fix(security): keep every CodeQL Action phase on one revision - #780
fix(security): keep every CodeQL Action phase on one revision#780seonghobae wants to merge 16 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/oc Refetch the live pull request and abort without writing unless its exact head is |
Rebuild the PR from protected develop with only the atomic CodeQL lifecycle update, its test-first contract, doctoring record, and changelog entry. Remove unrelated PDF.js and npm lockfile drift from this branch.
8d932e5 to
efd875b
Compare
|
Exact-head triage at |
|
@opencode-agent Review the exact current head |
Update every CodeQL lifecycle phase and SARIF uploader to the verified upstream v4.37.7 commit, refresh the regression contract, changelog, and doctoring, and record the v2.26.3 bundle update. Preserve immutable SHA pinning and the existing atomic-version policy.
|
Queued @opencode-agent for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
3 similar comments
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
2 similar comments
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
Already queued @opencode-agent on this exact request for PR #780 at head |
|
@opencode-agent Repair the exact current-head Ruff formatter blocker on the existing |
|
/oc Refetch PR #780 and abort without writing unless the live branch is Systematic-debugging evidence for this exact head:
The hand-edited layout on Verification acceptance on the successor exact head: focused |
|
@opencode-agent Repair only the current exact-head formatter blocker on the existing Authoritative current-head RED evidence is CI run Run the repository-pinned formatter ( |
Problem
Dependabot opens CodeQL
init,autobuild,analyze, andupload-sarifupdates independently. Merging them separately creates an unreviewed mixed CodeQL lifecycle. This branch is the canonical BandScope owner for keeping every checked-in CodeQL Action phase on one reviewed immutable revision.Exact current identity
develop@acdbea6344fe1231c39535b575f4de35e4c607c9.fix/codeql-action-consistency-v4-37-6.b860c4960083d3abf0ffe2682b2a75f0418f42c0.Exactly six files differ from protected
develop: the three CodeQL/SARIF workflow files,CHANGELOG.md, the CodeQL doctoring note, and the permanent Python contract test. There is no application dependency or root lockfile diff.Atomic v4.37.8 update
The branch now pins every checked-in
github/codeql-action/init,autobuild,analyze, andupload-sarifreference to CodeQL Actionv4.37.8target commitdb488ddef3bf6cb639b32c2e9a7c0a7ea8271d28and updates the matching version annotations.Fresh upstream verification on 2026-08-26 KST resolved
refs/tags/v4.37.8to annotated tag object37f2634a92ba38a0926ef79a0748ac8ae7d95ab2, whose target is commitdb488ddef3bf6cb639b32c2e9a7c0a7ea8271d28. The tag object is unsigned, so the security claim remains intentionally narrow: workflows execute the reviewed immutable commit SHA; no signed-tag claim is made. The v4.37.8 release reports no user-facing changes and retains the CodeQL bundle line introduced by v4.37.7.Workflow triggers, permissions, language selection, build behavior, SARIF paths, application dependencies, database, network authority, filesystem authority, model, and IPC surfaces are unchanged.
Regression contract / update order
The permanent guard in
services/analysis-engine/tests/test_codeql_action_revision_contract.pyscans every checked-in CodeQL Action reference, including malformed or mutable refs, and requires one reviewed exact SHA plus the matching version annotation.For this update the expected SHA/version was changed first in commit
c43bf95bc0cb0fff952c3ef46bcb15c31fd4bed5, making the old v4.37.7 workflow state a deterministic RED candidate. The workflow phases were then advanced on the same canonical branch, followed by doctoring and CHANGELOG. Hosted RED is not claimed unless a terminal run against that intermediate head is available; the test-first source order is the evidence currently available.Split Dependabot ownership
The fresh v4.37.8 split PRs #1026 (
init), #1028 (analyze), #1029 (autobuild), and #1030 (upload-sarif) are dependency fragments of this atomic lifecycle and are not independently merge-ready authority. Do not copy predecessor checks or approvals from those PRs into this branch. Close them only after this coordinated exact head is proven semantically superseding and accepted under the protected merge gate.Historical split sets (#764/#766/#767/#768 and #924/#930/#932/#933) remain predecessor evidence only.
Dependency / review boundaries
.githubworkflows are read-only control-plane authority from this BandScope writer.Exact-head verification
All workflow evidence from head
738495ca9d425fb34a12e76c0614eda356e68f3aand earlier is predecessor evidence after the v4.37.8 commits. Fresh repository and central workflows for exact current headb860c4960083d3abf0ffe2682b2a75f0418f42c0must be terminal-success before readiness can be claimed. Queued, pending, skipped-required, cancelled, failed, stale, predecessor-head, protected-base, self/author, model-only, or administrative-bypass evidence is non-passing.Merge gate
Keep Draft and unmerged until this unchanged exact head has the focused CodeQL revision contract GREEN, complete repository CI/build/release/SAST/security/SBOM/supply-chain/package evidence terminal-success, exact required owned statement/branch coverage and docstrings, fresh central OpenCode/Noema/Strix/coverage evidence, zero valid unresolved findings, a qualifying independent non-author last-push approval, and ordinary branch-protection acceptance without bypass. Never force-push, self-approve, weaken a gate, or merge one CodeQL phase independently.