Skip to content

ci: bump github/codeql-action from 3 to 4 in the actions group - #45

Open
dependabot[bot] wants to merge 1 commit into
linuxfrom
dependabot/github_actions/actions-1893dd32ff
Open

dependabot[bot] wants to merge 1 commit into
linuxfrom
dependabot/github_actions/actions-1893dd32ff

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: github/codeql-action.

Updates github/codeql-action from 3 to 4

Release notes

Sourced from github/codeql-action's releases.

v3.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

v3.37.9

  • Update default CodeQL bundle version to 2.26.4. #4106

v3.37.8

No user facing changes.

v3.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085

v3.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v3.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

v3.37.4

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

v3.37.3

No user facing changes.

v3.37.2

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

v3.37.1

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

v3.37.0

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

v3.36.3

No user facing changes.

v3.36.2

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

v3.36.1

No user facing changes.

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

... (truncated)

Commits
  • 762a5ed Add a helper to delete the CodeQL tools from the toolcache
  • ceb85f2 Distinguish GitHub-hosted runners from ones that look hosted
  • 9fddc16 Merge pull request #4088 from github/dependabot/npm_and_yarn/octokit/plugin-r...
  • 36cbf13 Address review comments
  • 38dd4a0 Don't record an overlay status when the job was cancelled
  • 2f3c1c9 Add an internal job-status input to the init Action
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [github/codeql-action](https://github.com/github/codeql-action).


Updates `github/codeql-action` from 3 to 4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 16, 2026
@dependabot
dependabot Bot requested a review from Cam8863 as a code owner September 16, 2026 21:56

@clippy-qa clippy-qa Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clippy reviewed this pull request

The diff is a straightforward and internally consistent bump of github/codeql-action from v3 to v4 across all three steps (init, autobuild, analyze). No new correctness bugs are introduced; v4 has the same permission requirements as v3 and is compatible with ubuntu-latest. Three pre-existing issues in the file are surfaced by the review but were not introduced by this change.

3 findings — 0 blocking · 0 nit · 3 pre-existing

2 findings could not be anchored to the diff, so they are here instead:

  • .github/workflows/codeql.yml:16 — pre-existing: Job-level permissions block is missing contents: read and actions: read When permissions: is explicitly set at the job level, all unspecified permissions default to none. The block only declares security-events: write, so contents: read (needed by actions/checkout to clone the repo) and actions: read (needed by CodeQL to download its bundle on private repositories) are implicitly none. On a private repo or a fork PR this would cause the checkout or Initialize CodeQL step to fail with a 403. The same block was present with v3, so this is not introduced by the bump.
  • .github/workflows/codeql.yml:13 — pre-existing: Stale comment claims multi-platform support that is not implemented The comment on line 13 reads "CodeQL runs on ubuntu-latest, windows-latest, and macos-latest" but runs-on: ubuntu-latest on line 14 is the only runner — no matrix strategy is defined. Platform-specific code paths (Windows DLL loading, macOS framework linkage) are never scanned, and a future maintainer reading this comment could be misled into believing coverage is broader than it is.

No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.

clippy-review: verdict=clean event=COMMENT normal=0 nit=0 pre_existing=3 inline=1 body=2 unresolved=0 head=0433f47

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pre-existing: CodeQL actions pinned to a mutable tag (@v4) rather than an immutable SHA

Lines 25, 35, and 49 all reference github/codeql-action/{init,autobuild,analyze}@v4, a mutable tag. A supply-chain attacker who force-pushes the v4 tag to a malicious commit would silently replace this security scanner with arbitrary code running with security-events: write access — the exact permission needed to tamper with SARIF results. SHA pinning (e.g. @<full-sha>) is the standard mitigation. The v3 references also used a mutable tag, so this pattern predates the diff.

@clippy-qa clippy-qa Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clippy reviewed this pull request

The diff is a single-file change bumping all three github/codeql-action steps from v3 to v4 in the CodeQL workflow; the change is mechanically correct and consistent. No bugs are introduced by the diff itself. Two pre-existing issues in the workflow are worth noting: the actions/checkout@v7 reference may point to a non-existent tag (latest known version was v4 as of August 2025), and the narrow permissions block could break the workflow on private repos or org-restricted token environments.

3 findings — 0 blocking · 1 nit · 2 pre-existing

2 findings could not be anchored to the diff, so they are here instead:

  • .github/workflows/codeql.yml:21 — pre-existing: actions/checkout@v7 may reference a non-existent tag As of August 2025 the latest published major version of actions/checkout was v4; v7 did not exist. If the tag is absent at workflow runtime, GitHub Actions fails the entire job before any step executes, silently breaking all CodeQL scanning. This predates the diff — the bump did not introduce it, but verifying that v7 is a real, current tag is worth confirming before merge.
  • .github/workflows/codeql.yml:16 — pre-existing: Narrow permissions block omits contents: read and actions: read The job declares only security-events: write. When explicit permissions are set at the job level, all unmentioned permissions default to none. GitHub's CodeQL documentation recommends contents: read (for checkout) and actions: read (for the analyze upload) on private repositories or organizations with restricted default GITHUB_TOKEN policies. On such repos the checkout or analyze step fails with a 403. This is pre-existing and unrelated to the v3→v4 bump, but the bump was an opportunity to fix it.

No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.

clippy-review: verdict=clean event=COMMENT normal=0 nit=1 pre_existing=2 inline=1 body=2 unresolved=0 head=0433f47

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Floating semver tags used instead of pinned SHA digests

All four action references (actions/checkout@v7, codeql-action/init@v4, codeql-action/autobuild@v4, codeql-action/analyze@v4) use mutable floating tags. A force-pushed or compromised tag silently substitutes different code into a step that holds security-events: write permission, enabling manipulation of SARIF results with no visible diff. The v3→v4 bump was a natural moment to pin each action to an immutable SHA digest; it was not taken.

@clippy-qa clippy-qa Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clippy reviewed this pull request

The diff is a three-line version bump of github/codeql-action from v3 to v4 across all three steps (init, autobuild, analyze) — consistent and complete. Two pre-existing issues were surfaced by the review that were not introduced by this change.

2 findings — 0 blocking · 0 nit · 2 pre-existing

2 findings could not be anchored to the diff, so they are here instead:

  • .github/workflows/codeql.yml:21 — pre-existing: actions/checkout@v7 does not correspond to any published release The current stable major version of actions/checkout is v4; v7 has not been released. This tag appears identically across all 11 workflow files in the repo, suggesting it may be a local/private tag. If the tag is ever absent or the repo runs on standard GitHub Actions infrastructure without that tag, every workflow will fail at checkout with 'Unable to resolve action'.
  • .github/workflows/codeql.yml:17 — pre-existing: permissions block omits contents: read, unlike every other workflow in the repo All other workflows (ci.yml, ci-linux.yml, publish-apt.yml, etc.) explicitly declare contents: read. This workflow only has security-events: write. On organizations with restrictive default permissions, checkout and source scanning can fail. Not introduced by this diff — the permissions block was unchanged — and verified not to be a new requirement of v4 over v3.

No blocking findings — nothing in scope blocks the merge, and no thread I opened is unresolved. Approval on this base branch is a human's to give.

clippy-review: verdict=clean event=COMMENT normal=0 nit=0 pre_existing=2 inline=0 body=2 unresolved=0 head=0433f47

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants