chore(deps): bump github/codeql-action from 4.34.1 to 4.36.2#267
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.34.1 to 4.36.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.34.1...8aad20d) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 Walkthrough워크스루세 개의 GitHub Actions 워크플로우( 변경 사항GitHub 액션 보안 스캔 업데이트
예상 코드 리뷰 수고도🎯 2 (Simple) | ⏱️ ~10 minutes 관련 PR
추천 검토자
축하 시
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ossf-scorecard.yml:
- Line 69: Update the inline comment that documents the version for the pinned
SHA on the uses line
"github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e" so
the comment's human-readable tag matches the SHA used elsewhere (change
"v4.35.2" to "v4.36.2"); locate the comment at the end of that uses line and
replace the version string only, keeping the SHA pin and explanatory text
intact.
In @.github/workflows/trivy.yml:
- Line 41: The inline comment next to the GitHub Action SHA pin for
github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e is
stale (it says v4.35.2); update the comment so the annotated tag/version matches
the pinned commit SHA (or remove the tag annotation) to avoid misleading version
information during security reviews—look for the uses line referencing
upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e and correct the adjacent
comment text accordingly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 75b67594-5e7b-43f2-aa1c-d18e60d3d84c
📒 Files selected for processing (3)
.github/workflows/codeql.yml.github/workflows/ossf-scorecard.yml.github/workflows/trivy.yml
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/trivy.yml:
- Line 41: The workflow pins github/codeql-action/upload-sarif to a SHA that
does not match the v4.36.2 tag; update the pinned commit or clarify intent:
replace the current SHA 8aad20d150bbac5944a9f9d289da16a4b0d87c1e with the
v4.36.2 tag's commit SHA 1a818fd5f97ed0ee9a823421bd5b171add01227f so the comment
and pin align, or if you deliberately need a different commit keep the existing
SHA but change the comment to explicitly state the actual commit SHA and reason
for choosing it (referencing upload-sarif and the v4.36.2 tag).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 664a879e-2162-406f-9a47-2223e4d9c90d
📒 Files selected for processing (2)
.github/workflows/ossf-scorecard.yml.github/workflows/trivy.yml
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/ossf-scorecard.yml
|
@coderabbitai resolve |
✅ Action performedComments resolved and changes approved. |
…codeql-action-4.36.2
…codeql-action-4.36.2
|
@coderabbitai resolve |
✅ Action performedComments resolved and changes approved. |
|
@coderabbitai resolve |
✅ Action performedComments resolved and changes approved. |
|
@coderabbitai resolve |
Rate Limit Exceeded
|
…codeql-action-4.36.2
…codeql-action-4.36.2
…codeql-action-4.36.2
…codeql-action-4.36.2
…codeql-action-4.36.2
Bumps github/codeql-action from 4.34.1 to 4.36.2.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
8aad20dMerge pull request #3949 from github/update-v4.36.2-dcb947ce1f521b08Add additional changelog notes8aeff0fUpdate changelog for v4.36.2dcb947cMerge pull request #3948 from github/update-bundle/codeql-bundle-v2.25.6c251bceAdd changelog note62953c1Update default bundle to codeql-bundle-v2.25.6423b570Merge pull request #3946 from github/dependabot/npm_and_yarn/npm-minor-5d507a...c35d1b1Merge pull request #3947 from github/dependabot/github_actions/dot-github/wor...cb1a588Merge pull request #3937 from github/robertbrignull/waitForProcessing_backoffba47406Merge pull request #3943 from github/henrymercer/cache-cli-version-infoDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)