chore(security): unify CodeQL Action v4.37.7 - #1274
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Implemented on exact head . The CodeQL pin contract now scans both and workflow files and only treats lines containing as action references, preventing both extension and explanatory-comment blind spots. Targeted contract tests: 4 passed; passed. |
|
Implemented on exact head fe69696. The CodeQL pin contract now scans both yml and yaml workflow files and only treats lines containing uses as action references, preventing extension and explanatory comment blind spots. Targeted contract tests: 4 passed. git diff check passed. |
|
Exact-head check RCA: current Strix run 32689043676 emitted provider-infrastructure output, produced no vulnerability report artifact, and failed on the NVIDIA fallback/direct-OpenAI provider path (LLM Provider NOT provided). The gate is correctly failing closed; no source vulnerability finding is present in this log. Revalidate after the provider/failover root PR is healthy. |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
1da2fce5a10c5036cb4c305b60b63594b0a446fd. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32718354490/job/97404293658)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32718354490/job/97404293658)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (7 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (7 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: codeql-action-single-version.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: codeql-action-single-version.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_codeql_pr_workflow_contract.py"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_codeql_pr_workflow_contract.py"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (7 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (7 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: codeql-action-single-version.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: codeql-action-single-version.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_codeql_pr_workflow_contract.py"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_codeql_pr_workflow_contract.py"]
R4 --> V4["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
1da2fce5a10c5036cb4c305b60b63594b0a446fd. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32718354490/job/97404293658)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32718354490/job/97404293658)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (7 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (7 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: codeql-action-single-version.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: codeql-action-single-version.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_codeql_pr_workflow_contract.py"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_codeql_pr_workflow_contract.py"]
R4 --> V4["targeted test run"]
Outcome
Pins all 14 central
github/codeql-actioninit,analyze, andupload-sarifuses to the full commit referenced by the official annotated v4.37.7 tag. This clean current-main replacement combines the complete scope of stale v4.37.6 alignment #918 with current v4.37.7 update #1107, which covered only two workflows.Supersedes #918.
Supersedes #1107.
Verification
Provenance
The official annotated
v4.37.7tag resolves toff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd. The doctoring record cites the official release and GitHub immutable-SHA guidance in APA 7th form.