Skip to content

chore(deps): update github/codeql-action action to v4.37.8 - #3978

Merged
thomhurst merged 1 commit into
mainfrom
renovate/github-codeql-action-4.x
Aug 21, 2026
Merged

chore(deps): update github/codeql-action action to v4.37.8#3978
thomhurst merged 1 commit into
mainfrom
renovate/github-codeql-action-4.x

Conversation

@thomhurst

@thomhurst thomhurst commented Aug 21, 2026

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v4.37.7v4.37.8

Release Notes

github/codeql-action (github/codeql-action)

v4.37.8

Compare Source

No user facing changes.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@thomhurst thomhurst added dependencies Pull requests that update a dependency file PATCH renovate-bot labels Aug 21, 2026
@thomhurst
thomhurst enabled auto-merge (squash) August 21, 2026 12:48
@coderabbitai

coderabbitai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 9c5f54df-df2d-4759-944b-b791ea4c98d2

📥 Commits

Reviewing files that changed from the base of the PR and between 10190bc and 285fb8c.

📒 Files selected for processing (1)
  • .github/workflows/codeql.yml

Included review availability: Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The CodeQL workflow updates four action references from v4.37.7 to v4.37.8. Workflow steps and SARIF upload behavior remain unchanged.

Changes

CodeQL workflow

Layer / File(s) Summary
Update CodeQL action references
.github/workflows/codeql.yml
The initialization, analysis, primary upload, and retry upload actions now use v4.37.8.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 285fb

This patch updates the CodeQL action without identified behavior or production-impacting risks; no actionable merge-blocking risk remains beyond normal checks and review.

Poem

I’m a rabbit with a watchful ear,
CodeQL hops to a version clear.
Four steps update in a tidy row,
The workflow keeps its steady flow.
Hop, scan, upload—go!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the CodeQL action version update in the workflow.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/github-codeql-action-4.x

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Aug 21, 2026

Copy link
Copy Markdown

Greptile Summary

Updates every CodeQL action invocation from v4.37.7 to v4.37.8 using a pinned commit SHA.

  • Updates the initialization and analysis actions.
  • Updates both primary and retry SARIF upload actions.

Confidence Score: 5/5

The PR appears safe to merge because the patch-level CodeQL action update is applied consistently across every invocation.

No concrete workflow regression or security-boundary change is established; action inputs and workflow behavior remain unchanged.

Important Files Changed

Filename Overview
.github/workflows/codeql.yml Consistently updates all four CodeQL action references to the same v4.37.8 commit without changing workflow inputs, permissions, or control flow.

Reviews (1): Last reviewed commit: "chore(deps): update github/codeql-action..." | Re-trigger Greptile

@thomhurst
thomhurst merged commit fbef627 into main Aug 21, 2026
15 checks passed
@thomhurst
thomhurst deleted the renovate/github-codeql-action-4.x branch August 21, 2026 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file PATCH renovate-bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants