fix(ci): run one codeql-action release across init and analyze - #505
Conversation
Dependabot bumped analyze (#491) and upload-sarif (#498) to v4.38.2, but the matching init bump (#497) was closed, so init still ran v4.38.1. CodeQL refuses a config written by another version, which fails every Analyze job on main and on open PRs. Pin init to v4.38.2 as well, correct the stale version comments, and group the codeql-action updates so Dependabot bumps them together. Signed-off-by: Ntege Daniel <danientege785@gmail.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: hiero-hackers/analytics/.coderabbit.yml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe Dependabot configuration groups GitHub CodeQL action updates. The CodeQL initialization action reference changes to v4.38.2, and the CodeQL analysis and Scorecard upload-SARIF version comments are updated to v4.38.2. ChangesCodeQL action alignment
Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The CodeQL actions are aligned on v4.38.2, addressing the reported mixed-release workflow failure. No actionable merge risk remains in the reviewed changes. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Picks up the codeql-action fix (hiero-hackers#505) so CodeQL runs on this PR. Signed-off-by: Ntege Daniel <danientege785@gmail.com>
Description:
Run one
github/codeql-actionrelease across the CodeQL workflow. Dependabot bumpedanalyze(#491) andupload-sarif(#498) to v4.38.2, but the matchinginitbump (#497) was closed, soinitstill runs v4.38.1.analyzethen refuses the configinitwrote:That fails both
Analyzejobs on main and on every open PR (e.g. #422).codeql-action/initto v4.38.2 (2892aa5), the same commit asanalyzeandupload-sarif# v4.3.5version comments on all three pinsgithub/codeql-action*updates in Dependabot so they are bumped in one PRRelated issue(s):
Follow-up to #491, #497, #498
Notes for reviewer:
v4.38.2's annotated tag resolves to
2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. Once this merges, re-running CodeQL on open PRs picks up the fixed workflow.Checklist
git commit -S -s