Skip to content

build(codeql): coordinate CodeQL Action 4.37.8 lifecycle - #1026

Draft
dependabot[bot] wants to merge 10 commits into
developfrom
dependabot/github_actions/develop/github/codeql-action/init-4.37.8
Draft

build(codeql): coordinate CodeQL Action 4.37.8 lifecycle#1026
dependabot[bot] wants to merge 10 commits into
developfrom
dependabot/github_actions/develop/github/codeql-action/init-4.37.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

Canonicalize the BandScope CodeQL Action lifecycle on immutable v4.37.8 pin db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 instead of landing phase-specific Dependabot updates independently.

Current exact identity:

  • base: protected develop@7ad56cf0065d068ec6463d92726de4855a6e201d
  • head: 9fc32ab18ce12a78a558de15af004070a7d01fd6
  • state: open, Draft, unmerged

Coordinated lifecycle

This branch now keeps github/codeql-action/init, autobuild, and analyze on the same v4.37.8 immutable SHA in .github/workflows/codeql.yml. It also absorbs the unique #1030 upload-sarif work so Scorecard and Trivy SARIF uploads use the same reviewed v4.37.8 immutable pin. test_codeql_action_version_contract.py protects the in-job init/autobuild/analyze lifecycle; test_codeql_upload_sarif_version_contract.py protects both SARIF uploader pins and their provenance comments. #1030 was closed unmerged only after these unique deltas were preserved here.

Dependabot configuration repair

Dependabot reported that configured label github-actions does not exist. The GitHub Actions ecosystem now uses the repository's existing taxonomy label area: ci-cd alongside dependencies, with test_dependabot_label_contract.py preventing regression to the invalid configured label.

Verification contract

Every push invalidates predecessor evidence. Current repository workflows for this exact head have been dispatched and are not counted as success until terminal. Before leaving Draft or merging, refetch and require the unchanged exact head to pass all applicable repository and central protected-branch gates, including CI/build/release, CodeQL JS/TS and Python analysis, security/dependency/Trivy/OSV/Scorecard, SBOM/supply-chain, coverage-evidence, OpenCode, Noema and Strix as applicable. Require zero valid unresolved review findings and a qualifying independent non-author last-push approval. Queued, cancelled, skipped, predecessor-head, self/author, model-only or status-only evidence is not success.

Do not bypass protection, weaken a gate, replace immutable action pins with tags, or split the CodeQL lifecycle back into competing phase writers.

Relates to #966.

@dependabot @github

dependabot Bot commented on behalf of github Aug 25, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 25, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 25, 2026 17:40
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 25, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Open in Devin Review

Comment thread .github/workflows/codeql.yml Outdated
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.8.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...db488dd)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/github/codeql-action/init-4.37.8 branch from 4af856c to 4a3ff13 Compare August 25, 2026 23:07
@seonghobae seonghobae changed the title build(deps): bump github/codeql-action/init from 4.37.0 to 4.37.8 build(codeql): coordinate CodeQL Action 4.37.8 lifecycle Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant