Skip to content

build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main - #174

Draft
seonghobae wants to merge 1 commit into
mainfrom
build/codeql-upload-sarif-4.37.9-main
Draft

build(deps): bump CodeQL SARIF uploader to 4.37.9 on current main#174
seonghobae wants to merge 1 commit into
mainfrom
build/codeql-upload-sarif-4.37.9-main

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Purpose

Reconstruct the still-valid one-line CodeQL SARIF uploader pin from #141 directly on the current protected Wardnet base without importing stale ancestry.

Protected/default main is exact a52ccd0a24a727d9349bb32def7713882d8cad1e. This branch was created from that exact protected head and changes only .github/workflows/scorecard-analysis.yml: github/codeql-action/upload-sarif moves from ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd to immutable commit cdf488f595d80d6e07e03d4674febd5ab45fa938 (v4.37.9). The protected ubuntu-24.04 runner, trigger, permissions, checkout pin, Scorecard pin, SARIF path, and behavior are unchanged.

Fresh upstream release inventory still lists immutable v4.37.9 as the newest v4 action release; its annotated tag resolves to commit cdf488f595d80d6e07e03d4674febd5ab45fa938, and the release updates the default CodeQL bundle to 2.26.4.

Successor / single-writer repair

#141 remains open only as predecessor evidence until this successor is proven complete. Its protected-main-relative effective delta was exactly the same one line. Do not close #141 until this exact successor reaches protected truth or otherwise demonstrates full valid-delta transfer. This PR does not copy any central .github reusable workflow authority and does not weaken a gate.

Exact-current evidence — 2026-09-06 KST

Current exact head remains 028caa05167f9e8f2589b681a8f79c633f406c30 on exact protected base a52ccd0a24a727d9349bb32def7713882d8cad1e; fresh compare is ahead 1 / behind 0 and the only changed path remains .github/workflows/scorecard-analysis.yml. Current inline review-thread inventory is empty and no review has been submitted.

Wardnet-owned current-head lanes that executed are terminal GREEN:

  • CI 34005444829 — success;
  • Security Scan 34005444805 — success;
  • SAST Semgrep 34005444956 — success.

CodeQL PR 34005444791 is terminal failure only at compatibility job 101416634299. The detect-language job succeeded. The compatibility job acquired a real ubuntu-24.04 runner, revalidated this exact PR/head/base, obtained OIDC and a repository-scoped app token, and successfully posted a codeql-scan repository dispatch carrying exact repository/PR/base/head/language/required-run/required-job identity. It then failed closed with VERDICT_STATE=pending because no authenticated terminal codeql-dispatch/actions status had yet been published to this exact head. Fresh combined commit status still contains no such delegated terminal status.

That delegated-verdict defect is advanced on canonical central owner issue ContextualWisdomLab/.github#1929 with this exact run/job payload. Do not change source, create a no-op commit, broadly rerun workflows, or promote predecessor verdicts. GREEN requires the central handler to publish an authenticated terminal verdict to this exact SHA and then wake/rerun only failed required job 101416634299; any genuine scan finding or later base drift becomes a separate causal lane.

Live organization ruleset 18156473 also still requires one unnamed approving review while exposing OrganizationAdmin/always bypass. .github#772 owns the solo-maintainer governance repair. This Draft is not a routine-bypass canary and must not be merged merely to probe whether the current admin principal silently traverses that bypass.

Integration gate

Keep Draft until one unchanged exact head has terminal-valid repository/security/SAST/CodeQL/review/thread/governance evidence on the then-current protected base. No self/model approval, routine administrator bypass, force push, destructive rebase, stale/predecessor evidence promotion, or source churn solely to redispatch.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work status: draft type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant