chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.7 - #1107
chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.7#1107dependabot[bot] wants to merge 19 commits into
Conversation
b0730d6 to
1a3e51b
Compare
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
d03fa6ebf0f877cbcbea870ec4f81a34e551ba5a. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- CodeQL PR/CodeQL compatibility analysis (actions): FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863748)
- CodeQL PR/CodeQL compatibility analysis (python): FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863632)
- CodeQL PR/CodeQL merge preview (actions): FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863678)
- CodeQL PR/CodeQL merge preview (python): FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863626)
- CodeQL compatibility analysis (actions) check run: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863748)
- CodeQL compatibility analysis (python) check run: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863632)
- CodeQL merge preview (actions) check run: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863678)
- CodeQL merge preview (python) check run: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32171546362/job/95824863626)
- Hourly NVIDIA NIM Review Repair/Hourly cadence, immutable source, NIM credential, and conflict scope: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32171543825/job/95823632068)
- Hourly cadence, immutable source, NIM credential, and conflict scope check run: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32171543825/job/95823632068)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
|
d03fa6e to
31f579a
Compare
|
Exact-current-head review request for |
|
Current-head repair on |
|
Current head is |
00dee6b to
2a98202
Compare
|
Rebased Dependabot update onto current main@c47bee59. Exact head: 2a98202. Current diff was checked for path integrity; required workflow YAML updates were actionlint-validated where applicable, and hash-lock changes retain explicit package/file digests. |
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.7. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.0...ff2f1c6) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
2a98202 to
3728920
Compare
|
@opencode-agent review exact current head |
…-action/init-4.37.7
…-action/init-4.37.7
|
@opencode-agent Please review exact current HEAD |
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
|
The failed Strix attempt was reviewed against exact head 3ef0265. The source/test step did not run: repository visibility lookup returned GitHub API HTTP 403 installation rate-limit. This is infrastructure-only evidence; the security gate was not weakened and a failed-only rerun is queued. |
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
affb6787066e83cd06f2f78574f01c364ca24e13. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32590780856/job/97074167582)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32590780856/job/97074167582)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
…-action/init-4.37.7
…-action/init-4.37.7
…-action/init-4.37.7
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
cf87c5389ad776c5f03b92226a3307bd7e759fe7. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32634912565/job/97183098656)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32634912565/job/97183098656)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
|
Superseded by clean protected-main replacement #1274. The replacement retains this PR’s official v4.37.7 commit while extending it to every central init, analyze, and upload-sarif use with a repository-wide regression contract. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github/codeql-action/init from 4.37.0 to 4.37.7.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
ff2f1c6Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8951a133Update changelog for v4.37.7be7a3dbMerge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334Merge pull request #4086 from github/mbg/thread-action-state-to-codeqlb4d8a54Rebuildab5db25Bump the npm-minor group across 1 directory with 8 updates38055a3DroploggerfromdatabaseInitClusterin interface1f87aedMerge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3dc1b98aMakeloggeravailable togetCodeQLForCmd6f0220eMerge pull request #4084 from github/navntoft/bump-undici