Skip to content

Upgrade CodeQL to V4: Fix 10 CodeQL Analysis Warnings and Errors#3770

Merged
gladjohn merged 2 commits intomasterfrom
reyap/codeql
Apr 6, 2026
Merged

Upgrade CodeQL to V4: Fix 10 CodeQL Analysis Warnings and Errors#3770
gladjohn merged 2 commits intomasterfrom
reyap/codeql

Conversation

@reginayap8
Copy link
Copy Markdown
Contributor

@reginayap8 reginayap8 commented Apr 3, 2026

Upgrade Pipeline Job Init@V4 to Fix 10 CodeQL Warnings and Errors in CodeQL Analysis

  • You've read the Contributor Guide and Code of Conduct.
  • You've included unit or integration tests for your change, where applicable.
  • You've included inline docs for your change, where applicable.
  • There's an open issue for the PR that you are making. If you'd like to propose a new feature or change, please open an issue to discuss the change or find an existing issue.

Summary of the changes (Less than 80 chars)

Description

Fix 10 CodeQL warnings in the pipeline analysis by setting the Github API permissions.

Solution: Add the following permissions in yaml file since they were missing and causing the pipeline check to fail.

  • Upgrade CodeQL pipeline step from V3 to V4
  • security-events: write — lets the action upload SARIF results and fetch feature flags from GitHub's API, which resolves the fallback warning.
  • actions: read — allows the action to read its own feature flag configuration.
  • contents: read — explicitly grants repo content access (best practice when listing multiple permissions).

Pipeline link to warnings
Link: https://github.com/AzureAD/microsoft-identity-web/actions/runs/23922732183

image

Fixes #{bug number} (in this specific format)

reginayap8 and others added 2 commits April 3, 2026 11:26
- Upgrade codeql-action/init and codeql-action/analyze from v3 to v4
  to resolve Node.js 20 deprecation warning
- Update permissions: security-events to write, add actions: read
  and contents: read to resolve feature flags CLI version warning
- Update commented autobuild reference from v2 to v4 for consistency

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@reginayap8 reginayap8 requested a review from a team as a code owner April 3, 2026 18:59
@reginayap8 reginayap8 changed the title Fix 10 CodeQL Analysis Warnings and Errors Upgrade CodeQL to V4: Fix 10 CodeQL Analysis Warnings and Errors Apr 3, 2026
@gladjohn gladjohn merged commit 83e7934 into master Apr 6, 2026
4 checks passed
@gladjohn gladjohn deleted the reyap/codeql branch April 6, 2026 18:10
This was referenced Apr 20, 2026
github-actions Bot pushed a commit to EelcoLos/nx-tinkering that referenced this pull request Apr 21, 2026
Pinned
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
at 4.8.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.8.0

## What's Changed
* Bump flatted from 3.3.3 to 3.4.2 in
/tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in
AzureAD/microsoft-identity-web#3753
* Update changelog.md for ID.Web 4.6.0 by @​bgavrilMS in
AzureAD/microsoft-identity-web#3756
* Add token binding to MicrosoftIdentityMessageHandler by @​cpp11nullptr
in AzureAD/microsoft-identity-web#3743
* Bump picomatch in /tests/DevApps/SidecarAdapter/typescript by
@​dependabot[bot] in
AzureAD/microsoft-identity-web#3759
* Documentation: Clarify managed identity credential types for
containerized vs. VM/App Service deployments by @​Copilot in
AzureAD/microsoft-identity-web#3585
* Bump path-to-regexp from 8.3.0 to 8.4.0 in
/tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in
AzureAD/microsoft-identity-web#3762
* Upgrade Microsoft Application Insights packages by @​RojaEnnam in
AzureAD/microsoft-identity-web#3763
* Use Abstractions 12 by @​pmaytak in
AzureAD/microsoft-identity-web#3761
* Post-4.7.0 by @​pmaytak in
AzureAD/microsoft-identity-web#3768
* Fix Comp Gov DOTNET-Security-10.0 by @​reginayap8 in
AzureAD/microsoft-identity-web#3769
* Upgrade CodeQL to V4: Fix 10 CodeQL Analysis Warnings and Errors by
@​reginayap8 in
AzureAD/microsoft-identity-web#3770
* fix warnings by @​gladjohn in
AzureAD/microsoft-identity-web#3771
* adding examples for using postgres as a distributed cache by
@​JaredMSFT in
AzureAD/microsoft-identity-web#3766
* Suppress AOT configuration-binding SYSLIB warnings in AotCompatibility
test app by @​Copilot in
AzureAD/microsoft-identity-web#3774
* Bump vite from 7.1.11 to 7.3.2 in
/tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in
AzureAD/microsoft-identity-web#3772
* Skip legacy B2C local-account Todo UI test in WebAppUiTests by
@​Copilot in AzureAD/microsoft-identity-web#3778
* Fix initialization of ConfidentialClientApplicationOptions in
MergedOptions by @​cpp11nullptr in
AzureAD/microsoft-identity-web#3760
* Bump net8/net9/net10 runtime package baselines to patched crypto
servicing versions by @​Copilot in
AzureAD/microsoft-identity-web#3779
* Fix flaky certificate test failures on CI by @​gladjohn in
AzureAD/microsoft-identity-web#3780
* MTLS Without Tokens Support by @​tlupes in
AzureAD/microsoft-identity-web#3747
* Fix CredentialsProvider DI lifetime mismatch causing startup crash in
Development by @​Avery-Dunn in
AzureAD/microsoft-identity-web#3783
* Remove unused DataProtection configuration from Sidecar by @​Copilot
in AzureAD/microsoft-identity-web#3776

## New Contributors
* @​RojaEnnam made their first contribution in
AzureAD/microsoft-identity-web#3763
* @​reginayap8 made their first contribution in
AzureAD/microsoft-identity-web#3769
* @​JaredMSFT made their first contribution in
AzureAD/microsoft-identity-web#3766

**Full Changelog**:
AzureAD/microsoft-identity-web@4.6.0...4.8.0

Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.7.0...4.8.0).
</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants