fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) - #90
Conversation
v4.38.1 (tag AND commit SHA 1c5b675) fails GitHub workflow-startup validation estate-wide: codeql/hypatia runs die with startup_failure, zero jobs, no API error text. Full investigation + evidence chain: nexia-list#100. Rollback to the v4.38.0 commit b96794f015dfd88f77b49b1c93e0fa7110f94c63 (matches green deed-ecosystem; satisfies repo SHA-pin policy), actions.lock re-keyed where present. Dependabot held at v4.38.0 unconditionally: versions-scoped ignores were bypassed downstream (nexia-list#101 re-raised the bump in SHA form, copying the inline warning comment while swapping the SHA). Canonical fix at origin: hyperpolymath/standards#973. Batch-mates: nexia-list#100 (merged), hypatia, vexometer, rsr-template-repo, burble.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (14)
|
| Layer / File(s) | Summary |
|---|---|
Pin CodeQL workflow actions .github/workflows/codeql.yml |
The init, autobuild, and analyze steps now use commit b96794f015dfd88f77b49b1c93e0fa7110f94c63, annotated as v4.38.0. |
Suppress CodeQL action updates .github/dependabot.yml |
Dependabot now ignores all updates to github/codeql-action. The comment records the pinned revision and the reason for the hold. |
Priority: ⬆️ High
Estimated code review effort: 1 (Trivial) | ~5 minutes
Change: Bug fix
Merge Risk: ⚪ Minimal · up to fca6b
The CodeQL rollback and version hold are consistent and introduce no identified merge-blocking risk.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the CodeQL action rollback to v4.38.0, the SHA pin, and the Dependabot hold. It accurately summarises the main changes. |
| Description check | ✅ Passed | The description directly explains the v4.38.1 startup_failure incident, the rollback, and the Dependabot hold. It is related to the changeset. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches
🛠️ Fix failing CI checks
- Commit to this branch
- Create a new PR
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks the pinned code,
The workflow hops along its road,
Dependabot rests its ears,
No newer tag can reach these gears,
Four paws guard the version load.
Comment @coderabbitai help to get the list of available commands.
|
✅ Coding Agent task started: View task and status The task will inspect the CI failures, validate its fix, and open a stacked fix pull request automatically.
⏭️ 1 check(s) skipped — already failing on `main` (not caused by this PR)
|
Summary
Estate-wide incident:
github/codeql-actionv4.38.1 fails GitHub workflow startup on every repo that took it — CodeQL/Hypatia runs die withstartup_failure, zero jobs dispatched, no error text in any API surface. The evidence chain (full detail: nexia-list#100):@v4.38.1tag (via dependabot #94)@1c5b675(4.38.1 SHA)@v4.38.1@1c5b675The v4.38.1 tag exists (peels to
1c5b675) and byte-identical workflow content runs under a fresh path — so the failure is the version value itself at GitHub's start-validation layer, not content, permissions (probes withsecurity-eventsstart fine), or the default-setup conflict.Changes here
codeql-reusable.yml,hypatia-scan-reusable.yml:codeql-action/*re-pinned1c5b675(v4.38.1) →b96794f0(v4.38.0 commit; wrong# v3comments corrected to# v4.38.0).actions.lock: re-keyed to the v4.38.0 SHA entries (dependabot bumped the reusable pins without regenerating the lock).dependabot.yml: full hold ongithub/codeql-action— scopedversions:ignores do NOT hold for this bot path (nexia-list#101 re-raised the bump in SHA form within an hour, copying the inline warning comment verbatim while swapping the SHA).Follow-ups
Consumer rollbacks shipped in the same batch: nexia-list (merged ✅), hypatia, vexometer, rsr-template-repo, metadatastician/burble (each with the same dependabot hold). Reconsider the hold when upstream clears v4.38.1 or a newer release verifies green on one canary repo.