build(deps): bump github/codeql-action from 4.38.1 to 4.38.2 - #289
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThe CodeQL workflow updates every init and analyze step from github/codeql-action v4.38.1 to the pinned v4.38.2 revision, keeping paired steps and both language jobs on a consistent action version to avoid workflow validation failures. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Combines the init and analyze bumps into a single change.
Every
github/codeql-actionstep in a workflow must use the same version, so the individual dependabot PRs fail CodeQL on their own (init@4.38.2 with analyze@4.38.1 errors with "Not all workflow steps that usegithub/codeql-actionactions use the same version").Supersedes #287 and #284. The upload-sarif bump (#281) lives in a separate workflow and merges independently.
Summary by Sourcery
CI: