Skip to content

build(deps): bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.2 - #41

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/upload-sarif-4.38.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/upload-sarif-4.38.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action/upload-sarif from 4.37.9 to 4.38.2 in .github/workflows/scorecard.yml.

Review notes (maintainer)

  • Pin verified: 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 is exactly what upstream tag v4.38.2 peels to (git ls-remote https://github.com/github/codeql-action 'refs/tags/v4.38.2^{}'). The previous pin, cdf488f…, was v4.37.9. Pinning by full commit SHA is preserved.
  • Stale comment (not changed here): the trailing comment on scorecard.yml:52 still reads # v3, although both the old and the new pins are v4.x releases. Dependabot updates the SHA but not that comment. Correct it to # v4.38.2 in a separate maintenance commit rather than editing this Dependabot branch: Dependabot only keeps rebasing a PR that nobody else has pushed to.
  • Scope: one line in scorecard.yml. CHANGELOG.md already lists the bump under Unreleased.
  • Validation: all 11 checks are green on head 8673c6e. Locally, tests/workflows.bash, ShellCheck 0.11.0, shfmt 3.13.1 and bash -n were clean, and the full suite passed except install-transaction.bash under root (environment-only, fixed in fix(sudo): keep line endings when replaying captured command output #49).
  • Merge order: independent; it merges cleanly onto current main even though its base is a few commits behind.
Upstream release notes (v4.38.0 to v4.38.2)

Compare: github/codeql-action@cdf488f...2892aa5


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting ·@·d·ependabot r·ebase.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • ·@·d·ependabot r·ebase will rebase this PR
  • ·@·d·ependabot r·ecreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • ·@·d·ependabot i·gnore t·his major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • ·@·d·ependabot i·gnore t·his minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • ·@·d·ependabot i·gnore t·his dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.9 to 4.38.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@cdf488f...2892aa5)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Copy link
Copy Markdown
Owner

Reviewed the complete diff at 8673c6e: this changes only the SHA-pinned github/codeql-action/upload-sarif action in the Scorecard workflow. It adds no installer/runtime changes or permission expansion. The existing CI run 36397271670 succeeded, and there are no outstanding review threads/comments to resolve.

Small documentation inconsistency: the inline # v3 label is stale for the 4.38.2 SHA named by this update; the executable pin is correct. I have left the Dependabot branch unchanged rather than disable its automatic maintenance for a cosmetic label.

The recorded CI predates the merged installer fixes #42/#43. Refresh/revalidate against current main before merging so those changes and this action update are qualified together.

@johnny4young johnny4young left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: bump github/codeql-action/upload-sarif 4.37.9 → 4.38.2

What it does: updates the pinned SHA of the SARIF upload step in .github/workflows/scorecard.yml:52.

Verdict: ready. Nothing blocking.

Checked

  • The new pin 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 is exactly the commit that the upstream tag v4.38.2 peels to (verified with git ls-remote https://github.com/github/codeql-action); the old pin cdf488f… is v4.37.9. Pinning by full SHA is preserved.
  • Only file touched is scorecard.yml; merges cleanly onto current main (the base is a few commits behind, no conflicts). All 11 check runs are green.
  • Local: workflow invariants (tests/workflows.bash), ShellCheck 0.11.0, shfmt 3.13.1 and bash -n all clean on this head.

Nits

  • 🟡 .github/workflows/scorecard.yml:52: the trailing version comment reads # v3, but both the old and the new pins are v4.x releases. Pre-existing, but Dependabot keeps it stale; # v4.38.2 would make the pin auditable at a glance like the other pinned actions.
  • 🟡 CHANGELOG.md already lists this bump under Unreleased (without a version), so no changelog edit is needed here.

Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency or automation update github-actions GitHub Actions workflow update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant