chore(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 - #80
chore(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9#80dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.4 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@f205ea1...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
⏱️ Benchmark (median ms, informational — not a gate)
|
Supersedes dependabot #79 and #80, which could never go green individually. `codeql-action/init` and `codeql-action/analyze` must be pinned to the same version; dependabot files them as separate PRs, so each one alone produces: ##[error]Loaded a configuration file for version '4.37.9', but running version '4.37.4' Both had sat since 2026-08-31 looking broken. Bumping the two lines together is exactly the union of the two PRs. The SHA was verified against GitHub rather than taken from the bot: the annotated tag v4.37.9 peels to cdf488f595d80d6e07e03d4674febd5ab45fa938. Backlog 3.2 records the shape, since every future codeql-action bump has it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PDo6xNNG4fJpBAPR3ha8R4
|
Looks like github/codeql-action/init is up-to-date now, so this is no longer needed. |
|
Closed by dependabot once the bump landed, but recording why this could never have gone green on its own, because the same shape will recur.
That is why this and #79 both sat from 2026-08-31 looking broken — they were only ever mergeable together. Landed as one commit ( Recorded in |
Bumps github/codeql-action/init from 4.37.4 to 4.37.9.
Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)