Skip to content

chore(deps): bump github/codeql-action from 4.38.0 to 4.38.1 - #2285

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/github/codeql-action-4.38.1
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/github/codeql-action-4.38.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action from 4.38.0 to 4.38.1.

Release notes

Sourced from github/codeql-action's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action's changelog.

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.38.0 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.38.0...v4.38.1)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Continuous Integration Workflows and Automation Dependencies Related to Dependencies labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 21, 2026 19:44
@dependabot dependabot Bot added Continuous Integration Workflows and Automation Dependencies Related to Dependencies labels Sep 21, 2026
@codecov

codecov Bot commented Sep 21, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.74%. Comparing base (ffa3528) to head (fe39d56).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #2285   +/-   ##
========================================
  Coverage    84.74%   84.74%           
========================================
  Files          354      354           
  Lines        31838    31838           
  Branches     31838    31838           
========================================
+ Hits         26981    26982    +1     
  Misses        4475     4475           
+ Partials       382      381    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@da2ce7 da2ce7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at fe39d56e8ae0f8d714fe5dac9d116af908566191 (round 1). Recomputed from the bytes at this head.

This is exactly one uses: edit at .github/workflows/security-scan.yaml:90 (1 addition, 1 deletion), changing github/codeql-action/upload-sarif@v4.38.0 to @v4.38.1. Annotated tag v4.38.1 is object c23de5a82f64bb08c6d9f28844551440ca298e76, which points to commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd; its non-prerelease release was published 2026-09-18T13:11:14Z. The release summary describes experimental per-language CodeQL bundles.

The 76-commit, 47-file upstream delta touches the used path in the shared built runtime lib/entry-points.js; it does not change upload-sarif/action.yml or an upload-sarif-specific source file. Shared source changes include src/actions-util.ts, src/status-report.ts, and src/util.ts; the per-language-bundle changes are in init/setup and download code, which this upload-sarif invocation does not exercise.

Findings

None.

Checked, no finding

  • Exact diff shape, unchanged action path, condition, and with: block.
  • The only workflow reference uses explicit @v4.38.1; no old workflow reference remains.
  • Base and merge base are ffa3528cfd9ed170eeb910c6273bf675637dd3d1; merge-tree is clean.
  • Conventional subject and generated dependency metadata match the diff; the Dependabot provenance trailer is not AI attribution.
  • Forbidden token absent from the changed file.

CI at this head (orchestrator's step, read after every run completed): 33 check-runs — 30 success, 3 skipped by design (Docker E2E on the pull_request event, and both Publish jobs). The Security Scan pull_request run — the workflow this bump edits — concluded success with upload-sarif@v4.38.1, as did the Testing push run. No startup_failure or action_required conclusion, so the organization allowlist admits github/codeql-action/upload-sarif@v4.38.1.

@da2ce7

da2ce7 commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

ACK fe39d56 — one-line tag bump of github/codeql-action to v4.38.1 across 1 workflow, tag verified against its release commit, the delta touching the used upload-sarif runtime, explicit-version format preserved

josecelano added a commit that referenced this pull request Sep 23, 2026
6eb66cb docs(skills): clarify Dependabot action notifications (Jose Celano)
7dcaebb ci(workflows): update download artifact action (Jose Celano)
8136153 ci(workflows): update install action (Jose Celano)
a9efd54 ci(workflows): update GitHub CodeQL action (Jose Celano)

Pull request description:

  # GitHub Workflow Actions Update Pull Request

  ## Summary

  Updated the current compatible releases of `github/codeql-action/upload-sarif`,
  `taiki-e/install-action`, and `actions/download-artifact`. Dependabot pull
  requests were used as advisory notifications; this branch follows the normal
  inventory, validation, and commit process.

  `actions/download-artifact` moves from v5 to v8. Its existing package-coverage
  workflow completed successfully on Dependabot PR #2307, confirming this use of
  `merge-multiple: true` remains compatible.

  ## Files/packages touched

  - `.github/workflows/coverage.yaml`
  - `.github/workflows/generate_coverage_pr.yaml`
  - `.github/workflows/security-scan.yaml`
  - `.github/workflows/testing.yaml`
  - `.github/skills/dev/maintenance/update-github-workflow-actions/SKILL.md`

  ## Organization allowed-actions policy

  No policy update was needed. The supplied organization allowlist was retained
  unchanged, so all entries remain available to other Torrust repositories.
  `taiki-e/install-action@v2.*` permits the updated third-party reference.
  GitHub-owned `actions/download-artifact@v8` and
  `github/codeql-action/upload-sarif@v4.38.1` completed successfully in their
  respective Dependabot PR workflow runs.

  ### Allowed actions before update

  ```text
  EndBug/export-label-config@v1.*,
  EndBug/label-sync@da00f2c,
  EndBug/label-sync@v2.*,
  Swatinem/rust-cache@v2.*,
  actions-rust-lang/setup-rust-toolchain@v1,
  alekitto/grcov@v0.2,
  aquasecurity/trivy-action@v0.*,
  codecov/codecov-action@v7.*,
  docker/build-push-action@v7.*,
  docker/login-action@v4.*,
  docker/metadata-action@v6.*,
  docker/setup-buildx-action@v4.*,
  dtolnay/rust-toolchain@nightly,
  dtolnay/rust-toolchain@stable,
  endbug/export-label-config@v1,
  mozilla-actions/sccache-action@*,
  peter-evans/create-pull-request@v5,
  rustsec/audit-check@v2.0.0,
  smorimoto/tune-github-hosted-runner-network@v1,
  stefanzweifel/git-auto-commit-action@v4,
  swatinem/rust-cache@v2,
  taiki-e/install-action@v2.*,
  taiki-e/install-action@v2.87.2,
  taiki-e/install-action@v2.87.9,
  ```

  ### Allowed actions after update

  ```text
  EndBug/export-label-config@v1.*,
  EndBug/label-sync@da00f2c,
  EndBug/label-sync@v2.*,
  Swatinem/rust-cache@v2.*,
  actions-rust-lang/setup-rust-toolchain@v1,
  alekitto/grcov@v0.2,
  aquasecurity/trivy-action@v0.*,
  codecov/codecov-action@v7.*,
  docker/build-push-action@v7.*,
  docker/login-action@v4.*,
  docker/metadata-action@v6.*,
  docker/setup-buildx-action@v4.*,
  dtolnay/rust-toolchain@nightly,
  dtolnay/rust-toolchain@stable,
  endbug/export-label-config@v1,
  mozilla-actions/sccache-action@*,
  peter-evans/create-pull-request@v5,
  rustsec/audit-check@v2.0.0,
  smorimoto/tune-github-hosted-runner-network@v1,
  stefanzweifel/git-auto-commit-action@v4,
  swatinem/rust-cache@v2,
  taiki-e/install-action@v2.*,
  taiki-e/install-action@v2.87.2,
  taiki-e/install-action@v2.87.9,
  ```

  ## Validation

  - `linter yaml`
  - `linter markdown`
  - `git diff --check`
  - `TORRUST_GIT_HOOKS_LOG_DIR=.tmp ./contrib/dev-tools/git/hooks/pre-commit.sh`
    passed for each signed commit.
  - Set-based comparison confirmed the unchanged before/after allowlists are
    identical; the updated third-party reference is permitted by
    `taiki-e/install-action@v2.*`.
  - Dependabot PRs #2285, #2306, and #2307 passed their hosted workflow checks.

ACKs for top commit:
  josecelano:
    ACK 6eb66cb

Tree-SHA512: b1a488ec1efd1038ec9c57d974669d2f09900053ebe44d336af02215ace1ec2b1622d65194c8e0b431f1f420407a5315cb49428118a04d669451b259d1efb838
@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Looks like github/codeql-action is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 23, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/develop/github/codeql-action-4.38.1 branch September 23, 2026 08:53

This branch was successfully deployed

1 active deployment
coverage — fe39d56e Deployed Sep 21, 2026 by dependabot[bot] via Generate Coverage Report #2230
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Continuous Integration Workflows and Automation Dependencies Related to Dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant