Repository navigation
chore(deps): bump github/codeql-action from 4.38.0 to 4.38.1 - #2285
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.38.0 to 4.38.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.38.0...v4.38.1) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #2285 +/- ##
========================================
Coverage 84.74% 84.74%
========================================
Files 354 354
Lines 31838 31838
Branches 31838 31838
========================================
+ Hits 26981 26982 +1
Misses 4475 4475
+ Partials 382 381 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
da2ce7
left a comment
There was a problem hiding this comment.
Reviewed at fe39d56e8ae0f8d714fe5dac9d116af908566191 (round 1). Recomputed from the bytes at this head.
This is exactly one uses: edit at .github/workflows/security-scan.yaml:90 (1 addition, 1 deletion), changing github/codeql-action/upload-sarif@v4.38.0 to @v4.38.1. Annotated tag v4.38.1 is object c23de5a82f64bb08c6d9f28844551440ca298e76, which points to commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd; its non-prerelease release was published 2026-09-18T13:11:14Z. The release summary describes experimental per-language CodeQL bundles.
The 76-commit, 47-file upstream delta touches the used path in the shared built runtime lib/entry-points.js; it does not change upload-sarif/action.yml or an upload-sarif-specific source file. Shared source changes include src/actions-util.ts, src/status-report.ts, and src/util.ts; the per-language-bundle changes are in init/setup and download code, which this upload-sarif invocation does not exercise.
Findings
None.
Checked, no finding
- Exact diff shape, unchanged action path, condition, and
with:block. - The only workflow reference uses explicit
@v4.38.1; no old workflow reference remains. - Base and merge base are
ffa3528cfd9ed170eeb910c6273bf675637dd3d1; merge-tree is clean. - Conventional subject and generated dependency metadata match the diff; the Dependabot provenance trailer is not AI attribution.
- Forbidden token absent from the changed file.
CI at this head (orchestrator's step, read after every run completed): 33 check-runs — 30 success, 3 skipped by design (Docker E2E on the pull_request event, and both Publish jobs). The Security Scan pull_request run — the workflow this bump edits — concluded success with upload-sarif@v4.38.1, as did the Testing push run. No startup_failure or action_required conclusion, so the organization allowlist admits github/codeql-action/upload-sarif@v4.38.1.
|
ACK fe39d56 — one-line tag bump of github/codeql-action to v4.38.1 across 1 workflow, tag verified against its release commit, the delta touching the used upload-sarif runtime, explicit-version format preserved |
6eb66cb docs(skills): clarify Dependabot action notifications (Jose Celano) 7dcaebb ci(workflows): update download artifact action (Jose Celano) 8136153 ci(workflows): update install action (Jose Celano) a9efd54 ci(workflows): update GitHub CodeQL action (Jose Celano) Pull request description: # GitHub Workflow Actions Update Pull Request ## Summary Updated the current compatible releases of `github/codeql-action/upload-sarif`, `taiki-e/install-action`, and `actions/download-artifact`. Dependabot pull requests were used as advisory notifications; this branch follows the normal inventory, validation, and commit process. `actions/download-artifact` moves from v5 to v8. Its existing package-coverage workflow completed successfully on Dependabot PR #2307, confirming this use of `merge-multiple: true` remains compatible. ## Files/packages touched - `.github/workflows/coverage.yaml` - `.github/workflows/generate_coverage_pr.yaml` - `.github/workflows/security-scan.yaml` - `.github/workflows/testing.yaml` - `.github/skills/dev/maintenance/update-github-workflow-actions/SKILL.md` ## Organization allowed-actions policy No policy update was needed. The supplied organization allowlist was retained unchanged, so all entries remain available to other Torrust repositories. `taiki-e/install-action@v2.*` permits the updated third-party reference. GitHub-owned `actions/download-artifact@v8` and `github/codeql-action/upload-sarif@v4.38.1` completed successfully in their respective Dependabot PR workflow runs. ### Allowed actions before update ```text EndBug/export-label-config@v1.*, EndBug/label-sync@da00f2c, EndBug/label-sync@v2.*, Swatinem/rust-cache@v2.*, actions-rust-lang/setup-rust-toolchain@v1, alekitto/grcov@v0.2, aquasecurity/trivy-action@v0.*, codecov/codecov-action@v7.*, docker/build-push-action@v7.*, docker/login-action@v4.*, docker/metadata-action@v6.*, docker/setup-buildx-action@v4.*, dtolnay/rust-toolchain@nightly, dtolnay/rust-toolchain@stable, endbug/export-label-config@v1, mozilla-actions/sccache-action@*, peter-evans/create-pull-request@v5, rustsec/audit-check@v2.0.0, smorimoto/tune-github-hosted-runner-network@v1, stefanzweifel/git-auto-commit-action@v4, swatinem/rust-cache@v2, taiki-e/install-action@v2.*, taiki-e/install-action@v2.87.2, taiki-e/install-action@v2.87.9, ``` ### Allowed actions after update ```text EndBug/export-label-config@v1.*, EndBug/label-sync@da00f2c, EndBug/label-sync@v2.*, Swatinem/rust-cache@v2.*, actions-rust-lang/setup-rust-toolchain@v1, alekitto/grcov@v0.2, aquasecurity/trivy-action@v0.*, codecov/codecov-action@v7.*, docker/build-push-action@v7.*, docker/login-action@v4.*, docker/metadata-action@v6.*, docker/setup-buildx-action@v4.*, dtolnay/rust-toolchain@nightly, dtolnay/rust-toolchain@stable, endbug/export-label-config@v1, mozilla-actions/sccache-action@*, peter-evans/create-pull-request@v5, rustsec/audit-check@v2.0.0, smorimoto/tune-github-hosted-runner-network@v1, stefanzweifel/git-auto-commit-action@v4, swatinem/rust-cache@v2, taiki-e/install-action@v2.*, taiki-e/install-action@v2.87.2, taiki-e/install-action@v2.87.9, ``` ## Validation - `linter yaml` - `linter markdown` - `git diff --check` - `TORRUST_GIT_HOOKS_LOG_DIR=.tmp ./contrib/dev-tools/git/hooks/pre-commit.sh` passed for each signed commit. - Set-based comparison confirmed the unchanged before/after allowlists are identical; the updated third-party reference is permitted by `taiki-e/install-action@v2.*`. - Dependabot PRs #2285, #2306, and #2307 passed their hosted workflow checks. ACKs for top commit: josecelano: ACK 6eb66cb Tree-SHA512: b1a488ec1efd1038ec9c57d974669d2f09900053ebe44d336af02215ace1ec2b1622d65194c8e0b431f1f420407a5315cb49428118a04d669451b259d1efb838
|
Looks like github/codeql-action is up-to-date now, so this is no longer needed. |
Bumps github/codeql-action from 4.38.0 to 4.38.1.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)