chore: bump github/codeql-action from 4 to 4.35.2#2463
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.35.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4...v4.35.2) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.35.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
tonyandrewmeyer
left a comment
There was a problem hiding this comment.
Interesting question here about pinning. Actions from Github are in our exclusion list so aren't pinned to hashes. Are we ok with pinnng to a major only, other than to avoid security updates? I feel like we are, so maybe the settings here are off.
I figured we were fine with pinning to major only, so I guess we do need a setting tweak.
I can't quite parse what you mean here. |
|
Whatever we decide here should be done for |
|
And concierge: canonical/concierge#186 |
|
@tonyandrewmeyer Is going to take care of this, and we're going to revisit our Dependabot settings anyway. |
|
In addition, we should rename LICENSE.txt to LICENSE to work around that silly bug where Dependabot picks up Python requirements in |
Bumps github/codeql-action from 4 to 4.35.2.
Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
95e58e9Merge pull request #3824 from github/update-v4.35.2-d2e135a736f31bfeUpdate changelog for v4.35.2d2e135aMerge pull request #3823 from github/update-bundle/codeql-bundle-v2.25.260abb65Add changelog note5a0a562Update default bundle to codeql-bundle-v2.25.26521697Merge pull request #3820 from github/dependabot/github_actions/dot-github/wor...3c45af2Merge pull request #3821 from github/dependabot/npm_and_yarn/npm-minor-345b93...f1c3393Rebuild1024fc4Rebuild9dd4cfeBump the npm-minor group across 1 directory with 6 updatesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)