Skip to content

Update github/codeql-action action to v4.38.0 (main) - #1849

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/main-github-actions
Sep 15, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/main-github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action action minor v4.37.9v4.38.0

Release Notes

github/codeql-action (github/codeql-action)

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 15, 2026 01:58
@renovate
renovate Bot enabled auto-merge (squash) September 15, 2026 01:58
@coderabbitai

coderabbitai Bot commented Sep 15, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 19c8cb63-542a-4e5e-8ba7-015673ffabdf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:00 AM UTC · Completed 2:07 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.78

@codecov

codecov Bot commented Sep 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
unit-tests 100.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

Medium

  • [protected-path] .github/workflows/codeql.yml, .github/workflows/scorecards.yml — This PR modifies files under the protected .github/ path (both are GitHub Actions workflow definitions). Human approval is always required for protected-path changes, regardless of context. Context: this is a Renovate-authored PR bumping github/codeql-action from v4.37.9 to v4.38.0; the four uses: refs now pin to b96794f015dfd88f77b49b1c93e0fa7110f94c63, which was verified against the upstream refs/tags/v4.38.0 annotated tag in github/codeql-action and is genuine. The repository's renovate.json (extending github>conforma/.github//config/renovate/renovate.json) authorizes Renovate to open these updates. No workflow permissions: blocks, secrets: references, or triggers were changed — the diff is a pure action-ref bump. Reviewer action required: confirm the release notes for v4.38.0 (linked in PR body) are acceptable, then approve.

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 15, 2026
@renovate
renovate Bot merged commit 5b78c3e into main Sep 15, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/main-github-actions branch September 15, 2026 05:37
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 15, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 5:38 AM UTC · Completed 5:42 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.83

@fullsend-ai-retro

Copy link
Copy Markdown

Renovate PR #1849 (bump github/codeql-action v4.37.9 → v4.38.0, SHA-repin only in two .github/workflows/*.yml files) was reviewed by the fullsend-ai-review agent (run 34919390055, fullsend-ai/agents@v0.41.0). The agent's four sub-reviewers (correctness, security, style-conventions, intent-coherence) all returned clean; only the governance protected-path sub-reviewer emitted two medium findings, because the diff touches .github/. It verified the new SHA against the upstream refs/tags/v4.38.0 tag and confirmed no permissions:/secrets:/trigger changes — solid, well-scoped analysis. post-review.sh then attached the requires-manual-review label at 02:07:29Z.

The label did not gate merge. Renovate auto-merged at 05:37:24Z (~3.5h later) with reviewDecision: REVIEW_REQUIRED, zero human approvals, and the requires-manual-review label still present. CODEOWNERS exists (.github/CODEOWNERS maps * to @conforma/devs) but branch protection evidently does not require CODEOWNERS approval on main, so renovate[bot] was free to hit the auto-merge path once CI passed.

Concrete evidence for existing open issue fullsend-ai/fullsend#6018 ("Post-review script should set REQUEST_CHANGES when applying requires-manual-review label") — this PR is a real-world instance where the label-only gate silently failed against a bot auto-merge, exactly the scenario #6018 addresses. Also related and worth cross-linking rather than re-filing: #5369 (COMMENT vs CHANGES_REQUESTED for governance-only findings on bot PRs), #7186 (staleness nudge for PRs held on the protected-path gate), and the protected-path severity-calibration cluster #3164/#2588/#3061/#4387/#3675 (downgrading protected-path for trusted-bot version-only bumps). One repo-side fix in conforma/policy is proposed below — it complements #6018 rather than duplicating it: even with a REQUEST_CHANGES review, the gate only bites if branch protection requires reviewer approval.

Proposals filed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants