Repository navigation
fix(ci): relock github/codeql-action at v4.38.2 so codeql.yml starts - #105
Conversation
#103 bumped codeql.yml to github/codeql-action@v4.38.2 but .github/workflows/actions.lock still pinned v4.38.0, so every codeql.yml run on main since 97ffa9d dies at startup ("Invalid lockfile", jobs=0; run 37046729552). Dependabot does not update the native lockfile. Regenerated with `gh actions-lock .github/workflows/codeql.yml`. The tool also pruned nine dependency entries that no workflow list, workflow file or transitive `uses:` edge references; the result is transitively closed and `gh actions-lock --no-fix` reports valid. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F1dMuLprAVdZyYPLwZ4t8q
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Autopilot could not be updated. Open Coding to check access and billing. |
Why
#103 bumped
codeql.ymltogithub/codeql-action@v4.38.2, but.github/workflows/actions.lock(the native Actions lockfile, which dependabot does not update) still pinnedv4.38.0. Since merge97ffa9deverycodeql.ymlrun onmainis a startup_failure with the annotationInvalid lockfile: .github/workflows/actions.lock#L1(run 37046729552), i.e. jobs=0 and no check-run at all. The parent9a1067aran green on 2026-10-01.What
Regenerated the lock entry with the authoritative tool:
github/codeql-action@v4.38.0→@v4.38.2(2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2)actions/cache,actions/checkout@3d3c…,actions/upload-artifact@043f…,denoland/setup-deno,dtolnay/rust-toolchain,editorconfig-checker,erlef/setup-beam,ossf/scorecard-action,webfactory/ssh-agent) that noworkflows:list, no workflow file and no transitiveuses:edge references. Measured before accepting: 0 references each; the new lock is transitively closed (9 entries, 3 edges, 0 unresolved) andgh actions-lock --no-fix --jsonreportsvalid: true.No workflow file changes.
Verification after merge
The first
codeql.ymlrun on the merge SHA must not bestartup_failure(actions/runs?head_sha=<merge>).🤖 Generated with Claude Code
https://claude.ai/code/session_01F1dMuLprAVdZyYPLwZ4t8q
Deferred red checks (non-required; standing ruling 2026-09-15)
governance / Allowlist Preflight— red on base97ffa9d(and on9a1067abefore it) → Deferred red checks on dependabot PR #103 #104governance / Workflow security linter— red on base97ffa9d(and on9a1067abefore it) → Deferred red checks on dependabot PR #103 #104