Skip to content

[release/v7.4.21] Bump github/codeql-action from 4.35.4 to 4.36.0 - #28045

Merged
Aditya Patwardhan (adityapatwardhan) merged 2 commits into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/27531-e73addb71
Sep 22, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 2 commits into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/27531-e73addb71

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27531 to release/v7.4.21

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of @app/dependabot

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Updates the CodeQL init, analyze, and SARIF upload actions used by release-branch security analysis to the approved 4.36.0 revision.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

Validated with git diff --check and reviewed the final commit diff: exactly three CodeQL action references (init, analyze, and upload-sarif) move to the intended pinned revision. Workflow execution will be validated by backport CI.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk under repository guidance because this changes security-analysis workflow infrastructure. Scope is limited to pinned CodeQL action revisions already merged and exercised on master.

Merge Conflicts

Both workflow files conflicted because release/v7.4.21 carried older pinned CodeQL revisions and the dependency chain also requires the setup-dotnet update from #27539. The #27539 backport commit was stacked first. Conflicts were resolved by preserving each release workflow's structure and replacing only the three CodeQL action SHAs with the incoming #27531 revision; final diff confirms no unrelated changes.

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 21, 2026
Copilot AI lite review requested due to automatic review settings September 21, 2026 21:19
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The macOS workflow contains a YAML indentation issue that can prevent the workflow from parsing/running, and the CodeQL action version annotations are inconsistent with the pinned SHA.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 2 Low severity

Open (3)
What changed in this PR

This PR backports workflow dependency pin updates onto release/v7.4.21, primarily updating GitHub Actions used for CI/build and CodeQL analysis to newer, pinned commit SHAs.

Changes:

  • Bump actions/setup-dotnet pins from v5.2.0 to v5.3.0 across multiple workflows.
  • Bump github/codeql-action pins (init/analyze/upload-sarif) to the v4.36.0 commit SHA in CodeQL-related workflows.
File Description
.github/​workflows/​xunit-tests.yml Updates actions/setup-dotnet pin to v5.3.0.
.github/​workflows/​windows-packaging-reusable.yml Updates actions/setup-dotnet pin to v5.3.0.
.github/​workflows/​analyze-reusable.yml Updates actions/setup-dotnet pin to v5.3.0 and bumps CodeQL init/analyze pins.
.github/​workflows/​scorecards.yml Bumps CodeQL SARIF upload action pin.
.github/​workflows/​macos-ci.yml Updates actions/setup-dotnet pin to v5.3.0 in the macOS packaging job.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 165 to +169
- name: checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 1000
- uses: actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2.0
- uses: actions/setup-dotnet@9a946fdbd5fb07b82b2f5a4466058b876ab72bb2 # v5.3.0
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@c10b8064de6f491fea524254123dbe5e09572f13 # v3.29.5
uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v3.29.5
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@c10b8064de6f491fea524254123dbe5e09572f13 # v3.29.5
uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v3.29.5
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit 1106bab into PowerShell:release/v7.4.21 Sep 22, 2026
37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants