Skip to content

ci: bump the actions group across 1 directory with 3 updates - #57

Merged
AndresSaa merged 2 commits into
mainfrom
dependabot/github_actions/actions-29ab28765e
Aug 27, 2026
Merged

AndresSaa merged 2 commits into
mainfrom
dependabot/github_actions/actions-29ab28765e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

What changed

  • Update github/codeql-action/init, analyze, and upload-sarif from 4.37.6 to 4.37.9.
  • Keep all CodeQL entry points pinned to the same immutable commit.

Why

CodeQL 4.37.9 includes the current 2.26.4 analysis bundle. Updating the three paths together avoids a split state where CI and SARIF upload use different releases.

Tested

  • CI passed on Node 22 and 24 across Linux, macOS, and Windows.
  • The Node 26 tracking leg passed.
  • CodeQL, Socket Security, and PR title checks passed.

Contract impact

CI-only. No public API, durability contract, on-disk format, runtime dependency, performance, or package output changes.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 19, 2026
@AndresSaa

Copy link
Copy Markdown
Owner

@dependabot recreate

Bumps the actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@5595cca...db488dd)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title ci: bump the actions group with 3 updates ci: bump the actions group across 1 directory with 3 updates Aug 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-29ab28765e branch from 6b73c6c to 72f9de9 Compare August 27, 2026 10:58
@AndresSaa
AndresSaa merged commit 9324385 into main Aug 27, 2026
13 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-29ab28765e branch August 27, 2026 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant