Repository navigation
chore(deps): bump the codeql-actions group with 2 updates - #6011
Conversation
Bumps the codeql-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.9 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdf488f...b96794f) Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdf488f...b96794f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: codeql-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: codeql-actions ... Signed-off-by: dependabot[bot] <support@github.com>
sunchao
left a comment
There was a problem hiding this comment.
Correctness
Reviewed 467c830b against f51f5831. This updates both CodeQL steps in .github/workflows/codeql.yml from 4.37.9 (cdf488f5) to 4.38.0 (b96794f0). Official release tags resolve to those exact commits. The full diff changes only those two pins, keeping initialization and analysis on the same release.
Both releases use Node 24. The existing languages: actions, analysis category, triggers and permissions remain compatible. The new internal job-status input has a runtime-provided default, and the analyze action's interface is unchanged. The release notes identify bundle 2.27.0, Linux Arm64 support and feature-gated toolcache cleanup. The cleanup checks for a GitHub-hosted runner, a shared filesystem and no earlier CodeQL setup. This workflow uses one initialization on a disposable x64 runner.
The CodeQL job checked out merge 8124ecbd, whose parents are the reviewed base and head and whose tree equals the head. Its log confirms the new action SHA, runner 2.337.0, Ubuntu 24.04 x64, CLI 2.27.0, extraction of the changed workflow, completion of all 18 queries and successful results upload. Local CI configuration and diff checks pass. The current 40 checks comprise 10 successes and 30 skips. The skipped product jobs are not runtime evidence. No Spark expression/operator implementation changes are present, so no Spark semantic or native execution claim is made. No P1/P2 finding.
Performance
The changes affect security-analysis setup, not query execution. The upstream cleanup can reduce unused bundle storage when its rollout flag enables it. The existing job still uses one analysis and one bundle setup. The successful run supports compatibility with the current runner budget, but it does not establish a performance improvement. A product microbenchmark would not test this change.
Design
Updating the paired steps together preserves their shared database and upload lifecycle. The existing codeql-actions Dependabot group already covers both callers. Full commit pins retain reproducible action selection while the official release supplies the CLI update. No new permissions, build toolchain or workflow branch is needed.
Abstraction & complexity
The implementation is two direct reference replacements and adds no local wrapper or configuration layer. The existing language and category keep the security scan scoped to GitHub Actions. I found no additional change needed before merge.
Bumps the codeql-actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze.
Updates
github/codeql-action/initfrom 4.37.9 to 4.38.0Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
b96794fMerge pull request #4131 from github/update-v4.38.0-7e08580a902d5093Update changelog for v4.38.07e08580Merge pull request #4130 from github/henrymercer/workflow-runner-sizingbfcc52bRun slow macOS checks on larger runners8c251e7Merge pull request #4129 from github/update-bundle/codeql-bundle-v2.27.00b7ca40Add changelog note40484b3Update default bundle to codeql-bundle-v2.27.0977e6ceMerge pull request #4124 from github/henrymercer/toolcache-bundle-cleanup40a6b38Address toolcache cleanup review feedbackdeece8fApply suggestion from@henrymercerUpdates
github/codeql-action/analyzefrom 4.37.9 to 4.38.0Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
b96794fMerge pull request #4131 from github/update-v4.38.0-7e08580a902d5093Update changelog for v4.38.07e08580Merge pull request #4130 from github/henrymercer/workflow-runner-sizingbfcc52bRun slow macOS checks on larger runners8c251e7Merge pull request #4129 from github/update-bundle/codeql-bundle-v2.27.00b7ca40Add changelog note40484b3Update default bundle to codeql-bundle-v2.27.0977e6ceMerge pull request #4124 from github/henrymercer/toolcache-bundle-cleanup40a6b38Address toolcache cleanup review feedbackdeece8fApply suggestion from@henrymercerDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions