chore(actions): bump github/codeql-action to 4.37.4 (init + analyze together) - #364
Merged
Conversation
…ogether) Dependabot raises these as two PRs (#356 analyze, #358 init) because they are two action paths, and NEITHER can go green alone: `init` and `analyze` must run from the same commit, so each half-bump fails both Analyze jobs on a version mismatch. One commit, one SHA, is the only shape that passes — the other two PRs are closed in favour of this one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Aug 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Menggantikan #356 dan #358, yang keduanya ditutup.
Dependabot menaikkan
github/codeql-action/initdan.../analyzesebagai dua PR terpisah karena keduanya path action yang berbeda. Tapi keduanya tak bisa hijau sendiri-sendiri:initdananalyzewajib berjalan dari commit yang SAMA, jadi tiap setengah-bump memerahkan kedua job Analyze dengan version mismatch — persis yang terlihat di #356 dan #358 (Analyze (actions)=fail,Analyze (javascript-typescript)=fail).Satu commit, satu SHA (
f205ea1c3313d32999d8d6a48b4f6530d4437b38), adalah satu-satunya bentuk yang lolos.Changeset
patchdisertakan:.github/workflows/*.ymltidak dikecualikan dari gerbang changeset di repo ini, dan changeset kosong ditolak.🤖 Generated with Claude Code