Skip to content

fix(ci): run one codeql-action release across init and analyze - #505

Merged
danielmarv merged 1 commit into
mainfrom
fix/codeql-action-version
Sep 30, 2026
Merged

danielmarv merged 1 commit into
mainfrom
fix/codeql-action-version

Conversation

@danielmarv

Copy link
Copy Markdown
Contributor

Description:

Run one github/codeql-action release across the CodeQL workflow. Dependabot bumped analyze (#491) and upload-sarif (#498) to v4.38.2, but the matching init bump (#497) was closed, so init still runs v4.38.1. analyze then refuses the config init wrote:

Loaded a configuration file for version '4.38.1', but running version '4.38.2'

That fails both Analyze jobs on main and on every open PR (e.g. #422).

  • Pin codeql-action/init to v4.38.2 (2892aa5), the same commit as analyze and upload-sarif
  • Correct the stale # v4.3.5 version comments on all three pins
  • Group the github/codeql-action* updates in Dependabot so they are bumped in one PR

Related issue(s):

Follow-up to #491, #497, #498

Notes for reviewer:

v4.38.2's annotated tag resolves to 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. Once this merges, re-running CodeQL on open PRs picks up the fixed workflow.

Checklist

  • Commits are signed and signed-off: git commit -S -s

Dependabot bumped analyze (#491) and upload-sarif (#498) to v4.38.2, but
the matching init bump (#497) was closed, so init still ran v4.38.1.
CodeQL refuses a config written by another version, which fails every
Analyze job on main and on open PRs.

Pin init to v4.38.2 as well, correct the stale version comments, and
group the codeql-action updates so Dependabot bumps them together.

Signed-off-by: Ntege Daniel <danientege785@gmail.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: hiero-hackers/analytics/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: 29b88dbb-2365-4e9d-892a-422e8f706fb5

📥 Commits

Reviewing files that changed from the base of the PR and between 193100a and 8a76fb1.

📒 Files selected for processing (3)
  • .github/dependabot.yml
  • .github/workflows/codeql.yml
  • .github/workflows/scorecard.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The Dependabot configuration groups GitHub CodeQL action updates. The CodeQL initialization action reference changes to v4.38.2, and the CodeQL analysis and Scorecard upload-SARIF version comments are updated to v4.38.2.

Changes

CodeQL action alignment

Layer / File(s) Summary
Group and align CodeQL action updates
.github/dependabot.yml, .github/workflows/codeql.yml, .github/workflows/scorecard.yml
Dependabot groups github/codeql-action* updates. The CodeQL initialization reference changes to v4.38.2. The analysis and upload-SARIF action version comments change to v4.38.2; their pinned commit references remain unchanged.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 8a76f

The CodeQL actions are aligned on v4.38.2, addressing the reported mixed-release workflow failure. No actionable merge risk remains in the reviewed changes.

Architecture Summary

Architecture risk: 🔵 Low · up to 8a76f

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/dependabot.yml: Adds a codeql-action Dependabot group for GitHub Actions updates matching github/codeql-action*; comments identify init, analyze, and upload-sarif as actions that must share a release.
  • observed — Modified behavior in .github/workflows/codeql.yml: The CodeQL initialization action is updated from commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd (v4.3.5) to 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 (v4.38.2).
  • observed — Modified behavior in .github/workflows/codeql.yml: The CodeQL analysis action retains commit 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2; its version comment changes from v4.3.5 to v4.38.2.
  • observed — Modified behavior in .github/workflows/scorecard.yml: The upload-SARIF action’s version comment changes from v4.3.5 to v4.38.2; its pinned commit SHA is unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the CodeQL version mismatch, the workflow updates, and the Dependabot grouping change.
Title check ✅ Passed The title clearly and concisely describes the primary change: aligning the CodeQL action release across the workflow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@danielmarv
danielmarv merged commit 6b818e3 into main Sep 30, 2026
13 checks passed
danielmarv added a commit to 5affron/analytics that referenced this pull request Sep 30, 2026
Picks up the codeql-action fix (hiero-hackers#505) so CodeQL runs on this PR.

Signed-off-by: Ntege Daniel <danientege785@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants