build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main - #174
Draft
seonghobae wants to merge 1 commit into
Draft
build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main#174seonghobae wants to merge 1 commit into
seonghobae wants to merge 1 commit into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Sep 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Reconstruct the still-valid one-line CodeQL SARIF uploader pin from #141 directly on the current protected Wardnet base without importing stale ancestry.
Protected/default
mainis exacta52ccd0a24a727d9349bb32def7713882d8cad1e. This branch was created from that exact protected head and changes only.github/workflows/scorecard-analysis.yml:github/codeql-action/upload-sarifmoves fromff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0ddto immutable commitcdf488f595d80d6e07e03d4674febd5ab45fa938(v4.37.9). The protectedubuntu-24.04runner, trigger, permissions, checkout pin, Scorecard pin, SARIF path, and behavior are unchanged.Fresh upstream release inventory still lists immutable
v4.37.9as the newest v4 action release; its annotated tag resolves to commitcdf488f595d80d6e07e03d4674febd5ab45fa938, and the release updates the default CodeQL bundle to 2.26.4.Successor / single-writer repair
#141 remains open only as predecessor evidence until this successor is proven complete. Its protected-main-relative effective delta was exactly the same one line. Do not close #141 until this exact successor reaches protected truth or otherwise demonstrates full valid-delta transfer. This PR does not copy any central
.githubreusable workflow authority and does not weaken a gate.Exact-current evidence — 2026-09-06 KST
Current exact head remains
028caa05167f9e8f2589b681a8f79c633f406c30on exact protected basea52ccd0a24a727d9349bb32def7713882d8cad1e; fresh compare is ahead 1 / behind 0 and the only changed path remains.github/workflows/scorecard-analysis.yml. Current inline review-thread inventory is empty and no review has been submitted.Wardnet-owned current-head lanes that executed are terminal GREEN:
34005444829— success;34005444805— success;34005444956— success.CodeQL PR
34005444791is terminal failure only at compatibility job101416634299. The detect-language job succeeded. The compatibility job acquired a realubuntu-24.04runner, revalidated this exact PR/head/base, obtained OIDC and a repository-scoped app token, and successfully posted acodeql-scanrepository dispatch carrying exact repository/PR/base/head/language/required-run/required-job identity. It then failed closed withVERDICT_STATE=pendingbecause no authenticated terminalcodeql-dispatch/actionsstatus had yet been published to this exact head. Fresh combined commit status still contains no such delegated terminal status.That delegated-verdict defect is advanced on canonical central owner issue
ContextualWisdomLab/.github#1929with this exact run/job payload. Do not change source, create a no-op commit, broadly rerun workflows, or promote predecessor verdicts. GREEN requires the central handler to publish an authenticated terminal verdict to this exact SHA and then wake/rerun only failed required job101416634299; any genuine scan finding or later base drift becomes a separate causal lane.Live organization ruleset
18156473also still requires one unnamed approving review while exposingOrganizationAdmin/alwaysbypass..github#772owns the solo-maintainer governance repair. This Draft is not a routine-bypass canary and must not be merged merely to probe whether the current admin principal silently traverses that bypass.Integration gate
Keep Draft until one unchanged exact head has terminal-valid repository/security/SAST/CodeQL/review/thread/governance evidence on the then-current protected base. No self/model approval, routine administrator bypass, force push, destructive rebase, stale/predecessor evidence promotion, or source churn solely to redispatch.