build(deps): bump CodeQL SARIF uploader to 4.37.9 - #141
Conversation
|
Warning Review limit reachedNext included review available in 46 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Pull request was converted to draft
|
Protected Successor #174 was reconstructed directly from exact current protected |
Problem
Protected
mainstill pinsgithub/codeql-action/upload-sarifto the v4.37.7 release-line commitff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd. Fresh upstream release inventory on 2026-09-05 shows v4.37.9 (published 2026-08-26) remains the latest v4 release and updates the default CodeQL bundle to 2.26.4. Its immutable commit iscdf488f595d80d6e07e03d4674febd5ab45fa938.Current protected-main integration
Protected
mainadvanced through #159 to exact5829a0f08d78de464dd24393ce5d0f25fba9d126. #159 also changed.github/workflows/scorecard-analysis.ymlby pinning the hosted runner toubuntu-24.04, so blindly carrying this branch's older file would regress the now-protected workflow-pressure contract.The branch was repaired non-destructively at exact
d52222df7f9103100e63ba046cc0764c9c13d944, with prior headfea3796a723080068cdc02e064065d6d53eeb3e0and live protected main as parents. The merged tree preserves #159'subuntu-24.04, triggers, permissions, checkout pin, Scorecard pin, SARIF path and behavior while changing only the SARIF uploader commit to v4.37.9. No force push or destructive rebase was used.Fresh compare against protected main reports
behind_by=0; the effective delta is exactly one line in.github/workflows/scorecard-analysis.yml.Verification contract
github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9;ubuntu-24.04workflow foundation remains intact;All predecessor check/review results are historical after the real protected-main integration. No self/model approval, force push, routine bypass, gate weakening or predecessor-evidence reuse.
Supersedes #126 only to the extent that this exact candidate carries the complete valid uploader-version delta; do not close any predecessor unless its remaining unique delta/evidence is verified fully transferred.