Skip to content

chore(deps): pair CodeQL updates and refresh the compatible platform manifest - #1143

Merged
abrichr merged 2 commits into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.38.0
Sep 14, 2026
Merged

abrichr merged 2 commits into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.38.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown
Contributor

CodeQL initialization and analysis now use the same 4.38.0 commit. Dependabot groups future updates because an analysis step can't read initialization state from a different action version. This includes #1144.

The platform manifest also selects published Flow 1.35.1 and Types 0.17.0. Flow requires Types below 0.18.0, so the manifest records that exact selection instead of selecting the latest incompatible Types release. The generator refreshes artifact digests, source references, dependency edges, and the generated compatibility report from the published records. Package versions and signed admissions don't change.

Validation: the offline manifest and source-boundary checks pass. The focused manifest drift and version-display tests pass. The live validator verifies the exact published artifacts, release sources, Desktop sidecar lock, and public status.

Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.9 to 4.38.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@cdf488f...b96794f)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 12, 2026
@dependabot
dependabot Bot requested a review from abrichr as a code owner September 12, 2026 07:43
Signed-off-by: abrichr <richard.abrich@mldsai.com>
@abrichr abrichr changed the title chore(deps): bump github/codeql-action/analyze from 4.37.9 to 4.38.0 chore(deps): pair CodeQL updates and refresh the compatible platform manifest Sep 14, 2026
@abrichr
abrichr merged commit 25175b9 into main Sep 14, 2026
13 checks passed
@abrichr
abrichr deleted the dependabot/github_actions/github/codeql-action/analyze-4.38.0 branch September 14, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant