ci: bump github/codeql-action/analyze from 3.37.0 to 4.37.3 - #28
ci: bump github/codeql-action/analyze from 3.37.0 to 4.37.3#28dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
✅ Deploy Preview for getregula ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
@dependabot rebase |
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 3.37.0 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@02c5e83...e4fba86) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
ee09278 to
eef2d81
Compare
🟢 Regula Compliance: PASS
Scanned by Regula — EU AI Act risk indication for code |
…ure action bumps Dependabot PRs #25 and #28 each bumped one half of the init/analyze pair. Neither could ever pass: a v3/v4 major mix hard-fails with "Loaded a configuration file for version '4.37.3', but running version '3.37.0'" (from PR #25's Analyze log), and merging them sequentially would have left main's CodeQL broken between the merges. Both pins move together here; the SHA is the v4.37.3 annotated tag's commit, verified by dereferencing the tag object via the GitHub API (the tag ref itself points at the tag object, which is why dependabot's diff and the tag ref SHA look different at first glance). Root cause fixed, not just the instance: dependabot.yml now groups all github-actions updates into a single PR, so paired actions can never again arrive as two individually-unmergeable PRs. Supersedes and closes #25 and #28. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Xay7z84om27jzJniYMyQpa
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github/codeql-action/analyze from 3.37.0 to 4.37.3.
Release notes
Sourced from github/codeql-action/analyze's releases.
... (truncated)
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
e4fba86Merge pull request #4031 from github/update-v4.37.3-72f6a9da0fb50ab5Update changelog for v4.37.372f6a9dMerge pull request #4030 from github/mbg/fix/no-proxy3b5ee58Use defaultrequestoptions instead ofundefinedbfb6be4Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621526ab84Rebuildd6217b9Update changelog and version after v4.37.2e064762Merge pull request #4027 from github/update-v4.37.2-385bcdc5ae0faed8Add a couple of change notes73aad0eUpdate changelog for v4.37.2