Skip to content

ci: bump github/codeql-action to v4.38.2 - #6

Merged
kalyazin merged 1 commit into
feat_write_protectionfrom
deps/codeql-action-4.38.2
Sep 28, 2026
Merged

kalyazin merged 1 commit into
feat_write_protectionfrom
deps/codeql-action-4.38.2

Conversation

@kalyazin

Copy link
Copy Markdown
Collaborator

Dependabot opened this bump as three pull requests, one per action path. They cannot land separately: init, analyze and upload-sarif must share a revision, and bumping one alone fails both CodeQL jobs with Loaded a configuration file for version '4.38.2', but running version '4.38.1' — observed on the init and analyze pull requests, where the jobs died after init and left an empty failed-run SARIF under each category.

ACTION_PINS in .github/scripts/security-workflow.test.py moves in the same commit; the shape test fails while the workflow and the pin disagree, which is what made the three split bumps red.

Verified: the three script tests pass; reverting the pin in the test alone puts the shape test red on all three uses.

Supersedes the three split bumps.

init, analyze and upload-sarif share one revision: the action refuses a run
whose analyze half was loaded from a different version than its init half,
so bumping one alone fails every CodeQL job with "Loaded a configuration
file for version X, but running version Y". Dependabot files them as three
pull requests, which is why this is one.

ACTION_PINS moves in the same commit, the shape test asserting the workflow
and the pin agree.

Signed-off-by: Nikita Kalyazin <nikita.kalyazin@e2b.dev>
@cla-bot cla-bot Bot added the cla-signed label Sep 28, 2026
@cursor

cursor Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Routine pinned-action version bump for CI only; no application or auth logic changes.

Overview
Bumps github/codeql-action from v4.38.1 to v4.38.2 across the security workflow in one commit so init, analyze, and upload-sarif all use the same commit SHA (2892aa5e…).

The workflow shape test’s ACTION_PINS entry for github/codeql-action is updated to match, keeping the allowlist in sync with security.yml (split Dependabot bumps would leave mixed versions and fail CodeQL with a config/runtime version mismatch).

Reviewed by Cursor Bugbot for commit ed6837d. Bugbot is set up for automated code reviews on this repo. Configure here.

@kalyazin
kalyazin marked this pull request as ready for review September 28, 2026 16:47
@kalyazin
kalyazin merged commit 959ad2c into feat_write_protection Sep 28, 2026
9 checks passed
@kalyazin
kalyazin deleted the deps/codeql-action-4.38.2 branch September 28, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant