Repository navigation
build(deps): bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.2 - #41
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.9 to 4.38.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdf488f...2892aa5) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Reviewed the complete diff at 8673c6e: this changes only the SHA-pinned Small documentation inconsistency: the inline The recorded CI predates the merged installer fixes #42/#43. Refresh/revalidate against current main before merging so those changes and this action update are qualified together. |
johnny4young
left a comment
There was a problem hiding this comment.
Review: bump github/codeql-action/upload-sarif 4.37.9 → 4.38.2
What it does: updates the pinned SHA of the SARIF upload step in .github/workflows/scorecard.yml:52.
Verdict: ready. Nothing blocking.
Checked
- The new pin
2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2is exactly the commit that the upstream tagv4.38.2peels to (verified withgit ls-remote https://github.com/github/codeql-action); the old pincdf488f…isv4.37.9. Pinning by full SHA is preserved. - Only file touched is
scorecard.yml; merges cleanly onto currentmain(the base is a few commits behind, no conflicts). All 11 check runs are green. - Local: workflow invariants (
tests/workflows.bash), ShellCheck 0.11.0, shfmt 3.13.1 andbash -nall clean on this head.
Nits
- 🟡
.github/workflows/scorecard.yml:52: the trailing version comment reads# v3, but both the old and the new pins are v4.x releases. Pre-existing, but Dependabot keeps it stale;# v4.38.2would make the pin auditable at a glance like the other pinned actions. - 🟡
CHANGELOG.mdalready lists this bump under Unreleased (without a version), so no changelog edit is needed here.
Generated by Claude Code
Bumps github/codeql-action/upload-sarif from 4.37.9 to 4.38.2 in
.github/workflows/scorecard.yml.Review notes (maintainer)
2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2is exactly what upstream tagv4.38.2peels to (git ls-remote https://github.com/github/codeql-action 'refs/tags/v4.38.2^{}'). The previous pin,cdf488f…, wasv4.37.9. Pinning by full commit SHA is preserved.scorecard.yml:52still reads# v3, although both the old and the new pins are v4.x releases. Dependabot updates the SHA but not that comment. Correct it to# v4.38.2in a separate maintenance commit rather than editing this Dependabot branch: Dependabot only keeps rebasing a PR that nobody else has pushed to.scorecard.yml.CHANGELOG.mdalready lists the bump under Unreleased.8673c6e. Locally,tests/workflows.bash, ShellCheck 0.11.0, shfmt 3.13.1 andbash -nwere clean, and the full suite passed exceptinstall-transaction.bashunder root (environment-only, fixed in fix(sudo): keep line endings when replaying captured command output #49).maineven though its base is a few commits behind.Upstream release notes (v4.38.0 to v4.38.2)
Compare: github/codeql-action@cdf488f...2892aa5
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
·@·d·ependabot r·ebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
·@·d·ependabot r·ebasewill rebase this PR·@·d·ependabot r·ecreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency·@·d·ependabot i·gnore t·his major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)·@·d·ependabot i·gnore t·his minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)·@·d·ependabot i·gnore t·his dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)