Skip to content

Bump CodeQL init and analyze actions to 4.38.1 - #28121

Merged
Dongbo Wang (daxian-dbw) merged 3 commits into
masterfrom
daxian-dbw-combined-codeql-bump
Sep 29, 2026
Merged

Dongbo Wang (daxian-dbw) merged 3 commits into
masterfrom
daxian-dbw-combined-codeql-bump

Conversation

@daxian-dbw

Copy link
Copy Markdown
Member

Summary

CodeQL init persists shared configuration that analyze reads later in the workflow, so both steps must run the same action version.

Dependabot generated #28054 and #28055 separately. Each PR updates only one of the two actions and therefore fails CI because the init and analyze versions do not match. This replacement combines both updates to 4.38.1 (1c5b675653bb5c22dbe9b12b556ec555138e09fd) and removes the stale trailing version comments from those two lines.

Validation

  • Verified the final diff against master changes only .github/workflows/analyze-reusable.yml
  • Verified both init and analyze use the identical 4.38.1 SHA
  • git diff --check passes
  • No repository-standard lightweight YAML validator is available

dependabot Bot and others added 3 commits September 28, 2026 12:34
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.0 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@7211b7c...1c5b675)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.36.0 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@7211b7c...1c5b675)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Copilot AI lite review requested due to automatic review settings September 28, 2026 19:34
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@daxian-dbw

Copy link
Copy Markdown
Member Author

Suppressing #28054 and #28055 because both changes need to be in one PR for the CodeQL CI to pass.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@daxian-dbw
Dongbo Wang (daxian-dbw) merged commit caeff5e into master Sep 29, 2026
40 of 41 checks passed
@daxian-dbw
Dongbo Wang (daxian-dbw) deleted the daxian-dbw-combined-codeql-bump branch September 29, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backport-7.4.x-Consider Backport-7.5.x-Consider Backport-7.6.x-Consider CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants