Skip to content

build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3#45

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.36.3
Closed

build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3#45
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action/analyze-4.36.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action/analyze from 4.36.2 to 4.36.3.

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.36.3

No user facing changes.

Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

4.36.0 - 22 May 2026

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893
  • Update default CodeQL bundle version to 2.25.5. #3926

4.35.5 - 15 May 2026

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880

4.35.4 - 07 May 2026

  • Update default CodeQL bundle version to 2.25.4. #3881

4.35.3 - 01 May 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #3837
  • Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #3850
  • Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853
  • Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #3852
  • Update default CodeQL bundle version to 2.25.3. #3865

4.35.2 - 15 Apr 2026

  • The undocumented TRAP cache cleanup feature that could be enabled using the CODEQL_ACTION_CLEANUP_TRAP_CACHES environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the trap-caching: false input to the init Action. #3795

... (truncated)

Commits
  • 54f647b Merge pull request #3984 from github/update-v4.36.3-1f34ec164
  • e78819e Trigger checks
  • 2c9d3d6 Update changelog for v4.36.3
  • 1f34ec1 Merge pull request #3983 from github/mbg/repo-props/ff-for-config-file-prop
  • d5f0145 Log when repository property has a value but is ignored
  • f27f563 Add test for when the FF is off
  • 0025d0f Use FF
  • f7fa18f Add FF for config file repo property
  • 628fc3f Merge pull request #3979 from github/henrymercer/overlay-db-cleanup-size-tele...
  • 9cfb67b Add clarifying comments
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@8aad20d...54f647b)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 3, 2026 07:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@clawsweeper

clawsweeper Bot commented Jul 3, 2026

Copy link
Copy Markdown

Codex review: needs changes before merge. Reviewed July 3, 2026, 3:28 AM ET / 07:28 UTC.

Summary
Dependabot updates the CodeQL analyze workflow step from the v4.36.2 commit to the v4.36.3 commit.

Reproducibility: For the PR defect, yes. The PR's own CodeQL run reproduces the failure with the version-mismatch error after analyze is updated without init.

Review metrics: 2 noteworthy metrics.

  • Workflow pins changed: 1 changed, 1 matching pin left unchanged. CodeQL init and analyze share versioned state, so updating only one action creates the failing version mismatch.
  • CodeQL check result: 1 failing CodeQL job. The failing security-analysis workflow is direct runtime proof that the branch is not merge-ready.

Merge readiness
Overall: 🧂 unranked krab
Proof: 🌊 off-meta tidepool
Patch quality: 🧂 unranked krab
Result: blocked by patch quality or review findings.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Rank-up moves:

  • Update the CodeQL init step to 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a as well.
  • Rerun the CodeQL workflow and confirm the version-mismatch error is gone.

Risk before merge

  • [P1] Merging as-is would keep the CodeQL workflow broken on pull requests, pushes to main, and scheduled runs because init and analyze would run different CodeQL Action versions.

Maintainer options:

  1. Repair the paired CodeQL pins (recommended)
    Change the init step to the same v4.36.3 commit as analyze and rerun the CodeQL workflow before merge.
  2. Ask Dependabot to recreate a grouped update
    If maintainers prefer bot-owned dependency branches, recreate the PR after grouping the paired CodeQL init and analyze updates.
  3. Close this generated branch
    If the repository does not want a repaired Dependabot branch, close this PR and let the next grouped dependency update replace it.
Copy recommended automerge instruction
@clawsweeper automerge

Special instructions:
Update .github/workflows/codeql.yml so github/codeql-action/init and github/codeql-action/analyze both use 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a, then verify the CodeQL job no longer fails with a version mismatch.

Next step before merge

  • [P2] The blocker is a narrow mechanical repair: keep the paired CodeQL action pins on the same upstream commit.

Security
Needs attention: The branch breaks the repository's CodeQL analysis workflow by mixing CodeQL Action versions.

Review findings

  • [P1] Keep CodeQL init and analyze on the same version — .github/workflows/codeql.yml:28
Review details

Best possible solution:

Update both CodeQL init and analyze to the same v4.36.3 commit, then require the CodeQL job to pass before merge.

Do we have a high-confidence way to reproduce the issue?

For the PR defect, yes. The PR's own CodeQL run reproduces the failure with the version-mismatch error after analyze is updated without init.

Is this the best way to solve the issue?

No. Updating only analyze is not sufficient; the maintainable fix is to keep the CodeQL init and analyze action pins in lockstep.

Full review comments:

  • [P1] Keep CodeQL init and analyze on the same version — .github/workflows/codeql.yml:28
    The workflow still initializes CodeQL with v4.36.2 but now runs analyze from v4.36.3. The PR's CodeQL job fails with Loaded a configuration file for version '4.36.2', but running version '4.36.3'; update the init action to the same v4.36.3 commit as analyze.
    Confidence: 0.98

Overall correctness: patch is incorrect
Overall confidence: 0.98

AGENTS.md: found, but no applicable review policy affected this item.

Codex review notes: model internal, reasoning high; reviewed against 009c5f5894ae.

Label changes

Label changes:

  • add P2: This is a concrete workflow dependency bug with limited blast radius, but it breaks CodeQL analysis until repaired.
  • add merge-risk: 🚨 automation: The PR diff already causes the CodeQL workflow to fail because init and analyze run different action versions.
  • add rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🌊 off-meta tidepool and patch quality is 🧂 unranked krab.
  • add status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for this Dependabot bot PR; the actual GitHub Actions run is the relevant validation signal and it currently fails.

Label justifications:

  • P2: This is a concrete workflow dependency bug with limited blast radius, but it breaks CodeQL analysis until repaired.
  • merge-risk: 🚨 automation: The PR diff already causes the CodeQL workflow to fail because init and analyze run different action versions.
  • rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🌊 off-meta tidepool and patch quality is 🧂 unranked krab.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for this Dependabot bot PR; the actual GitHub Actions run is the relevant validation signal and it currently fails.
Evidence reviewed

Security concerns:

  • [medium] CodeQL scan fails after mismatched action update — .github/workflows/codeql.yml:28
    The failed CodeQL job shows init wrote v4.36.2 configuration while analyze ran v4.36.3, so security analysis would remain broken if this branch were merged as-is.
    Confidence: 0.98

Acceptance criteria:

  • [P1] Inspect .github/workflows/codeql.yml to confirm init and analyze use the same 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a commit.
  • [P1] Rerun or await the PR CodeQL workflow and confirm the analyze job no longer reports the 4.36.2 versus 4.36.3 configuration mismatch.

What I checked:

  • Current workflow uses paired CodeQL pins: Current main pins both github/codeql-action/init and github/codeql-action/analyze to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e in .github/workflows/codeql.yml. (.github/workflows/codeql.yml:25, 009c5f5894ae)
  • PR updates analyze only: The PR changes only .github/workflows/codeql.yml with 1 addition and 1 deletion, replacing the analyze action SHA while leaving init at the old SHA. (.github/workflows/codeql.yml:28, 4093c5e14b86)
  • CodeQL job failure proves the mismatch: The failing CodeQL run reports: Loaded a configuration file for version '4.36.2', but running version '4.36.3'. (.github/workflows/codeql.yml:28, 4093c5e14b86)
  • Upstream tag target is valid: The upstream v4.36.3 annotated tag points to commit 54f647b7e1bb85c95cddabcd46b0c578ec92bc1a, matching the new analyze SHA. (54f647b7e1bb)
  • Workflow provenance: The current CodeQL workflow lines blame to the v0.13.2 release preparation commit by Peter Steinberger. (.github/workflows/codeql.yml:20, a8c08fa7ea68)
  • Workflow ownership routing: CODEOWNERS routes .github/workflows/ changes to openclaw/openclaw-secops. (.github/CODEOWNERS:4, 009c5f5894ae)

Likely related people:

  • Peter Steinberger: The current CodeQL workflow lines, including both CodeQL action pins, blame to the v0.13.2 release-prep commit. (role: recent area contributor; confidence: high; commits: a8c08fa7ea68; files: .github/workflows/codeql.yml)
  • openclaw/openclaw-secops: The repository CODEOWNERS file assigns .github/workflows/ changes to this team. (role: CODEOWNERS routing owner; confidence: high; commits: a8c08fa7ea68; files: .github/CODEOWNERS, .github/workflows/codeql.yml)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@clawsweeper clawsweeper Bot added rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. labels Jul 3, 2026
@steipete

steipete commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Superseded by #46 and landed in 06bb3ae46d2105def1a3cac3698abce70232fccc.

This PR updated only CodeQL analyze, while init stayed on the prior version; its live CodeQL job reproduced the resulting version mismatch. The Dependabot branch was not maintainer-writable (maintainerCanModify=false), so the update was recreated as one maintainer commit that updates both stages and groups future github/codeql-action/* updates.

Proof: https://github.com/openclaw/crawlkit/actions/runs/28776028506 passed on the replacement head, with both stages executing the same v4.36.3 SHA. Thanks @dependabot for surfacing the update. For future contributor PRs, enabling “Allow edits by maintainers” lets us repair coordinated changes in place; Dependabot branches do not offer that path here.

@steipete steipete closed this Jul 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action/analyze-4.36.3 branch July 6, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. P2 Normal priority bug or improvement with limited blast radius. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant