEQL_ACTION_CLEANUP_TRAP_CACHES variable. This repository runs CodeQL on GitHub-hosted ubuntu-latest with the default bundle and does not set that variable, so neither applies.

Acceptance criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions