Skip to content

build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3#43

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/init-4.36.3
Closed

build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3#43
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/init-4.36.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action/init from 4.36.2 to 4.36.3.

Release notes

Sourced from github/codeql-action/init's releases.

v4.36.3

No user facing changes.

Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

4.36.0 - 22 May 2026

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893
  • Update default CodeQL bundle version to 2.25.5. #3926

4.35.5 - 15 May 2026

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880

4.35.4 - 07 May 2026

  • Update default CodeQL bundle version to 2.25.4. #3881

4.35.3 - 01 May 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #3837
  • Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #3850
  • Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853
  • Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #3852
  • Update default CodeQL bundle version to 2.25.3. #3865

4.35.2 - 15 Apr 2026

  • The undocumented TRAP cache cleanup feature that could be enabled using the CODEQL_ACTION_CLEANUP_TRAP_CACHES environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the trap-caching: false input to the init Action. #3795

... (truncated)

Commits
  • 54f647b Merge pull request #3984 from github/update-v4.36.3-1f34ec164
  • e78819e Trigger checks
  • 2c9d3d6 Update changelog for v4.36.3
  • 1f34ec1 Merge pull request #3983 from github/mbg/repo-props/ff-for-config-file-prop
  • d5f0145 Log when repository property has a value but is ignored
  • f27f563 Add test for when the FF is off
  • 0025d0f Use FF
  • f7fa18f Add FF for config file repo property
  • 628fc3f Merge pull request #3979 from github/henrymercer/overlay-db-cleanup-size-tele...
  • 9cfb67b Add clarifying comments
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@8aad20d...54f647b)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 3, 2026 07:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@clawsweeper

clawsweeper Bot commented Jul 3, 2026

Copy link
Copy Markdown

Codex review: needs changes before merge. Reviewed July 5, 2026, 3:50 AM ET / 07:50 UTC.

Summary
The branch changes .github/workflows/codeql.yml to update the CodeQL init action pin from the v4.36.2 commit to the v4.36.3 commit.

Reproducibility: yes. for the PR defect: the PR's CodeQL run downloaded different SHAs for init and analyze, then failed with the 4.36.3-versus-4.36.2 configuration error.

Review metrics: 2 noteworthy metrics.

  • CodeQL action pins: 1 of 2 updated. The workflow has paired CodeQL init/analyze steps, and updating only one creates the observed version mismatch.
  • CodeQL check result: 1 failing workflow job. The PR's own CodeQL job failed at runtime, so the automation risk is confirmed rather than speculative.

Merge readiness
Overall: 🧂 unranked krab
Proof: 🌊 off-meta tidepool
Patch quality: 🧂 unranked krab
Result: blocked by patch quality or review findings.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Rank-up moves:

  • Update the CodeQL analyze step to 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a as well.
  • Rerun or wait for the CodeQL workflow and confirm the version-mismatch error is gone.

Risk before merge

  • [P1] Merging as-is would break CodeQL analysis on main, pull requests, and scheduled runs because init writes v4.36.3 state while analyze runs v4.36.2.
  • [P1] The companion analyze-only update at build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 #45 is related but does not make this PR safe by itself; the safe path is a coordinated pin update or grouped replacement.

Maintainer options:

  1. Repair the paired CodeQL pins (recommended)
    Update the analyze step to the same v4.36.3 commit as init and rerun the CodeQL workflow before merge.
  2. Replace the split Dependabot updates
    Close the split init/analyze Dependabot PRs and recreate a single grouped CodeQL Action update if maintainers prefer bot-owned branches.
Copy recommended automerge instruction
@clawsweeper automerge

Special instructions:
Update `.github/workflows/codeql.yml` so both `github/codeql-action/init` and `github/codeql-action/analyze` use commit `54f647b7e1bb85c95cddabcd46b0c578ec92bc1a`, then verify the CodeQL job no longer fails with a 4.36.3-versus-4.36.2 configuration error.

Next step before merge

  • [P2] A repair worker can make the one-line matching SHA update to the analyze step; no maintainer product decision is needed.

Security
Needs attention: The diff touches the repository's CodeQL security scanning workflow and currently breaks that scan by mixing CodeQL Action versions.

Review findings

  • [P1] Keep CodeQL init and analyze on the same version — .github/workflows/codeql.yml:25
Review details

Best possible solution:

Land a coordinated CodeQL Action update where both init and analyze use 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a, then require the CodeQL job to pass before merge.

Do we have a high-confidence way to reproduce the issue?

Yes for the PR defect: the PR's CodeQL run downloaded different SHAs for init and analyze, then failed with the 4.36.3-versus-4.36.2 configuration error.

Is this the best way to solve the issue?

No for the current PR as submitted: updating only init is not a maintainable dependency bump because CodeQL init/analyze share versioned state. The narrow fix is to keep both action pins on the same upstream commit.

Full review comments:

  • [P1] Keep CodeQL init and analyze on the same version — .github/workflows/codeql.yml:25
    This PR updates only github/codeql-action/init to v4.36.3 while github/codeql-action/analyze remains pinned to v4.36.2. The PR's own CodeQL job fails with Loaded a configuration file for version '4.36.3', but running version '4.36.2', so update analyze to the same 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a SHA or land a grouped CodeQL update.
    Confidence: 0.99

Overall correctness: patch is incorrect
Overall confidence: 0.98

AGENTS.md: found, but no applicable review policy affected this item.

Codex review notes: model internal, reasoning high; reviewed against 009c5f5894ae.

Label changes

Label justifications:

  • P2: This is a normal-priority workflow dependency update with limited blast radius, but it currently breaks CodeQL analysis until repaired.
  • merge-risk: 🚨 automation: The diff changes GitHub Actions CodeQL pins and the PR run already fails because init and analyze use different action versions.
  • rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🌊 off-meta tidepool and patch quality is 🧂 unranked krab.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Contributor-posted real behavior proof is not required for this Dependabot bot PR; the relevant runtime validation is the GitHub Actions CodeQL job, which currently fails.
Evidence reviewed

Security concerns:

  • [medium] CodeQL scan fails with mixed action versions — .github/workflows/codeql.yml:25
    Updating init without analyze causes the CodeQL job to fail before analysis completes, which would leave this repository's CodeQL scanning workflow broken if merged unchanged.
    Confidence: 0.98

Acceptance criteria:

  • [P1] git diff --check.
  • [P1] rg -n "github/codeql-action/(init|analyze)@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a" .github/workflows/codeql.yml.
  • [P1] GitHub Actions CodeQL / analyze check passes on the repaired branch.

What I checked:

Likely related people:

  • steipete: Git blame and GitHub commit metadata show steipete authored the current CodeQL workflow lines in the v0.13.2 release-prep commit. (role: recent area contributor; confidence: high; commits: a8c08fa7ea68; files: .github/workflows/codeql.yml)
  • openclaw/openclaw-secops: .github/CODEOWNERS routes workflow changes under /.github/workflows/ to this team. (role: declared code-owner team; confidence: high; commits: a8c08fa7ea68; files: .github/CODEOWNERS, .github/workflows/codeql.yml)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.
Review history (1 earlier review cycle)
  • reviewed 2026-07-04T06:00:00.934Z sha c449a34 :: needs changes before merge. :: [P1] Keep CodeQL init and analyze on the same version

@clawsweeper clawsweeper Bot added rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. labels Jul 3, 2026
@steipete

steipete commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Superseded by #46 and landed in 06bb3ae46d2105def1a3cac3698abce70232fccc.

This PR updated only CodeQL init, while analyze stayed on the prior version; its live CodeQL job reproduced the resulting version mismatch. The Dependabot branch was not maintainer-writable (maintainerCanModify=false), so the update was recreated as one maintainer commit that updates both stages and groups future github/codeql-action/* updates.

Proof: https://github.com/openclaw/crawlkit/actions/runs/28776028506 passed on the replacement head, with both stages executing the same v4.36.3 SHA. Thanks @dependabot for surfacing the update. For future contributor PRs, enabling “Allow edits by maintainers” lets us repair coordinated changes in place; Dependabot branches do not offer that path here.

@steipete steipete closed this Jul 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action/init-4.36.3 branch July 6, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. P2 Normal priority bug or improvement with limited blast radius. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant