Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Dec 2, 2025

Description

Dependabot bumped github/codeql-action from 4.31.2 to 4.31.6 (hash fe4161a26a8629af62121b670040955b330f9af2), but version tag comments remained at v3.29.5.

Updated version comments in:

  • .github/workflows/reusable_codeql.yml - codeql-action/init and codeql-action/analyze
  • .github/workflows/reusable_trivy.yml - codeql-action/upload-sarif
  • .github/workflows/scorecard.yml - codeql-action/upload-sarif

Based on #1547 but targeting main branch.

Ref: #1545

Checklist

  • Code compiles without errors locally
  • All tests pass locally
  • CI workflows execute properly
Original prompt

Dependabot bumped github/codeql-action from 4.31.2 to 4.31.6 (hash fe4161a26a8629af62121b670040955b330f9af2), but version tag comments remained at v3.29.5. This PR updates the comments to reflect the actual version.

Update the version tag comments in the following workflow files so they match the bumped version:

  • .github/workflows/reusable_codeql.yml - update version comments for codeql-action/init and codeql-action/analyze to v4.31.6
  • .github/workflows/reusable_trivy.yml - update version comment for codeql-action/upload-sarif to v4.31.6
  • .github/workflows/scorecard.yml - update version comment for codeql-action/upload-sarif to v4.31.6

This PR is based on #1547 (see: #1547) but targets the main branch instead of the dependabot branch.

Checklist:

  • Code compiles without errors locally
  • All tests pass locally
  • CI workflows execute properly

Ref: #1545

This pull request was created as a result of the following prompt from Copilot chat.

Dependabot bumped github/codeql-action from 4.31.2 to 4.31.6 (hash fe4161a26a8629af62121b670040955b330f9af2), but version tag comments remained at v3.29.5. This PR updates the comments to reflect the actual version.

Update the version tag comments in the following workflow files so they match the bumped version:

  • .github/workflows/reusable_codeql.yml - update version comments for codeql-action/init and codeql-action/analyze to v4.31.6
  • .github/workflows/reusable_trivy.yml - update version comment for codeql-action/upload-sarif to v4.31.6
  • .github/workflows/scorecard.yml - update version comment for codeql-action/upload-sarif to v4.31.6

This PR is based on #1547 (see: #1547) but targets the main branch instead of the dependabot branch.

Checklist:

  • Code compiles without errors locally
  • All tests pass locally
  • CI workflows execute properly

Ref: #1545


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Copilot AI changed the title [WIP] Update version tag comments for codeql-action Update version tag comments for codeql-action to v4.31.6 Dec 2, 2025
Copilot AI requested a review from PatKamin December 2, 2025 12:49
Copilot finished work on behalf of PatKamin December 2, 2025 12:49
@PatKamin PatKamin marked this pull request as ready for review December 2, 2025 13:09
@PatKamin PatKamin requested a review from a team as a code owner December 2, 2025 13:09
@lukaszstolarczuk lukaszstolarczuk merged commit a344252 into main Dec 2, 2025
165 checks passed
@lukaszstolarczuk lukaszstolarczuk deleted the copilot/update-codeql-action-version-comments branch December 2, 2025 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants