ci: bump github/codeql-action/analyze from 4.37.3 to 4.37.4 - #8
ci: bump github/codeql-action/analyze from 4.37.3 to 4.37.4#8dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.3 to 4.37.4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e4fba86...f205ea1) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Closes the work in Dependabot #8 and #9, which could not be merged as they stood. Dependabot raised the bump as two PRs, one for codeql-action/init and one for codeql-action/analyze. They are subpaths of a single action repository and share a commit SHA, and CodeQL requires init and analyze to run the same version. So each PR moved one step and left the other behind, and each failed on its own branch with: Loaded a configuration file for version '4.37.3', but running version '4.37.4' plus the workflow warning that not all codeql-action steps use the same version. Neither PR was individually mergeable, and merging them in sequence would have left main broken between the two merges. Doing both in one commit keeps main green throughout. e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 -> f205ea1c3313d32999d8d6a48b4f6530d4437b38, the SHA Dependabot proposed in both PRs, still pinned by SHA with the version in a trailing comment. Ruff 0.16.1 is a separate change and stays with its own PR (#7).
|
Superseded by 9887c96 on Closing rather than merging because this bump could not land as two PRs. Merging them in sequence would also have left No action needed; the version you proposed is now in place. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps github/codeql-action/analyze from 4.37.3 to 4.37.4.
Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
f205ea1Merge pull request #4053 from github/update-v4.37.4-9130ce0f7e40d079Update changelog for v4.37.49130ce0Merge pull request #4051 from github/update-bundle/codeql-bundle-v2.26.2c62d824Add changelog noteda0c190Update default bundle to codeql-bundle-v2.26.218420e3Merge pull request #4043 from github/mbg/ts/changelog7e8d897Merge pull request #4046 from github/mbg/repo-prop/code-quality2d4c474Log!analysisKindSupportedcase98c05a1Fix argument validation inrollback-changelog.ts8289a49Ignore repository property for unsupported analysis kindsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)