Skip to content

chore(deps): update CodeQL action atomically - #168

Merged
avksp merged 1 commit into
mainfrom
chore/codeql-4.37.9-atomic
Aug 30, 2026
Merged

chore(deps): update CodeQL action atomically#168
avksp merged 1 commit into
mainfrom
chore/codeql-4.37.9-atomic

Conversation

@avksp

@avksp avksp commented Aug 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • update both CodeQL init and analyze actions to the same v4.37.9 commit SHA
  • group CodeQL actions in Dependabot so future updates arrive atomically
  • reject mixed CodeQL action revisions in the CI security validator

Validation

  • full baseline-aware Python quality run: PASS (2039 tests)
  • quality validation: PASS
  • CI security validation: PASS
  • targeted release/package tests: PASS
  • YAML parse and git diff check: PASS

Replaces #161 and #162, whose one-sided updates produce an unsupported mixed CodeQL action version.

@avksp

avksp commented Aug 30, 2026

Copy link
Copy Markdown
Owner Author

Independent exact-head audits completed for bec34e4bad0b7f5238baba56c762ba62ac558bb6.

  • Grok 4.6, xhigh reasoning: PASS, no High/Medium findings. Verified v4.37.9 tag commit, atomic init/analyze pins, fail-closed mismatch behavior, Dependabot matching, scoped tests, and clean worktree. Three non-blocking Low observations concerned validator/grouping hardening only.
  • OpenCode GLM 5.3: PASS, no High/Medium findings. Verified tag dereference, seven adversarial validator mutations, valid Dependabot YAML/group placement, 298 release tests plus 12 package tests, and clean worktree. Two non-blocking Low observations concerned hypothetical future CodeQL sub-actions and comment consistency.

GitHub checks are fully green, including the real CodeQL v4.37.9 job and all OS/Python matrix jobs. Required changes: none.

@avksp
avksp merged commit 90cb0c9 into main Aug 30, 2026
22 checks passed
@avksp
avksp deleted the chore/codeql-4.37.9-atomic branch August 30, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant