build(deps): bump github/codeql-action from 4.37.1 to 4.37.3 - #8003
build(deps): bump github/codeql-action from 4.37.1 to 4.37.3#8003dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the GitHub Actions CodeQL workflow to use a newer patch release of the github/codeql-action steps.
Changes:
- Bump
github/codeql-action/initfromv4.37.1tov4.37.3 - Bump
github/codeql-action/analyzefromv4.37.1tov4.37.3
| # Initializes the CodeQL tools for scanning. | ||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v4.37.1 | ||
| uses: github/codeql-action/init@v4.37.3 |
|
|
||
| - name: Perform CodeQL Analysis | ||
| uses: github/codeql-action/analyze@v4.37.1 | ||
| uses: github/codeql-action/analyze@v4.37.3 |
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.1 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.1...v4.37.3) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
901069d to
bb36ff4
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
Suppressed comments (2)
.github/workflows/codeql-analysis.yml:73
- Pinning GitHub Actions by mutable tags (like
v3/v3.x.y) can allow supply-chain changes without a code review. Consider pinninguses:to a full commit SHA (optionally with a comment indicating the human-readable release) for stronger provenance.
uses: github/codeql-action/init@v4.37.3
.github/workflows/codeql-analysis.yml:99
- Pinning GitHub Actions by mutable tags (like
v3/v3.x.y) can allow supply-chain changes without a code review. Consider pinninguses:to a full commit SHA (optionally with a comment indicating the human-readable release) for stronger provenance.
uses: github/codeql-action/analyze@v4.37.3
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
Suppressed comments (2)
.github/workflows/codeql-analysis.yml:73
- Security hardening: consider pinning GitHub Actions to a full commit SHA (optionally with a comment for the corresponding version tag). Pinning reduces supply-chain risk compared to mutable tags like
v4.37.3.
uses: github/codeql-action/init@v4.37.3
.github/workflows/codeql-analysis.yml:99
- Security hardening: consider pinning GitHub Actions to a full commit SHA (optionally with a comment for the corresponding version tag). Pinning reduces supply-chain risk compared to mutable tags like
v4.37.3.
uses: github/codeql-action/analyze@v4.37.3
|
Superseded by #8030. |
Pull request was closed
Bumps github/codeql-action from 4.37.1 to 4.37.3.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
Commits
e4fba86Merge pull request #4031 from github/update-v4.37.3-72f6a9da0fb50ab5Update changelog for v4.37.372f6a9dMerge pull request #4030 from github/mbg/fix/no-proxy3b5ee58Use defaultrequestoptions instead ofundefinedbfb6be4Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621526ab84Rebuildd6217b9Update changelog and version after v4.37.2e064762Merge pull request #4027 from github/update-v4.37.2-385bcdc5ae0faed8Add a couple of change notes73aad0eUpdate changelog for v4.37.2