Skip to content

build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main - #174

Draft
seonghobae wants to merge 1 commit into
mainfrom
build/codeql-upload-sarif-4.37.9-main
Draft

build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main#174
seonghobae wants to merge 1 commit into
mainfrom
build/codeql-upload-sarif-4.37.9-main

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Purpose

Reconstruct the still-valid one-line CodeQL SARIF uploader pin from #141 directly on the current protected Wardnet base without importing stale ancestry.

Protected/default main is exact a52ccd0a24a727d9349bb32def7713882d8cad1e. This branch was created from that exact protected head and changes only .github/workflows/scorecard-analysis.yml: github/codeql-action/upload-sarif moves from ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd to immutable commit cdf488f595d80d6e07e03d4674febd5ab45fa938 (v4.37.9). The protected ubuntu-24.04 runner, trigger, permissions, checkout pin, Scorecard pin, SARIF path, and behavior are unchanged.

Fresh upstream release inventory still lists immutable v4.37.9 as the newest v4 action release; its annotated tag resolves to commit cdf488f595d80d6e07e03d4674febd5ab45fa938, and the release updates the default CodeQL bundle to 2.26.4.

Successor / single-writer repair

#141 remains open only as predecessor evidence until this successor is proven complete. Its protected-main-relative effective delta was exactly the same one line. Do not close #141 until this exact successor reaches protected truth or otherwise demonstrates full valid-delta transfer. This PR does not copy any central .github reusable workflow authority and does not weaken a gate.

Exact-current evidence — 2026-09-06 KST

Current exact head remains 028caa05167f9e8f2589b681a8f79c633f406c30 on exact protected base a52ccd0a24a727d9349bb32def7713882d8cad1e; fresh compare is ahead 1 / behind 0 and the only changed path remains .github/workflows/scorecard-analysis.yml. Current inline review-thread inventory is empty and no review has been submitted.

Wardnet-owned current-head lanes that executed are terminal GREEN:

  • CI 34005444829 — success;
  • Security Scan 34005444805 — success;
  • SAST Semgrep 34005444956 — success.

CodeQL PR 34005444791 is terminal failure only at compatibility job 101416634299. The detect-language job succeeded. The compatibility job acquired a real ubuntu-24.04 runner, revalidated this exact PR/head/base, obtained OIDC and a repository-scoped app token, and successfully posted a codeql-scan repository dispatch carrying exact repository/PR/base/head/language/required-run/required-job identity. It then failed closed with VERDICT_STATE=pending because no authenticated terminal codeql-dispatch/actions status had yet been published to this exact head. Fresh combined commit status still contains no such delegated terminal status.

That delegated-verdict defect is advanced on canonical central owner issue ContextualWisdomLab/.github#1929 with this exact run/job payload. Do not change source, create a no-op commit, broadly rerun workflows, or promote predecessor verdicts. GREEN requires the central handler to publish an authenticated terminal verdict to this exact SHA and then wake/rerun only failed required job 101416634299; any genuine scan finding or later base drift becomes a separate causal lane.

Live organization ruleset 18156473 also still requires one unnamed approving review while exposing OrganizationAdmin/always bypass. .github#772 owns the solo-maintainer governance repair. This Draft is not a routine-bypass canary and must not be merged merely to probe whether the current admin principal silently traverses that bypass.

Integration gate

Keep Draft until one unchanged exact head has terminal-valid repository/security/SAST/CodeQL/review/thread/governance evidence on the then-current protected base. No self/model approval, routine administrator bypass, force push, destructive rebase, stale/predecessor evidence promotion, or source churn solely to redispatch.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant