Skip to content

chore(deps): update github/codeql-action digest to 2892aa5 - #221

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action (changelog) action digest 5595cca → 2892aa5

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.13%. Comparing base (e347388) to head (189920c).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #221   +/-   ##
=======================================
  Coverage   94.13%   94.13%           
=======================================
  Files          10       10           
  Lines         290      290           
  Branches      105      105           
=======================================
  Hits          273      273           
  Misses          1        1           
  Partials       16       16           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest, but the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). Skipping auto-merge — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep: skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (any change to .github/workflows/** is flagged for human approval). The change itself is a digest bump on github/codeql-action and CI is green, but policy requires a human review for workflow-file edits. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), which is out of scope for autopilot auto-merge regardless of CI state or labels. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if the change is wanted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Even though checks are green and the change is only a digest bump of github/codeql-action, my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to ff2f1c6 chore(deps): update github/codeql-action digest to db488dd Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 43cd070 to 7f63b36 Compare August 21, 2026 14:43
@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which is in the excluded paths for auto-merge. Skipping auto-merge; please review and merge manually if appropriate.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7f63b36 to e9a3057 Compare August 22, 2026 00:03

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (5595cca → db488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review — hard exclusion in scope.

PR #221 modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action). Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.

CI is green and the change is a routine CodeQL action digest update; human reviewer can merge after confirming the new digest matches an upstream release. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagged by DevSecOps autopilot: hard exclusion — touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope. Please review manually and merge when satisfied.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from e9a3057 to 7e75162 Compare August 26, 2026 00:05
@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to db488dd chore(deps): update github/codeql-action digest to cdf488f Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7e75162 to 5cff28d Compare August 26, 2026 16:09

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security (permissions, secrets, supply-chain). Not auto-merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Flagged for human approval — not auto-merged.

Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest 5595cca → cdf488f (scorecard workflow).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. Acceptable, but the autopilot does not auto-merge workflow changes per policy.

Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily Renovate sweep — flagged for human review.

This PR modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action), which falls under the hard-excluded CI/CD workflow paths. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.

No auto-merge performed. Please review the workflow edit and merge manually if approved.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 5cff28d to d2d111b Compare September 1, 2026 00:02

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot flagged this PR for human approval.

Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.

What this PR does: Updates the github/codeql-action digest from 5595cca → cdf488f (action digest bump).

CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change itself is a CodeQL action digest bump (5595cca → cdf488f) and looks safe, but workflow changes always need a human to confirm there's no permissions/secrets expansion. Please review and merge if you're comfortable. — tldr: green CI but excluded from auto-merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green. The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review. Please review and merge if you're comfortable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion for automated merge: workflow files execute with repository credentials, so an action digest bump there needs a human to confirm the new digest maps to the intended upstream tag. CI is fully green — this is a policy hold, not a quality problem. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged by the daily Renovate sweep). CI is fully green (CodeQL + Lint/Test/Build/Security + E2E + codecov), so the diff itself looks safe — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a digest bump of github/codeql-action (5595cca → cdf488f). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.

This PR updates github/codeql-action digest in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge. Not approving. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to cdf488f chore(deps): update github/codeql-action digest to b96794f Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from d2d111b to 7345b0b Compare September 9, 2026 23:13
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 82ee1cab-9c29-4058-a947-013247cb8af5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awaiting human approval. This PR modifies .github/workflows/scorecard.yml, which falls under the DevSecOps autopilot's hard exclusion for workflow-file changes. In addition, CI is currently failing (Lint, Test, Build & Security reported failure on 2026-09-09). The digest bump to github/codeql-action b96794f should be reviewed by a maintainer with workflow-edit authority. (DevSecOps daily sweep)

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagging for human approval (devsecops sweep, 2026-09-11).

This PR updates the GitHub CodeQL Action digest, but the diff touches .github/workflows/scorecard.yml. The daily sweep's hard-exclusion policy auto-skips any PR that modifies .github/workflows/** or .github/actions/**, even when the change is a trusted-action version bump.

Also: Lint, Test, Build & Security is FAILURE on the latest run.

Please review and merge manually when ready.

@timoa

timoa commented Sep 12, 2026

Copy link
Copy Markdown
Owner

Renovate sweep (TIM-298): flagged skipped-blocked.

  • Touches .github/workflows/scorecard.yml — hard exclusion (workflow file changes require explicit human review).
  • Lint, Test, Build & Security check failed on this PR.
  • No security/patch label is present on this PR.

Action: human approval required. Please triage the lint failure and confirm the scorecard workflow change is intended before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion under the DevSecOps daily Renovate sweep policy — any PR that touches GitHub Actions workflows requires human review, regardless of label. Additionally, Lint, Test, Build & Security and CodeQL-Build are FAILURE on the latest run. Please review the workflow diff (digest bump only, no permission/secrets changes) and merge manually once the CI failure is investigated.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awaiting human review: this PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which is on the hard-exclusion list for this autopilot. Workflow files change CI surface and can affect supply-chain gates, so I will not auto-merge. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep: this PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which falls under the hard exclusion rule for CI workflow files. Per the autopilot policy, such PRs are flagged for human approval rather than auto-merged, regardless of CI state. Please review and merge manually when satisfied.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps sweep: skipped auto-merge. Hard exclusion — diff touches .github/workflows/scorecard.yml. Needs human review for action-digest bump before merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep — DevSecOps autopilot (TIM-353).

Hard exclusion: this PR modifies .github/workflows/scorecard.yml. Per the sweep policy, workflow-file changes require human approval and are never auto-merged. No labels present, so no risk-tier classification could be applied.

Action: awaiting-human. Please review and merge manually if appropriate.

---🤖 Generated by Renovate sweep autopilot at 2026-09-18T00:00:00Z

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to b96794f chore(deps): update github/codeql-action digest to 1c5b675 Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7345b0b to 19e6cde Compare September 18, 2026 21:40
@timoa

timoa commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Renovate daily sweep (TIM-356). Skipped: required checks CodeQL-Build and Lint, Test, Build & Security are FAILING. PR also touches .github/workflows/scorecard.yml (hard exclusion — no auto-merge either way). codeql-action digest bump only; please review the CodeQL job logs.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep: skipping. PR modifies .github/workflows/scorecard.yml (codeql-action digest bump). Hard exclusion — workflow-touching changes require human approval per DevSecOps policy. CI also shows Lint, Test, Build & Security FAILURE on 2026-09-18. Asking for a human to review and merge manually if desired.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps sweep (TIM-360): auto-merge skipped. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (.github/workflows/**). Also CI: Lint, Test, Build & Security FAILURE. Required: human review and approval.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate autopilot: hard exclusion triggered. Diff touches .github/workflows/scorecard.yml (github/codeql-action digest bump). Per DevSecOps policy, any PR modifying .github/workflows/** is never auto-merged. Requesting human review and approval before merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate digest bump of github/codeql-action modifies . Hard exclusion: workflow-file changes require human review and are not eligible for auto-merge. Also, the Lint, Test, Build & Security check is currently failing. Please triage and merge manually once approved.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate digest bump of github/codeql-action modifies .github/workflows/scorecard.yml. Hard exclusion: workflow-file changes require human review and are not eligible for auto-merge. Also, the Lint, Test, Build & Security check is currently failing. Please triage and merge manually once approved.

@timoa

timoa commented Sep 24, 2026

Copy link
Copy Markdown
Owner

DevSecOps daily sweep (2026-09-24): touches .github/workflows/scorecard.yml (hard exclusion) and Lint, Test, Build & Security FAILURE. Skipping. Needs human review of workflow diff.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to 1c5b675 chore(deps): update github/codeql-action digest to 2892aa5 Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 19e6cde to 189920c Compare September 24, 2026 23:05

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this PR as awaiting-human review.

Reason: PR touches .github/workflows/** (hard exclusion list). Renovate bumps to GitHub Actions or third-party action versions can change supply-chain trust boundaries (digest pinning, action permissions, with: credentials). Human approval required before merge.

No auto-merge. No approve from autopilot.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hard exclusion: this PR touches .github/workflows/scorecard.yml (CI/workflow config). Per the DevSecOps guard in TIM-376, PRs that modify .github/workflows/** are never auto-merged. Needs human review/approval before merge.

Diff summary: bumps github/codeql-action digest (5595cca → 2892aa5) in scorecard.yml only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant