chore(github-action): update action github/codeql-action (v4.37.6 → v4.37.7) - #261
Conversation
|
Renovate PR AnalysisUpdate Summary
Release Changes
Breaking ChangesNone affecting our usage. The Code Changes RequiredNone. The PR updates all 3 references in the repo, each pinned by commit SHA with the version comment retained:
Verified via Security ImpactPositive but low-risk: newer CodeQL analysis engine (bundle 2.26.3) and patched npm transitive dependencies (brace-expansion) improve the scanning toolchain itself. No effect on built container images — the action runs only in CI and does not alter image contents or the threat surface of published images. RecommendationSafe to merge — patch bump of a CI-only GitHub Action, digest-pinned, covers all references, no breaking input changes, and not in the exclusion list (not a runtime base image, not an LLM/AI SDK, not cni-plugins, not a major bump). |
This PR contains the following updates:
v4.37.6→v4.37.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
github/codeql-action (github/codeql-action)
v4.37.7Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.