-
Notifications
You must be signed in to change notification settings - Fork 2
gha: bump github/codeql-action from 4.31.7 to 4.31.8 #835
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
gha: bump github/codeql-action from 4.31.7 to 4.31.8 #835
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.31.7 to 4.31.8. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cf1bb45...1b168cd) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.31.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Changed Files
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Important
Looks good to me! 👍
Reviewed everything up to d5e75ff in 47 seconds. Click for details.
- Reviewed
74lines of code in4files - Skipped
0files when reviewing. - Skipped posting
7draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. .github/workflows/codeql-analysis.yml:60
- Draft comment:
Updated 'github/codeql-action/init' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e (v4.31.8). Ensure that any custom query configurations are still compatible with the new CodeQL bundle defaults. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%The comment is asking the PR author to ensure compatibility with the new CodeQL bundle defaults, which falls under the rule of not asking the author to ensure behavior is intended or tested. It does not provide a specific suggestion or point out a specific issue.
2. .github/workflows/codeql-analysis.yml:75
- Draft comment:
Updated 'github/codeql-action/autobuild' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e (v4.31.8). This ensures the build step aligns with the updated CodeQL bundle. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, providing details about a dependency update. It does not offer any suggestions, ask for confirmation, or highlight any potential issues. According to the rules, purely informative comments should be removed.
3. .github/workflows/codeql-analysis.yml:89
- Draft comment:
Updated 'github/codeql-action/analyze' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e (v4.31.8). - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, as it only states that a specific action was updated to a certain commit. It does not provide any actionable feedback or suggestions for improvement.
4. .github/workflows/scan.yml:52
- Draft comment:
Updated 'github/codeql-action/upload-sarif' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e in the Snyk job. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, as it only states that a specific action was updated to a certain commit. It does not provide any suggestions, questions, or concerns about the code change.
5. .github/workflows/scan.yml:87
- Draft comment:
Updated 'github/codeql-action/upload-sarif' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e in the Gosec job. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, as it only states that a specific action was updated to a certain commit. It does not provide any suggestions, ask for confirmation, or highlight any potential issues.
6. .github/workflows/scorecard.yml:80
- Draft comment:
Updated 'github/codeql-action/upload-sarif' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e for uploading security scorecard results. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, as it only states that a specific action was updated to a certain commit. It doesn't provide any actionable feedback or suggestions for improvement.
7. .github/workflows/snyk.yml:43
- Draft comment:
Updated 'github/codeql-action/upload-sarif' to commit 1b168cd39490f61582a9beae412bb7057a6b2c4e in the Snyk workflow. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is purely informative, as it only states that a specific action was updated to a certain commit in a workflow. It does not provide any suggestions, ask for confirmation, or highlight any potential issues.
Workflow ID: wflow_rK78tPuyYkQ7NbN5
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
|



Bumps github/codeql-action from 4.31.7 to 4.31.8.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
1b168cdMerge pull request #3355 from github/update-v4.31.8-1b0b941e1120f277Update changelog for v4.31.81b0b941Merge pull request #3354 from github/update-bundle/codeql-bundle-v2.23.8db812c1Add changelog note2930dbaUpdate default bundle to codeql-bundle-v2.23.8c43362bMerge pull request #3340 from github/kaspersv/check-for-overlayBaseSpecifier002a7f2Overlay: log overlayBaseSpecifier at debug log-level5b7e7fcUpdate src/codeql.ts149d184Merge pull request #3345 from github/mergeback/v4.31.7-to-main-cf1bb45a97c2630RebuildDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Important
Bumps
github/codeql-actionfrom 4.31.7 to 4.31.8 across multiple GitHub Actions workflows.github/codeql-actionfrom 4.31.7 to 4.31.8 in.github/workflows/codeql-analysis.yml,.github/workflows/scan.yml,.github/workflows/scorecard.yml, and.github/workflows/snyk.yml.init,autobuild,analyze, andupload-sarifsteps incodeql-analysis.yml.upload-sarifstep inscan.yml,scorecard.yml, andsnyk.yml.This description was created by
for d5e75ff. You can customize this summary. It will automatically update as commits are pushed.