Skip to content

Update CodeQL action versions to v4 - #81

Open
hspaans wants to merge 1 commit into
masterfrom
hspaans-patch-1
Open

hspaans wants to merge 1 commit into
masterfrom
hspaans-patch-1

Conversation

@hspaans

@hspaans hspaans commented Sep 26, 2026

Copy link
Copy Markdown
Owner

This pull request updates the GitHub Actions workflow for CodeQL analysis to use the latest major version of the CodeQL action instead of a specific patch version. This ensures the workflow benefits from the latest features and security patches without manual updates.

Workflow dependency updates:

  • .github/workflows/codeql.yml: Updated the github/codeql-action/init and github/codeql-action/analyze actions from version v4.38.0 to the latest v4 major version. [1] [2]

Copilot AI balanced review requested due to automatic review settings September 26, 2026 19:39
@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 2 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/codeql.yml

PackageVersionLicenseIssue Type
github/codeql-action/analyze4.*.*NullUnknown License
github/codeql-action/init4.*.*NullUnknown License
Allowed Licenses: GPL-2.0-or-later, LGPL-2.1-or-later, GFDL-1.1-or-later, MIT, MPL-2.0, CC-BY-4.0, CC-BY-SA-4.0, Apache-2.0
Excluded from license check: pkg:actions/dependency-review-action

OpenSSF Scorecard

PackageVersionScoreDetails
actions/github/codeql-action/analyze 4.*.* UnknownUnknown
actions/github/codeql-action/init 4.*.* UnknownUnknown

Scanned Files

  • .github/workflows/codeql.yml

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Both codeql-action references are updated consistently to the major tag, matching the repository's established convention of pinning actions to major versions.

Review effort: Balanced
Findings: None

What changed in this PR

This PR updates the CodeQL Advanced workflow to reference the CodeQL action by its major version tag (v4) instead of a pinned patch version (v4.38.0). This allows the workflow to automatically pick up patch/minor updates and security fixes to the CodeQL action without manual bumps. The change aligns codeql.yml with the rest of the repository, where all actions are pinned to major tags (e.g., actions/checkout@v7, actions/setup-python@v7, actions/dependency-review-action@v5).

Changes:

  • Updated github/codeql-action/init from v4.38.0 to v4.
  • Updated github/codeql-action/analyze from v4.38.0 to v4.
File Description
.github/​workflows/​codeql.yml Repins the two github/codeql-action steps (init, analyze) from patch version v4.38.0 to the floating v4 major tag, matching the major-tag pinning style used by other actions in the repo.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants