fix(deps): Bump github/codeql-action/analyze from 4.36.3 to 4.37.3 - #28
fix(deps): Bump github/codeql-action/analyze from 4.36.3 to 4.37.3#28dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.36.3 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@54f647b...e4fba86) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
@codereviewai full review. |
Supersedes the two dependabot PRs that split this pair — #25 (init -> 4.37.4) and #28 (analyze -> 4.37.3). Each was red on its own, and neither was wrong: analyze reads the version-stamped config that init writes and refuses a mismatch, so bumping one half fails with Loaded a configuration file for version '4.37.4', but running version '4.36.3' Both pins now move together to v4.37.5, the newest release, which also carries the init fix for a bundle-download network error terminating the step instead of falling back. .github/dependabot.yml grows a `codeql-action` group over `github/codeql-action*` so the next bump arrives as one PR instead of splitting into a broken pair again. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Supersedes the two dependabot PRs that split this pair — #25 (init -> 4.37.4) and #28 (analyze -> 4.37.3). Each was red on its own, and neither was wrong: analyze reads the version-stamped config that init writes and refuses a mismatch, so bumping one half fails with Loaded a configuration file for version '4.37.4', but running version '4.36.3' Both pins now move together to v4.37.5, the newest release, which also carries the init fix for a bundle-download network error terminating the step instead of falling back. .github/dependabot.yml grows a `codeql-action` group over `github/codeql-action*` so the next bump arrives as one PR instead of splitting into a broken pair again. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Superseded by #25, which landed on master as Dependabot sees That is why this PR and #25 were each red on their own while neither was wrong. #25 now moves both pins together to
|
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps github/codeql-action/analyze from 4.36.3 to 4.37.3.
Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
e4fba86Merge pull request #4031 from github/update-v4.37.3-72f6a9da0fb50ab5Update changelog for v4.37.372f6a9dMerge pull request #4030 from github/mbg/fix/no-proxy3b5ee58Use defaultrequestoptions instead ofundefinedbfb6be4Merge pull request #4028 from github/mergeback/v4.37.2-to-main-e0647621526ab84Rebuildd6217b9Update changelog and version after v4.37.2e064762Merge pull request #4027 from github/update-v4.37.2-385bcdc5ae0faed8Add a couple of change notes73aad0eUpdate changelog for v4.37.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)