ci(security): align CodeQL init and analyze at 4.37.6 - #474
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughCodeQL 워크플로의 ChangesCodeQL 액션 업데이트
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
The only Trivy gate failure was reproduced locally: base Hono |
Root cause
The open CodeQL upgrade lanes diverged: #425 aligned both
initandanalyzeat 4.37.5, while #471 advanced onlyinitto 4.37.6. Merging either unchanged would leave an older or split action identity.Narrow remediation
github/codeql-action/initandgithub/codeql-action/analyzeto the immutable 4.37.6 commit5595ccaf912efad79be6eef63a5619ff05969be3..github/workflows/codeql.yml.Evidence identities
develop@74a5e99d53b57aa9bc5fcfeab9a9447cf4cc2cf9f340ebbe3c99aa17c0612ee0ed45ccb4920de929bf21857f18e74ae5d6c8956ae1c2c5d0464af51bRepository-native and organization review/security gates must pass on this exact head before merge.
Summary by CodeRabbit