Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
persist-credentials: false

- name: Initialize CodeQL
uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v4.37.1
uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- workflow ---'
cat -n .github/workflows/codeql.yml

printf '%s\n' '--- CodeQL action references ---'
rg -n 'uses:\s*github/codeql-action/' .github/workflows/codeql.yml

printf '%s\n' '--- repository metadata ---'
git remote -v || true

printf '%s\n' '--- tag and commit resolution ---'
python3 - <<'PY'
import json, urllib.request

repo = "github/codeql-action"
for tag in ("v2.37.3", "v4.37.3", "v4.37.1"):
    ref_url = f"https://api.github.com/repos/{repo}/git/ref/tags/{tag}"
    try:
        with urllib.request.urlopen(ref_url) as r:
            ref = json.load(r)
        obj = ref["object"]
        print(tag, "ref_object", obj)
        sha = obj["sha"]
        if obj["type"] == "tag":
            with urllib.request.urlopen(
                f"https://api.github.com/repos/{repo}/git/tags/{sha}"
            ) as r:
                tag_obj = json.load(r)
            print(tag, "dereferenced", tag_obj.get("object"))
            sha = tag_obj["object"]["sha"]
        with urllib.request.urlopen(
            f"https://api.github.com/repos/{repo}/commits/{sha}"
        ) as r:
            commit = json.load(r)
        print(tag, "commit", commit.get("sha"))
    except Exception as e:
        print(tag, "ERROR", e)

for sha in (
    "e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81",
    "7188fc363630916deb702c7fdcf4e481b751f97a",
):
    try:
        with urllib.request.urlopen(
            f"https://api.github.com/repos/{repo}/commits/{sha}"
        ) as r:
            commit = json.load(r)
        print("pin", sha, "resolves_to", commit.get("sha"))
    except Exception as e:
        print("pin", sha, "ERROR", e)
PY

Repository: Xquik-dev/x-twitter-scraper-ruby

Length of output: 2526


🏁 Script executed:

#!/bin/bash
set -eu

api() {
  curl --fail --silent --show-error --location --insecure \
    -H 'Accept: application/vnd.github+json' \
    -H 'X-GitHub-Api-Version: 2022-11-28' "$1"
}

repo='github/codeql-action'

for tag in v4.37.3 v4.37.1; do
  printf '%s\n' "--- $tag ref ---"
  ref="$(api "https://api.github.com/repos/$repo/git/ref/tags/$tag")"
  printf '%s\n' "$ref" | jq '{ref, object}'
  type="$(printf '%s\n' "$ref" | jq -r '.object.type')"
  sha="$(printf '%s\n' "$ref" | jq -r '.object.sha')"
  if [ "$type" = tag ]; then
    printf '%s\n' "--- $tag annotated tag object ---"
    tag_obj="$(api "https://api.github.com/repos/$repo/git/tags/$sha")"
    printf '%s\n' "$tag_obj" | jq '{sha: .sha, object}'
    sha="$(printf '%s\n' "$tag_obj" | jq -r '.object.sha')"
  fi
  printf '%s\n' "--- $tag commit validation ---"
  api "https://api.github.com/repos/$repo/commits/$sha" | jq '{sha, commit: {message: .commit.message}}'
done

for sha in \
  e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 \
  7188fc363630916deb702c7fdcf4e481b751f97a
do
  printf '%s\n' "--- pin $sha ---"
  api "https://api.github.com/repos/$repo/commits/$sha" | jq '{sha, commit: {message: .commit.message}}'
done

Repository: Xquik-dev/x-twitter-scraper-ruby

Length of output: 292


🌐 Web query:

github/codeql-action v4.37.3 e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81

💡 Result:

The identifier e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 is the full Git commit SHA for version v4.37.3 of the github/codeql-action repository [1][2]. This version was released on July 22, 2026 [3][4]. According to the official changelog, this release contained no user-facing changes [3][2]. The commit was associated with pull request #4031 in the github/codeql-action repository [1]. Users typically reference this commit SHA in their GitHub Actions workflow files to pin the action to a specific, immutable version, as shown in the following example syntax [5][6][7]: uses: github/codeql-action@e4fba86 By pinning to a specific SHA rather than a major version tag (like v4), users ensure that their workflow behavior remains consistent and is not affected by subsequent updates or changes within that version branch [8].

Citations:


🌐 Web query:

github/codeql-action v4.37.1 7188fc363630916deb702c7fdcf4e481b751f97a

💡 Result:

The hash 7188fc363630916deb702c7fdcf4e481b751f97a corresponds to the merge commit for version 4.37.1 of the GitHub CodeQL Action, which was released on July 16, 2026 [1][2]. Key details of this release include: - Default CodeQL Bundle Update: The default CodeQL bundle version was updated to 2.26.1 [1][3]. - Deprecation Warning: This release introduced a deprecation warning for users of CodeQL versions 2.20.6 and earlier [1][4]. These specific versions were discontinued on July 1, 2026, alongside GitHub Enterprise Server 3.16, and they will lose support in the next minor release of the CodeQL Action [5][3]. The CodeQL Action is maintained by GitHub and is used to run CodeQL analysis for code scanning [6][7]. Users are generally encouraged to reference the action by a major version tag (such as v4) in their workflow files to automatically receive the latest releases and updates within that version [8][6].

Citations:


🌐 Web query:

site:github.com/github/codeql-action CHANGELOG mixed versions init analyze unsupported same version

💡 Result:

In the GitHub CodeQL Action, mixing different versions of the action within the same workflow is considered unsupported and can cause unpredictable results [1][2][3]. To address this, recent versions of the CodeQL Action include validation logic [1][3]: * A warning is emitted from the codeql-action/init step if the workflow is detected to be using different versions of the CodeQL Action [1][3]. * An error is thrown by subsequent CodeQL Action steps (such as analyze) if they attempt to load a configuration file that was generated by a different version of the codeql-action/init step [1][3]. To resolve or prevent these issues, ensure that all steps in your CodeQL workflow (e.g., init, analyze, upload-sarif) use the exact same version of the CodeQL Action [1][3]. If you are referencing the action using a tag like @v3 or @v4, update your workflow to use specific, matching versions across all steps to maintain consistency and avoid these errors [1][4].

Citations:


🌐 Web query:

site:docs.github.com CodeQL Action init analyze same version workflow

💡 Result:

When using the CodeQL Action in a GitHub Actions workflow, you must use the same version for both the init and analyze steps [1][2]. GitHub Actions workflow best practices, as well as the design of the CodeQL Action, require these steps to be part of the same job to ensure the CodeQL database created during the init and build phase is correctly preserved and processed by the analyze phase [3][2]. In a standard CodeQL workflow, the steps are structured within a single job as follows [1][2]: 1. Initialize CodeQL: The github/codeql-action/init action prepares the environment and initializes the CodeQL tools [1]. 2. Build (for compiled languages): The code is built between the init and analyze steps, allowing CodeQL to observe the compiler activity and create the database [3]. 3. Perform CodeQL Analysis: The github/codeql-action/analyze action processes the database and uploads the results [1][2]. If you were to use different versions or split these actions across different jobs without proper artifact management, the analyze step would be unable to locate or correctly interpret the CodeQL database generated by the init step, leading to analysis failures [3][2]. Additionally, ensure that if you are using a containerized environment, all these processes occur within the same container instance [2].

Citations:


Use one CodeQL Action revision in this workflow.

init uses v4.37.3, but analyze uses v4.37.1. Mixed versions are unsupported and can cause analyze to fail when it reads configuration from init. Update analyze to e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/codeql.yml at line 29, Update the CodeQL workflow’s
analyze action to use revision e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81,
matching the revision already used by the init action.

with:
languages: ruby
build-mode: none
Expand Down
Loading