chore(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 - #219
Conversation
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.7 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
[rootline-team/qa] 2026-09-05T16:28:29Z QA_BLOCKED — SHA El producto compila y los smokes seleccionados pasan, pero el cambio propio de este PR no ha sido ejecutado: Entorno y procedencia
Fixture real sin Git
version: 2
root: true
scope:
match: "*.md"
schema:
status:
type: enum
required: true
values: [Pending, Completed]
---
status: Pending
---
# QA task
Desbloqueo requeridoEjecutar manualmente Limitación: no modifiqué código ni disparé workflows. El comentario de Dependabot sobre la etiqueta inexistente |
pablontiv
left a comment
There was a problem hiding this comment.
[rootline-team/revisor] 2026-09-05T16:42:38Z
Resultado: BLOCKED — SHA 5813332b7af9c03bd6a731e0d294283583c498bc
Revisé el diff completo, el estado del PR, comentarios, threads, reglas vigentes y ejecuciones asociadas al SHA. El cambio está acotado al pin de github/codeql-action/upload-sarif y no encontré un defecto material adicional en el diff. CI #828 está en success y no hay solicitudes de cambios ni threads pendientes.
No se integra porque el gate QA obligatorio sigue bloqueado. El informe [rootline-team/qa] vigente es QA_BLOCKED para este mismo SHA y una consulta fresca de Actions sigue mostrando una sola ejecución: CI #828. No existe ejecución de OpenSSF Scorecard que haya ejercitado el paso modificado Upload to code-scanning.
Para desbloquear:
- Ejecutar manualmente
OpenSSF Scorecardsobre la ramadependabot/github_actions/github/codeql-action/upload-sarif-4.37.9. - Confirmar que Upload to code-scanning termina satisfactoriamente en este SHA.
- Obtener
QA_PASSde[rootline-team/qa]para el mismo SHA. - Revalidar SHA, checks y reglas antes del merge por squash.
No se intentó merge.
Bumps github/codeql-action/upload-sarif from 4.37.7 to 4.37.9.
Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)