fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) - #55
Conversation
v4.38.1 (tag AND commit SHA 1c5b675) fails GitHub workflow-startup validation estate-wide (startup_failure, zero jobs). Investigation: nexia-list#100. Rollback to v4.38.0 commit b96794f015dfd88f77b49b1c93e0fa7110f94c63; actions.lock re-keyed where present; dependabot held unconditionally. Canonical: standards#973.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (19)
🔇 Additional comments (2)
📝 SummarySummary by CodeRabbit
WalkthroughThe workflow updates CodeQL actions to v4.38.0. Dependabot ignores further updates for ChangesCodeQL version control
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The workflow pins CodeQL to v4.38.0 and holds further updates, with no supported production failure established for the current change. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkExplanation The description provides a detailed summary and change list, but it omits the required RSR Quality Checklist and the Testing section. It also does not provide the applicable checklist results or test evidence. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the CodeQL trail Comment |
|



Summary
Estate-wide incident:
github/codeql-actionv4.38.1 fails GitHub workflow startup on every repo that took it — CodeQL/Hypatia runs die withstartup_failure, zero jobs dispatched, no error text via the API. Full investigation + evidence chain: nexia-list#100.Changes
codeql-action/*refs (tag@v4.38.1or SHA1c5b675…) re-pinned to the v4.38.0 commitb96794f015dfd88f77b49b1c93e0fa7110f94c63(green on deed-ecosystem; satisfies SHA-pin policy).actions.lockre-keyed where present (dependabot bumpsuses:without regenerating the lock → governance linter failure).dependabot.yml: full hold ongithub/codeql-action— scopedversions:ignores do NOT hold on this path (nexia-list#101 re-raised the bump in SHA form within an hour, copying the inline warning comment verbatim while swapping the SHA).Canonical fix at the estate origin: standards#973. Batch-mates: nexia-list#100 (merged), hypatia#828, vexometer#90, rsr-template-repo#191, empty-linter#99, modshells#119, plasma-parser-writer#98, robodog-defensive-systems-lab#145, twingate-helm-deploy#138, wokelang#147, laniakea#91, maa-framework#198, methodologies#92, rpa-elysium#134, scripts#136, universal-chat-extractor#165, verisimdb#280. Lift the hold once upstream clears 4.38.1 or a canary verifies green.