chore(deps): bump github/codeql-action/autobuild from 2f90a82ab7eece7aa899ce5d384db49efd7337ea to 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac#69
Conversation
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 2f90a82ab7eece7aa899ce5d384db49efd7337ea to 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@2f90a82...9cea582) --- updated-dependencies: - dependency-name: github/codeql-action/autobuild dependency-version: 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
❌ The last analysis has failed. |
| languages: rust | ||
| - name: Autobuild | ||
| uses: github/codeql-action/autobuild@2f90a82ab7eece7aa899ce5d384db49efd7337ea # v3 | ||
| uses: github/codeql-action/autobuild@9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac # v3 |
There was a problem hiding this comment.
WARNING: Only autobuild was bumped to 9cea5827... while init (line 32) and analyze (line 38) still reference 2f90a82.... Mixing different versions of the same CodeQL action bundle in a single workflow risks compatibility issues and may contribute to the SonarQube analysis failure.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
|
|
||
| - name: Autobuild | ||
| uses: github/codeql-action/autobuild@2f90a82ab7eece7aa899ce5d384db49efd7337ea # v4 | ||
| uses: github/codeql-action/autobuild@9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac # v4 |
There was a problem hiding this comment.
WARNING: Only autobuild was bumped to 9cea5827... while init (line 34) and analyze (line 42) still reference 2f90a82.... Mixing different versions of the same CodeQL action bundle in a single workflow risks compatibility issues.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Code Review SummaryStatus: 2 Warnings | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Reviewed by step-3.7-flash-20260528 · Input: 196.4K · Output: 9.8K · Cached: 128.9K |
Bumps github/codeql-action/autobuild from 2f90a82ab7eece7aa899ce5d384db49efd7337ea to 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac.
Changelog
Sourced from github/codeql-action/autobuild's changelog.
... (truncated)
Commits
9cea582Merge pull request #3977 from github/dependabot/github_actions/dot-github/wor...4d33596Merge pull request #3976 from github/dependabot/github_actions/dot-github/wor...bc9b48eMerge pull request #3975 from github/dependabot/npm_and_yarn/npm-minor-82bd63...d56b7d7Rebuilddca26a3Rebuild490a5f6Bump actions/checkout from 6.0.3 to 7.0.0 in /.github/workflows1582c0eBump the actions-minor group across 1 directory with 3 updatesd8d3457Rebuild98470abBump the npm-minor group across 1 directory with 3 updatesa16f4a4Merge pull request #3974 from github/mbg/deps/globDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Bump
github/codeql-action/autobuildto commit9cea5827Updates the pinned commit hash for
github/codeql-action/autobuildin both codeql-rust.yml and codeql.yml from2f90a82to9cea5827.Macroscope summarized fa72168.