chore(deps): bump github/codeql-action/init from 4.37.3 to 4.37.7 - #135
chore(deps): bump github/codeql-action/init from 4.37.3 to 4.37.7#135dependabot[bot] wants to merge 1 commit into
Conversation
athena-omt
left a comment
There was a problem hiding this comment.
Approved. Reviewed current head 82405b5 locally on Athena: the two workflow-only changes consistently update github/codeql-action/init to the immutable commit for upstream tag v4.37.7. The security workflow call paths and adjacent reusable-workflow/action-pin tests passed. Live PR state is clean and mergeable; CI Gate and Fast Checks passed. No prior reviews, comments, or unresolved review threads; auto-merge is disabled. Residual risk: CodeQL itself is intentionally skipped for this pull-request event by the existing workflow conditions, but the immutable pin was independently verified against the upstream v4.37.7 tag.
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.3 to 4.37.7. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...ff2f1c6) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
82405b5 to
7a37f50
Compare
athena-omt
left a comment
There was a problem hiding this comment.
Approved. Reviewed current head 7a37f50 locally on Athena. The PR changes only the immutable github/codeql-action/init pin in security.yml and security-pr.yml, consistently updating e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 to ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd. Local action-pin validation passed; the live PR is mergeable and clean, with CI Gate, Fast Checks, Validate Secrets, Dependabot verification, Validate Action Pins, and attestation checks successful. No inline or issue comments were present. Auto-merge is enabled. Residual risk: CodeQL, dependency-review, and SBOM are intentionally skipped for this PR event.
Bumps github/codeql-action/init from 4.37.3 to 4.37.7.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
ff2f1c6Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8951a133Update changelog for v4.37.7be7a3dbMerge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334Merge pull request #4086 from github/mbg/thread-action-state-to-codeqlb4d8a54Rebuildab5db25Bump the npm-minor group across 1 directory with 8 updates38055a3DroploggerfromdatabaseInitClusterin interface1f87aedMerge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3dc1b98aMakeloggeravailable togetCodeQLForCmd6f0220eMerge pull request #4084 from github/navntoft/bump-undici