Skip to content

ci: pin every codeql-action step to v4.37.7 - #74

Merged
leonacostaok merged 1 commit into
mainfrom
ci/codeql-4.37.7
Aug 17, 2026
Merged

leonacostaok merged 1 commit into
mainfrom
ci/codeql-4.37.7

Conversation

@leonacostaok

Copy link
Copy Markdown
Member

Supersedes #69, which cannot pass on its own.

Why Dependabot can't do this one

Dependabot opens one PR per action path, so init and analyze move independently. CodeQL requires them to be the exact same version, not merely the same major.

Merging #68 took init to v4.37.6 while analyze stayed on v3.28.1. #69 then failed with:

Loaded a configuration file for version '4.37.6', but running version '4.37.7'

because by the time Dependabot recreated it, the target had moved again. Neither PR can be green while the other is open, in either merge order. This is structural, not a one-off.

What this does

All three uses go to v4.37.7 in one commit:

File Step Was
codeql.yml init v4.37.6
codeql.yml analyze v3.28.1
scorecard.yml upload-sarif v4.37.6

upload-sarif was on the same stale pin and would have drifted next. Keeping all three on one line makes the next bump one decision rather than a race between three PRs.

Note that CodeQL was passing on main despite the v4/v3 split, so this is consistency and future-proofing, not an outage fix.

Dependabot cannot fix this, and its two open PRs prove it. It raises one PR per
action path, so init and analyze move independently — but CodeQL requires them
to be the exact same version, not merely the same major. Bumping init to
v4.37.6 (#68) left analyze on v3.28.1, and #69 then failed with

  Loaded a configuration file for version '4.37.6', but running version '4.37.7'

because by the time it was recreated the target had moved again. Neither PR can
be green while the other is open, no matter the order they merge in.

So all three uses go to v4.37.7 in one commit: init and analyze in codeql.yml,
and upload-sarif in scorecard.yml, which was on the same stale pin. Keeping them
on one line means the next bump is one decision instead of a race between three.

Supersedes #69.
@leonacostaok
leonacostaok merged commit 2a0cefc into main Aug 17, 2026
15 checks passed
@leonacostaok
leonacostaok deleted the ci/codeql-4.37.7 branch August 17, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant