chore(deps): bump github/codeql-action/analyze from 4.37.6 to 4.37.7 - #157
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump github/codeql-action/analyze from 4.37.6 to 4.37.7#157dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Coding-Dev-Tools
added a commit
that referenced
this pull request
Aug 22, 2026
- dependabot.yml: group github/codeql-action/* so init+analyze always bump in one PR; a mixed-version pair deterministically fails CodeQL's analyze post-action step (seen on open dependabot #157/#158) - .gitignore: schema-migration flock (.*.migration.lock, held live while the server runs) plus regenerable root-level diagnostic dumps (/404_paths.txt /disk_report.txt /large_files.txt /stats_pm2.txt /venv_status.txt /r3.txt)
Coding-Dev-Tools
added a commit
that referenced
this pull request
Aug 22, 2026
Mixed codeql-action versions broke the Analyze jobs ('Loaded a
configuration file for version 4.37.7, but running version 4.37.6'):
this branch bumped only the two init steps while the two analyze steps
(codeql.yml, release.yml) stayed on 4.37.6. Pin all four refs to the
same 4.37.7 SHA (ff2f1c6) so both workflows run a consistent action
version; supersedes #157.
Coding-Dev-Tools
added a commit
that referenced
this pull request
Aug 23, 2026
- dependabot.yml: group github/codeql-action/* so init+analyze always bump in one PR; a mixed-version pair deterministically fails CodeQL's analyze post-action step (seen on open dependabot #157/#158) - .gitignore: schema-migration flock (.*.migration.lock, held live while the server runs) plus regenerable root-level diagnostic dumps (/404_paths.txt /disk_report.txt /large_files.txt /stats_pm2.txt /venv_status.txt /r3.txt)
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.6 to 4.37.7. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@5595cca...ff2f1c6) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/github/codeql-action/analyze-4.37.7
branch
from
August 23, 2026 07:28
f62dc34 to
95b3e37
Compare
Contributor
Author
|
Superseded by #161. |
dependabot
Bot
deleted the
dependabot/github_actions/github/codeql-action/analyze-4.37.7
branch
August 23, 2026 07:29
Coding-Dev-Tools
added a commit
that referenced
this pull request
Aug 24, 2026
Mixed codeql-action versions broke the Analyze jobs ('Loaded a
configuration file for version 4.37.7, but running version 4.37.6'):
this branch bumped only the two init steps while the two analyze steps
(codeql.yml, release.yml) stayed on 4.37.6. Pin all four refs to the
same 4.37.7 SHA (ff2f1c6) so both workflows run a consistent action
version; supersedes #157.
Coding-Dev-Tools
added a commit
that referenced
this pull request
Aug 24, 2026
- dependabot.yml: group github/codeql-action/* so init+analyze always bump in one PR; a mixed-version pair deterministically fails CodeQL's analyze post-action step (seen on open dependabot #157/#158) - .gitignore: schema-migration flock (.*.migration.lock, held live while the server runs) plus regenerable root-level diagnostic dumps (/404_paths.txt /disk_report.txt /large_files.txt /stats_pm2.txt /venv_status.txt /r3.txt)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github/codeql-action/analyze from 4.37.6 to 4.37.7.
Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
ff2f1c6Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8951a133Update changelog for v4.37.7be7a3dbMerge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334Merge pull request #4086 from github/mbg/thread-action-state-to-codeqlb4d8a54Rebuildab5db25Bump the npm-minor group across 1 directory with 8 updates38055a3DroploggerfromdatabaseInitClusterin interface1f87aedMerge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3dc1b98aMakeloggeravailable togetCodeQLForCmd6f0220eMerge pull request #4084 from github/navntoft/bump-undici