Skip to content

build(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 - #163

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/upload-sarif-4.37.9
Closed

build(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9#163
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/upload-sarif-4.37.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Superseded by #141 after fresh protected-base comparison.

Both candidates start from main@cc15cc2c34daf8c104eeb83d52a6a66f3cd6e128, touch only .github/workflows/scorecard-analysis.yml, and replace the same previous immutable upload-sarif SHA with upstream v4.37.9 commit cdf488f595d80d6e07e03d4674febd5ab45fa938. #141 preserves the more precise source comment (# v4.37.9) and already records the upstream tag/commit verification. #163 has no additional valid source, test, fixture, contract, or evidence delta to preserve.

No check/review evidence from this Dependabot head transfers to #141; #141 must satisfy its own unchanged-head gates before integration.

Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.7 to 4.37.9.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@ff2f1c6...cdf488f)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 3, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 3, 2026 20:12
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Sep 3, 2026
@seonghobae seonghobae closed this Sep 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action/upload-sarif-4.37.9 branch September 3, 2026 20:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant