diff --git a/.github/dependabot.yml b/.github/dependabot.yml index a91454d4b..db0dd83cd 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,7 +16,14 @@ updates: # SHA-form re-bump attempt bypassed versions-scoped ignores — see # nexia-list#101/#104). Hold until upstream clears 4.38.1 or a newer # release verifies green; revisit deliberately, not weekly. - - dependency-name: "github/codeql-action" + # + # The trailing * is load-bearing. Workflows reference the SUBPATH + # actions (github/codeql-action/init, /analyze, /upload-sarif) and + # Dependabot treats each subpath as its own dependency name -- so a + # bare "github/codeql-action" entry matches NONE of them. That is how + # #977 re-bumped 4.38.0 -> 4.38.1 on 2026-09-22 straight through this + # hold, startup-killing codeql.yml and scorecard.yml (jobs=0). + - dependency-name: "github/codeql-action*" # github-actions major bumps are usually safe — the SHA pin is the real # version. Standards repo is the canonical-template host so we want the # PRs fast (daily) and grouped. If a specific action proves unstable on diff --git a/.github/workflows/codeql-reusable.yml b/.github/workflows/codeql-reusable.yml index 9f0158d41..4e13fa00d 100644 --- a/.github/workflows/codeql-reusable.yml +++ b/.github/workflows/codeql-reusable.yml @@ -94,12 +94,12 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with: languages: ${{ inputs.language }} build-mode: ${{ inputs.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with: category: "/language:${{ inputs.language }}" diff --git a/.github/workflows/hypatia-scan-reusable.yml b/.github/workflows/hypatia-scan-reusable.yml index 313f8679d..e4dc53f84 100644 --- a/.github/workflows/hypatia-scan-reusable.yml +++ b/.github/workflows/hypatia-scan-reusable.yml @@ -242,7 +242,7 @@ jobs: # This flag only tolerates a genuine upload failure (e.g. Advanced # Security disabled on a private repo) once the job is actually running. continue-on-error: true - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with: sarif_file: hypatia.sarif category: hypatia diff --git a/.github/workflows/scorecard-reusable.yml b/.github/workflows/scorecard-reusable.yml index 1f9da93f6..7fa7240c5 100644 --- a/.github/workflows/scorecard-reusable.yml +++ b/.github/workflows/scorecard-reusable.yml @@ -92,7 +92,7 @@ jobs: printf 'reconciled=false\n' >> "$GITHUB_OUTPUT" fi - name: Upload SARIF to code scanning - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v3 + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with: sarif_file: ${{ steps.select-sarif.outputs.file }} @@ -225,7 +225,7 @@ jobs: printf 'reconciled=false\n' >> "$GITHUB_OUTPUT" fi - name: Upload SARIF to code scanning - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with: sarif_file: ${{ steps.select-sarif.outputs.file }} - name: Retain scan evidence