Bump github/codeql-action/init from d8073367669608af8fbcc5f63dd0a0d52bb90cff to 1c5b675653bb5c22dbe9b12b556ec555138e09fd - #2
Open
dependabot[bot] wants to merge 6 commits into
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Every repository here asks strangers to run it against their own data, and until now none of them said where to send a security report, what counts as one, or how to get the tests running. That is the first thing a careful person looks for and the first thing missing. The security policy is specific to this tool rather than a template: what is a vulnerability here, and what is a bug that deserves an issue instead.
Actions are pinned to commits instead of tags: a tag can be moved by whoever owns the action, a commit cannot, and the version stays in a comment beside it. Scorecard publishes its result to the public OpenSSF registry, CodeQL reads the paths the tests do not reach, and release artefacts now carry provenance anyone can verify with `gh attestation verify`. A number a stranger can look up is worth more than a README claiming care.
The census of the 2,000 most visited sites joins the UCP survey as its own section, with the first survey keeping its date and its numbers. The security.txt survey gets a page of its own, built the same way: every figure is read out of the file the audit run wrote, so a number that is not in that file cannot appear on the page, and no site name ever reaches the site. Purple on white, laid out like dkautomation.dev, with white as the theme rather than a preference: this is a page people link to and screenshot, and it should look the same to everyone.
init from v3 and analyze from v4 in one run ends in 'loaded a configuration file for version 4.38.0, but running version 3.38.1'. The steps are pinned to one commit of v4, which is the version GitHub now serves.
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from d8073367669608af8fbcc5f63dd0a0d52bb90cff to 1c5b675653bb5c22dbe9b12b556ec555138e09fd. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@d807336...1c5b675) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/github/codeql-action/init-4.38.0
branch
from
September 19, 2026 08:45
90fb43d to
22bab40
Compare
dkautomation23
force-pushed
the
main
branch
2 times, most recently
from
September 21, 2026 09:44
245b0e0 to
9035e8e
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github/codeql-action/init from d8073367669608af8fbcc5f63dd0a0d52bb90cff to 1c5b675653bb5c22dbe9b12b556ec555138e09fd.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits