chore(deps): bump github/codeql-action from 4 to 4.37.4 - #1563
chore(deps): bump github/codeql-action from 4 to 4.37.4#1563dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4...v4.37.4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.4 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 83e787f3c4
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| # Initializes the CodeQL tools for scanning | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v4 | ||
| uses: github/codeql-action/init@v4.37.4 |
There was a problem hiding this comment.
Keep CodeQL on the moving major tag
This workflow identifies itself as an advanced CodeQL setup, and the CodeQL Action docs recommend using the moving major tag (for example, v4) so scans automatically pick up new action fixes, features, and CodeQL CLI/query bundles; pinning init to v4.37.4 freezes the scanner until another Dependabot PR is merged. In repos where weekly scheduled scans are expected to stay current even without dependency PR churn, this leaves security analysis running stale bits, and the same pinning should be reverted to @v4 for the CodeQL steps. See GitHub’s guidance: https://github.com/github/codeql-action#keeping-the-codeql-action-up-to-date-in-advanced-setups
Useful? React with 👍 / 👎.
|
🤖 pr-fix routine: blocked on a protected file path A reviewer's feedback requires modifying Context for whoever picks this up:
The routine will not pick this PR up again until the Generated by Claude Code |
Bumps github/codeql-action from 4 to 4.37.4.
Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
Commits
18420e3Merge pull request #4043 from github/mbg/ts/changelog7e8d897Merge pull request #4046 from github/mbg/repo-prop/code-quality2d4c474Log!analysisKindSupportedcase98c05a1Fix argument validation inrollback-changelog.ts8289a49Ignore repository property for unsupported analysis kinds2a8731cMoveconfig-filecomputation after determining theanalysisKinds3434fbbMerge pull request #4044 from github/mbg/ff/promote-toolcache3013ac0PromoteAllowToolcacheInputfeature74b15aaInstall JS deps if needed inpost-release-mergebackworkflowf00f809Fix checking keys rather than valuesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)