chore(deps): bump github/codeql-action/autobuild from 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac to 3cf0a529d8434171b6af190714e8d5b7abb83927 - #78
Conversation
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac to 3cf0a529d8434171b6af190714e8d5b7abb83927. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@9cea582...3cf0a52) --- updated-dependencies: - dependency-name: github/codeql-action/autobuild dependency-version: 3cf0a529d8434171b6af190714e8d5b7abb83927 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
❌ The last analysis has failed. |
| uses: github/codeql-action/autobuild@9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac # v3 | ||
| uses: github/codeql-action/autobuild@3cf0a529d8434171b6af190714e8d5b7abb83927 # v3 | ||
| - name: Perform CodeQL Analysis | ||
| uses: github/codeql-action/analyze@9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac # v3 |
There was a problem hiding this comment.
WARNING: Version mismatch — init and analyze remain on the old CodeQL Action commit while autobuild was bumped
The CodeQL workflow is now using a mixed set of pinned commits. init (line 32) and analyze reference 9cea5827, while autobuild was updated to 3cf0a529. This could lead to compatibility issues if the autobuild output format changed between versions.
Consider bumping init and analyze to the same commit as autobuild, or verifying that the old versions are still compatible with the new autobuild.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| uses: github/codeql-action/autobuild@3cf0a529d8434171b6af190714e8d5b7abb83927 # v4 | ||
|
|
||
| - name: Perform CodeQL Analysis | ||
| uses: github/codeql-action/analyze@9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac # v4 |
There was a problem hiding this comment.
WARNING: Version mismatch — init and analyze remain on the old CodeQL Action commit while autobuild was bumped
The CodeQL workflow is now using a mixed set of pinned commits. init (line 34) and analyze reference 9cea5827, while autobuild was updated to 3cf0a529. This could lead to compatibility issues if the autobuild output format changed between versions.
Consider bumping init and analyze to the same commit as autobuild, or verifying that the old versions are still compatible with the new autobuild.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Code Review SummaryStatus: 2 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Reviewed by step-3.7-flash-20260528 · Input: 71.5K · Output: 7K · Cached: 309.4K |
|
Superseded by #82. |
Bumps github/codeql-action/autobuild from 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac to 3cf0a529d8434171b6af190714e8d5b7abb83927.
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
3cf0a52Merge pull request #3986 from github/dependabot/npm_and_yarn/npm-minor-41f375...de65da3Merge pull request #3991 from github/mergeback/v4.36.3-to-main-54f647b7b16b719Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-41f3755806b987514Rebuilda04a87cUpdate changelog and version after v4.36.354f647bMerge pull request #3984 from github/update-v4.36.3-1f34ec164e78819eTrigger checksc1e7c7aMerge pull request #3981 from github/mario-campos/runCliJson50bd53bMerge pull request #3989 from github/dependabot/npm_and_yarn/js-yaml-5.1.0289efcaRe-addforceQuotes: trueDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Bump
github/codeql-action/autobuildto commit3cf0a529Updates the pinned commit hash for
github/codeql-action/autobuildin both codeql.yml and codeql-rust.yml.Macroscope summarized 149cf02.