Currently, codeql-action/init and analyze expect to be running at the exact same version. Please make this more resilient to slight version drift, so the two components can be updated separately from each other.
At the moment, codeql-action has a Dependabot Compatibility Score of only 2%. This literally means that 98% of customer projects currently see pipeline-breaking pull requests — for each and every CodeQL release. Many projects require all test pipelines to pass before merging a pull request. However, with CodeQL’s current releases, Dependabot sends two pull requests that depend on each other (examples: brawer/osmdiffs#379 and brawer/osmdiffs#380). While project maintainers can bypass their automated checks, the current mutual dependency of independently released CodeQL components causes mental load to project maintainers.
To become more resilient, perhaps you could change codeql-action/init to emit config files that also work with the past ~3 versions of codeql/analyze. Alternatively, perhaps you could change codeql/analyze to accept config files produced by newer versions of codeql/init; for this, you might want to add a “minimum required codeql-analyze version” field (or so) to your internal file format.
Whatever your technical solution ends up being, huge thanks for fixing this. The 98% of Dependabot/CodeQL users whose projects you’re currently breaking with every CodeQL release will be eternally grateful. :-)
Currently,
codeql-action/initandanalyzeexpect to be running at the exact same version. Please make this more resilient to slight version drift, so the two components can be updated separately from each other.At the moment, codeql-action has a Dependabot Compatibility Score of only 2%. This literally means that 98% of customer projects currently see pipeline-breaking pull requests — for each and every CodeQL release. Many projects require all test pipelines to pass before merging a pull request. However, with CodeQL’s current releases, Dependabot sends two pull requests that depend on each other (examples: brawer/osmdiffs#379 and brawer/osmdiffs#380). While project maintainers can bypass their automated checks, the current mutual dependency of independently released CodeQL components causes mental load to project maintainers.
To become more resilient, perhaps you could change
codeql-action/initto emit config files that also work with the past ~3 versions ofcodeql/analyze. Alternatively, perhaps you could changecodeql/analyzeto accept config files produced by newer versions ofcodeql/init; for this, you might want to add a “minimum required codeql-analyze version” field (or so) to your internal file format.Whatever your technical solution ends up being, huge thanks for fixing this. The 98% of Dependabot/CodeQL users whose projects you’re currently breaking with every CodeQL release will be eternally grateful. :-)