ci: bump github/codeql-action from 3 to 4 in the actions group - #45
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions group with 1 update: [github/codeql-action](https://github.com/github/codeql-action). Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Clippy reviewed this pull request
The diff is a straightforward and internally consistent bump of github/codeql-action from v3 to v4 across all three steps (init, autobuild, analyze). No new correctness bugs are introduced; v4 has the same permission requirements as v3 and is compatible with ubuntu-latest. Three pre-existing issues in the file are surfaced by the review but were not introduced by this change.
3 findings — 0 blocking · 0 nit · 3 pre-existing
2 findings could not be anchored to the diff, so they are here instead:
.github/workflows/codeql.yml:16— pre-existing: Job-level permissions block is missingcontents: readandactions: readWhenpermissions:is explicitly set at the job level, all unspecified permissions default tonone. The block only declaressecurity-events: write, socontents: read(needed byactions/checkoutto clone the repo) andactions: read(needed by CodeQL to download its bundle on private repositories) are implicitlynone. On a private repo or a fork PR this would cause the checkout or Initialize CodeQL step to fail with a 403. The same block was present with v3, so this is not introduced by the bump..github/workflows/codeql.yml:13— pre-existing: Stale comment claims multi-platform support that is not implemented The comment on line 13 reads "CodeQL runs on ubuntu-latest, windows-latest, and macos-latest" butruns-on: ubuntu-lateston line 14 is the only runner — no matrix strategy is defined. Platform-specific code paths (Windows DLL loading, macOS framework linkage) are never scanned, and a future maintainer reading this comment could be misled into believing coverage is broader than it is.
No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.
clippy-review: verdict=clean event=COMMENT normal=0 nit=0 pre_existing=3 inline=1 body=2 unresolved=0 head=0433f47
| # Initializes the CodeQL tools for scanning. | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| uses: github/codeql-action/init@v4 |
There was a problem hiding this comment.
pre-existing: CodeQL actions pinned to a mutable tag (@v4) rather than an immutable SHA
Lines 25, 35, and 49 all reference github/codeql-action/{init,autobuild,analyze}@v4, a mutable tag. A supply-chain attacker who force-pushes the v4 tag to a malicious commit would silently replace this security scanner with arbitrary code running with security-events: write access — the exact permission needed to tamper with SARIF results. SHA pinning (e.g. @<full-sha>) is the standard mitigation. The v3 references also used a mutable tag, so this pattern predates the diff.
There was a problem hiding this comment.
Clippy reviewed this pull request
The diff is a single-file change bumping all three github/codeql-action steps from v3 to v4 in the CodeQL workflow; the change is mechanically correct and consistent. No bugs are introduced by the diff itself. Two pre-existing issues in the workflow are worth noting: the actions/checkout@v7 reference may point to a non-existent tag (latest known version was v4 as of August 2025), and the narrow permissions block could break the workflow on private repos or org-restricted token environments.
3 findings — 0 blocking · 1 nit · 2 pre-existing
2 findings could not be anchored to the diff, so they are here instead:
.github/workflows/codeql.yml:21— pre-existing: actions/checkout@v7 may reference a non-existent tag As of August 2025 the latest published major version ofactions/checkoutwas v4; v7 did not exist. If the tag is absent at workflow runtime, GitHub Actions fails the entire job before any step executes, silently breaking all CodeQL scanning. This predates the diff — the bump did not introduce it, but verifying that v7 is a real, current tag is worth confirming before merge..github/workflows/codeql.yml:16— pre-existing: Narrow permissions block omits contents: read and actions: read The job declares onlysecurity-events: write. When explicit permissions are set at the job level, all unmentioned permissions default tonone. GitHub's CodeQL documentation recommendscontents: read(for checkout) andactions: read(for the analyze upload) on private repositories or organizations with restricted default GITHUB_TOKEN policies. On such repos the checkout or analyze step fails with a 403. This is pre-existing and unrelated to the v3→v4 bump, but the bump was an opportunity to fix it.
No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.
clippy-review: verdict=clean event=COMMENT normal=0 nit=1 pre_existing=2 inline=1 body=2 unresolved=0 head=0433f47
| # Initializes the CodeQL tools for scanning. | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| uses: github/codeql-action/init@v4 |
There was a problem hiding this comment.
nit: Floating semver tags used instead of pinned SHA digests
All four action references (actions/checkout@v7, codeql-action/init@v4, codeql-action/autobuild@v4, codeql-action/analyze@v4) use mutable floating tags. A force-pushed or compromised tag silently substitutes different code into a step that holds security-events: write permission, enabling manipulation of SARIF results with no visible diff. The v3→v4 bump was a natural moment to pin each action to an immutable SHA digest; it was not taken.
There was a problem hiding this comment.
Clippy reviewed this pull request
The diff is a three-line version bump of github/codeql-action from v3 to v4 across all three steps (init, autobuild, analyze) — consistent and complete. Two pre-existing issues were surfaced by the review that were not introduced by this change.
2 findings — 0 blocking · 0 nit · 2 pre-existing
2 findings could not be anchored to the diff, so they are here instead:
.github/workflows/codeql.yml:21— pre-existing: actions/checkout@v7 does not correspond to any published release The current stable major version of actions/checkout is v4; v7 has not been released. This tag appears identically across all 11 workflow files in the repo, suggesting it may be a local/private tag. If the tag is ever absent or the repo runs on standard GitHub Actions infrastructure without that tag, every workflow will fail at checkout with 'Unable to resolve action'..github/workflows/codeql.yml:17— pre-existing: permissions block omits contents: read, unlike every other workflow in the repo All other workflows (ci.yml, ci-linux.yml, publish-apt.yml, etc.) explicitly declarecontents: read. This workflow only hassecurity-events: write. On organizations with restrictive default permissions, checkout and source scanning can fail. Not introduced by this diff — the permissions block was unchanged — and verified not to be a new requirement of v4 over v3.
No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.
clippy-review: verdict=clean event=COMMENT normal=0 nit=0 pre_existing=2 inline=0 body=2 unresolved=0 head=0433f47
Bumps the actions group with 1 update: github/codeql-action.
Updates
github/codeql-actionfrom 3 to 4Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
762a5edAdd a helper to delete the CodeQL tools from the toolcacheceb85f2Distinguish GitHub-hosted runners from ones that look hosted9fddc16Merge pull request #4088 from github/dependabot/npm_and_yarn/octokit/plugin-r...36cbf13Address review comments38dd4a0Don't record an overlay status when the job was cancelled2f3c1c9Add an internaljob-statusinput to theinitActionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions