Skip to content

ci: re-pin codeql-action to the true v4.38.0 commit - #97

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/repin-codeql-v4.38.0
Sep 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
ci/repin-codeql-v4.38.0

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Re-pin codeql-action to the true v4.38.0 commit

This repo pinned github/codeql-action to a commit whose trailing comment said # v4.38.0.
It is not v4.38.0. Dereferencing both annotated tags:

tag tag object commit
v4.38.0 4bd7200e b96794f015dfd88f77b49b1c93e0fa7110f94c63
v4.38.1 c23de5a8 1c5b675653bb5c22dbe9b12b556ec555138e09fd

So the pin was v4.38.1 — the version blocked estate-wide (nexia-list#100) — wearing a
v4.38.0 label. The comment lied; in several repos the actions.lock recorded
ref: 'v4.38.1' for the same SHA and had been telling the truth all along.

Where the ref was a bare tag @v4.38.1, it was additionally unpinned — a mutable ref
upstream can re-point at any time. Those are now pinned to a SHA and moved off the blocked
version.

Why one commit

GitHub compares actions.lock to the workflow by literal string. A lock edit and a workflow
edit that disagree — even for one commit — produce a startup_failure, not a stale lock. So the
workflow uses:, the lock's workflows: reference, the dependencies: record
(ref, commit, key) and any nested uses: sub-list all move together here.

Several of these workflows are dead on main right now

A base-state census of all 40 affected repos compared each workflow's literal uses: ref against
its own actions.lock entry before any change:

lock state for the affected workflow repos status on main
no actions.lock at all 14 runs — workflow-only rewrite
entry agrees with the workflow 19 instances runs — lock and workflow move together here
entry already names b96794f0… while the workflow still pins the blocked SHA 16 instances startup_failure — dead
no entry for that workflow path 2 instances runs (enforcement is per-path opt-in)

That third row is the important one. In those repos the lock had already been moved to the
correct v4.38.0 commit and the workflow never followed, so the two disagree and GitHub rejects the
run at startup. Directly observed: hyperpolymath/scripts reports CodeQL Security Analysis startup_failure on its current main head.

So for those repos this PR is not hygiene — it resurrects a CodeQL workflow that has not run at
all
. Expect previously-absent checks to appear; a red among them is a scanner speaking for the
first time, not a regression.

The last row was measured, not assumed: a missing lock entry leaves a workflow unvalidated and it
runs normally (metadatastician/metadatastician-governance, whose lock covers 3 of 8 workflows).
Only a disagreeing entry is fatal. No lock keys are added here — adding one would newly enable
enforcement for a workflow that is currently exempt, which is a policy change, not a repair.

How this was verified before it was written

The transformer was dry-run against fetched copies of every distinct shape in the estate and the
result checked semantically at the YAML level, not by reading a diff:

  • the codeql-action record reads exactly ref: v4.38.0, commit: sha1-b96794f0…, with
    owner_id/repo_id untouched;
  • every workflows: edge and every nested uses: edge resolves to a record — the lock stays
    transitively closed, which is what actually keeps jobs from vanishing;
  • no file anywhere still names the blocked version;
  • a line-conservation invariant holds: every output line is an input line, possibly retargeted.
    A line may only be dropped as a rename-collapse duplicate, and every drop is reported.

The dry run caught three destructive bugs before any repo was touched — an over-eager dedupe that
deleted pre-existing legitimate refs, a record-body pattern that silently dropped 12-space nested
uses: lists, and a line rebuild that ate the - of list-item uses:.

Mutation-tested, because a passing check proves nothing until it kills a mutant: blinding the
workflow rewriter and blinding the lock retarget were both caught by the cross-file lock guard;
the unmutated control reports LOCK-OK.

Expected effect

CodeQL moves from the blocked v4.38.1 to v4.38.0. Any red here that predates this commit is
pre-existing and is tracked separately under the stopping rule — a new scanner finding is an issue
with acceptance criteria, not a merge blocker.

Refs hyperpolymath/standards#1005.

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

The pin 1c5b675653bb5c22dbe9b12b556ec555138e09fd is the commit that the
annotated tag v4.38.1 dereferences to -- not v4.38.0, despite the trailing
comment claiming otherwise. v4.38.1 is blocked estate-wide (nexia-list#100),
so every repo carrying this pin has in fact been running the blocked version.

  v4.38.0 -> tag object 4bd7200e -> commit b96794f015dfd88f77b49b1c93e0fa7110f94c63
  v4.38.1 -> tag object c23de5a8 -> commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd

Where the ref was a bare tag (@v4.38.1) it was also unpinned -- a mutable ref
upstream can re-point at will -- so it is now pinned to a SHA as well as moved
off the blocked version.

In a number of repos the lock had already been moved to b96794f0 while the
workflow was left on the blocked SHA. Those two disagree, so the workflow is
currently rejected at startup and has not been running at all; this commit
makes the workflow match the lock and brings it back to life.

The workflow and actions.lock are changed in a single commit: GitHub compares
the lock to the workflow by literal string, so a partial edit is a startup
failure rather than a stale lock.

Refs: hyperpolymath/standards#1005

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b1a18134-fc42-448a-b278-62c231e8c7b1

📥 Commits

Reviewing files that changed from the base of the PR and between f02b589 and 78f7fb7.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/codeql.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (6)
  • GitHub Check: governance / Guix primary / Nix fallback policy
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: CodeQL Analysis (actions, none)
⚠️ CI failures not shown inline (11)

GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/quality-gates.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 14.

GitHub Actions: Workflow Security Linter / lint-workflows: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/quality-gates.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 14.

GitHub Actions: Governance / 4_governance _ Well-Known (RFC 9116 + RSR).txt: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run MIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)
 �[36;1mMIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)�[0m
 �[36;1mif [ -n "$MIXED" ]; then�[0m
 �[36;1m  echo "::error::Mixed content (HTTP in HTML)"�[0m

GitHub Actions: Governance / 5_governance _ Security policy checks.txt: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / governance _ Security policy checks: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / 8_governance _ Code quality + docs.txt: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / governance _ Code quality + docs: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / 9_governance _ Workflow security linter.txt: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run failed=0
 �[36;1mfailed=0�[0m
 �[36;1mfor file in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$file" ] || continue�[0m
 �[36;1m  if ! head -1 "$file" | grep -q "^# SPDX-License-Identifier:"; then�[0m
 �[36;1m    echo "ERROR: $file missing SPDX header"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1m  if ! grep -q "^permissions:" "$file"; then�[0m
 �[36;1m    echo "ERROR: $file missing top-level 'permissions:' declaration"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1m[ $failed -eq 1 ] && { echo "Add SPDX header + permissions:"; exit 1; }�[0m
 �[36;1mecho "All workflows have SPDX headers + permissions"�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/quality-gates.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 Add SPDX header + permissions:
 ##[error]Process completed with exit code 1.

GitHub Actions: Governance / governance _ Workflow security linter: ci: re-pin codeql-action to the true v4.38.0 commit

Conclusion: failure

View job details

##[group]Run failed=0
 �[36;1mfailed=0�[0m
 �[36;1mfor file in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$file" ] || continue�[0m
 �[36;1m  if ! head -1 "$file" | grep -q "^# SPDX-License-Identifier:"; then�[0m
 �[36;1m    echo "ERROR: $file missing SPDX header"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1m  if ! grep -q "^permissions:" "$file"; then�[0m
 �[36;1m    echo "ERROR: $file missing top-level 'permissions:' declaration"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1m[ $failed -eq 1 ] && { echo "Add SPDX header + permissions:"; exit 1; }�[0m
 �[36;1mecho "All workflows have SPDX headers + permissions"�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/quality-gates.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 Add SPDX header + permissions:
 ##[error]Process completed with exit code 1.
🧰 Additional context used
🪛 GitHub Actions: Governance / 9_governance _ Workflow security linter.txt
.github/workflows/codeql.yml

[error] 1-1: Workflow validation step failed: missing SPDX header. Add an SPDX-License-Identifier comment on the first line.

🪛 GitHub Actions: Governance / governance _ Workflow security linter
.github/workflows/codeql.yml

[error] 1-1: Workflow validation failed: missing SPDX header on line 1.

🪛 GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt
.github/workflows/codeql.yml

[error] 1-1: SPDX header check failed: missing SPDX-License-Identifier on the first line. The workflow validation command exited with code 14.

🪛 GitHub Actions: Workflow Security Linter / lint-workflows
.github/workflows/codeql.yml

[error] 1-1: SPDX header check failed: missing SPDX-License-Identifier on the first line. Command failed with exit code 14.

🔇 Additional comments (1)
.github/workflows/codeql.yml (1)

37-37: LGTM!

Also applies to: 43-43, 46-46


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the version-pinned actions used for automated code security checks.

Walkthrough

The CodeQL workflow updates the commit pin for its init, autobuild, and analyze steps. The release tag and blocking metadata remain unchanged.

Changes

CodeQL Workflow

Layer / File(s) Summary
Update CodeQL action pins
.github/workflows/codeql.yml
The init, autobuild, and analyze steps now use commit b96794f015dfd88f77b49b1c93e0fa7110f94c63. The v4.38.0 tag and blocking metadata are unchanged.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 78f7f

The CodeQL steps and lock metadata agree on the pinned commit, so no actionable merge risk is identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: re-pinning codeql-action to the correct v4.38.0 commit.
Description check ✅ Passed The description explains the CodeQL action re-pin, the workflow and lock updates, and the intended effect. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the pins in place
Three CodeQL steps now share the trace
The tag stays set, the block stays true
A fresh commit guides each step through
Then hops away beneath the moon

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 8dbe60b into main Sep 22, 2026
19 of 22 checks passed
@hyperpolymath
hyperpolymath deleted the ci/repin-codeql-v4.38.0 branch September 22, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant