Repository navigation
ci: bump github/codeql-action/analyze from 3.28.1 to 4.37.7 - #69
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
@dependabot rebase |
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 3.28.1 to 4.37.7. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b6a472f...ff2f1c6) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
86d218d to
54bd9ff
Compare
Dependabot cannot fix this, and its two open PRs prove it. It raises one PR per action path, so init and analyze move independently — but CodeQL requires them to be the exact same version, not merely the same major. Bumping init to v4.37.6 (#68) left analyze on v3.28.1, and #69 then failed with Loaded a configuration file for version '4.37.6', but running version '4.37.7' because by the time it was recreated the target had moved again. Neither PR can be green while the other is open, no matter the order they merge in. So all three uses go to v4.37.7 in one commit: init and analyze in codeql.yml, and upload-sarif in scorecard.yml, which was on the same stale pin. Keeping them on one line means the next bump is one decision instead of a race between three. Supersedes #69.
|
Superseded by #74, which moves This PR could not pass on its own. CodeQL requires |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github/codeql-action/analyze from 3.28.1 to 4.37.7.
Release notes
Sourced from github/codeql-action/analyze's releases.
... (truncated)
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
ff2f1c6Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8951a133Update changelog for v4.37.7be7a3dbMerge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334Merge pull request #4086 from github/mbg/thread-action-state-to-codeqlb4d8a54Rebuildab5db25Bump the npm-minor group across 1 directory with 8 updates38055a3DroploggerfromdatabaseInitClusterin interface1f87aedMerge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3dc1b98aMakeloggeravailable togetCodeQLForCmd6f0220eMerge pull request #4084 from github/navntoft/bump-undici