Skip to content

build(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 - #269

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.38.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.38.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action/analyze from 4.38.1 to 4.38.2.

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.38.1 to 4.38.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 3, 2026 12:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 3, 2026
@clawsweeper

clawsweeper Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Oct 3, 2026
@clawsweeper

clawsweeper Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Codex review: blocked before merge. Reviewed October 6, 2026, 3:46 PM ET / 19:46 UTC (Revision 4).

ClawSweeper review

What this changes

Updates Discrawl’s CodeQL analysis action from 4.38.1 to 4.38.2 while retaining an immutable commit pin.

Regression provenance

Possible regression — probable (reviewed change; failure trace). No predecessor PR is attributed.

Merge readiness

⛔ Blocked before merge - 3 items remain

The update remains useful, but the previously reported version mismatch is still unfixed and demonstrably breaks CodeQL analysis. Neither current main nor the latest release includes this update.

Priority: P2
Reviewed head: 0c85fb87109c6dfb249a4d1dfd2dc886cbda72c0

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The small, legitimate dependency update has a clear repair path, but its current split-version workflow fails.
Proof confidence 🌊 off-meta tidepool Not applicable: Dependabot is exempt from contributor runtime proof. The actual hosted CodeQL run nevertheless establishes the introduced failure; a successful complete run after aligning the pins remains necessary validation. No stored-data contract changes.
Patch quality 🦐 gold shrimp (3/6) 1 actionable review finding remain.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: Dependabot is exempt from contributor runtime proof. The actual hosted CodeQL run nevertheless establishes the introduced failure; a successful complete run after aligning the pins remains necessary validation. No stored-data contract changes.
Evidence reviewed 9 items Exact introduced mismatch: The pinned introduction changes only analyze to 4.38.2; init remains at 4.38.1 on line 32. Workflow permissions and triggers are unchanged.
Actual workflow failure: The analyze check for the exact PR head failed. Its annotations report: Loaded a configuration file for version '4.38.1', but running version '4.38.2'. They also explicitly warn that CodeQL steps use different versions. Run: https://github.com/openclaw/discrawl/actions/runs/37124347776/job/111206530788.
Dependency contract applies: The changed workflow directly executes this dependency. Its configuration producer records the action version, and its loader throws ConfigurationError when the recorded version differs from the running action version.
Findings 1 actionable finding [P2] Update the initialization action alongside analysis
Security None None.

How this fits together

Discrawl’s CodeQL workflow scans its Go source on pull requests, main-branch pushes, and scheduled runs. Initialization prepares the analysis configuration, which the analysis action consumes to publish security findings.

flowchart LR
  A[Repository events] --> B[Checkout Go source]
  B --> C[Initialize CodeQL]
  C --> D[Check action versions]
  D --> E[Analyze source]
  D --> F[Reject version mismatch]
  E --> G[Publish security findings]
Loading

Before merge

  • Update the initialization action alongside analysis (P2) - Initialization remains on 4.38.1 while this line runs analysis on 4.38.2. CodeQL rejects configuration recorded by a different action version, and this exact head’s hosted run fails with that error. Update init to the same 4.38.2 commit in this landing change; the open companion PR cannot make this branch independently safe.
  • Resolve merge risk (P1) - Landing the analysis-only upgrade leaves initialization on 4.38.1, causing CodeQL to reject its configuration and preventing the security scan from completing.
  • Complete next step (P2) - Pin initialization to the same 4.38.2 commit as analysis and obtain a successful complete CodeQL run before merge.

Findings

  • [P2] Update the initialization action alongside analysis — .github/workflows/codeql.yml:37
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
CodeQL version alignment 1 of 2 action pins updated Initialization and analysis must use the same action version to consume the shared configuration.

Merge-risk options

Maintainer options:

  1. Align both CodeQL pins (recommended)
    Include the initialization upgrade in this landing change so both actions use 4.38.2 and the complete workflow succeeds.
Copy recommended automerge instruction
@clawsweeper automerge

Special instructions:
Pin github/codeql-action/init and github/codeql-action/analyze in .github/workflows/codeql.yml to 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 with v4.38.2 comments, preserve permissions and triggers, and require a successful complete CodeQL run.

Technical review

Best possible solution:

Upgrade initialization and analysis atomically to the same verified 4.38.2 commit, preserving workflow permissions and obtaining a successful complete security scan.

Do we have a high-confidence way to reproduce the issue?

Yes: the exact PR head’s hosted workflow records the version-mismatch failure, and the dependency source explains the rejection. No local execution was needed.

Is this the best way to solve the issue?

No: upgrading only analysis violates CodeQL’s shared configuration contract; updating both immutable pins together is the narrow repair.

Full review comments:

  • [P2] Update the initialization action alongside analysis — .github/workflows/codeql.yml:37
    Initialization remains on 4.38.1 while this line runs analysis on 4.38.2. CodeQL rejects configuration recorded by a different action version, and this exact head’s hosted run fails with that error. Update init to the same 4.38.2 commit in this landing change; the open companion PR cannot make this branch independently safe.
    Confidence: 1

Overall correctness: patch is incorrect
Overall confidence: 0.99

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 76618b71c379.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a bounded dependency update with a demonstrated security-scanning workflow defect and no runtime user regression.
  • merge-risk: 🚨 automation: The introduced split between CodeQL action versions causes the actual analysis workflow to fail.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🦐 gold shrimp.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Dependabot is exempt from contributor runtime proof. The actual hosted CodeQL run nevertheless establishes the introduced failure; a successful complete run after aligning the pins remains necessary validation. No stored-data contract changes.

Evidence

Acceptance criteria:

  • [P1] git diff --check.
  • [P1] git diff -- .github/workflows/codeql.yml.
  • [P1] gh pr checks 269 --repo openclaw/discrawl.
  • [P1] gh run view --repo openclaw/discrawl --log.

What I checked:

Likely related people:

  • unknown: The claimed source-line change could not be verified from bounded local history. (role: source history unknown; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Align init and analyze at 4.38.2 and obtain a successful complete CodeQL run.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (3 earlier review cycles)
  • reviewed 2026-10-03T12:56:11.506Z sha 0c85fb8 :: blocked before merge. :: [P2] Update the initialization action alongside analysis
  • reviewed 2026-10-04T00:45:42.221Z sha 0c85fb8 :: blocked before merge. :: [P2] Update the initialization action alongside analysis
  • reviewed 2026-10-06T03:35:04.143Z sha 0c85fb8 :: blocked before merge. :: [P2] Update the initialization action alongside analysis

@steipete

steipete commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Incorporated into #272, now merged. CodeQL initialization and analysis were updated together to v4.38.2 so their configuration versions match; the same PR includes TruffleHog v3.97.9 and groups future CodeQL updates. The combined head passed CodeQL, secret scans, full CI, and the remote make check gate (86.0% coverage). Thanks for the update.

Closing this separate update as superseded by the verified combined change.

@steipete steipete closed this Oct 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action/analyze-4.38.2 branch October 7, 2026 07:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant