Skip to content

chore(deps): update github/codeql-action action to v4.36.0 (.github/workflows)#2384

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github/workflows/github-codeql-action-4.x
Open

chore(deps): update github/codeql-action action to v4.36.0 (.github/workflows)#2384
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github/workflows/github-codeql-action-4.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 22, 2026

This PR contains the following updates:

Package Type Update Change
github/codeql-action action minor v4.35.5v4.36.0

Release Notes

github/codeql-action (github/codeql-action)

v4.36.0

Compare Source

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #​3894
  • Add support for SHA-256 Git object IDs. #​3893
  • Update default CodeQL bundle version to 2.25.5. #​3926

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner May 22, 2026 16:16
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label May 22, 2026
@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps Bot commented May 22, 2026

Greptile Summary

This PR updates the CodeQL SARIF upload action used by two GitHub workflows. The main changes are:

  • Updates the govulncheck SARIF upload action pin to github/codeql-action/upload-sarif v4.36.0.
  • Updates the Scorecard SARIF upload action pin to github/codeql-action/upload-sarif v4.36.0.
  • Keeps the existing workflow inputs and permissions unchanged.

Confidence Score: 5/5

This looks safe to merge.

  • No blocking issues found in the changed workflow lines.
  • The updated action SHA matches the referenced upstream version.
  • The existing SARIF upload inputs and permissions still match the action contract.

Important Files Changed

Filename Overview
.github/workflows/govulncheck.yml Updates the pinned SARIF upload action SHA and version comment.
.github/workflows/scorecard.yml Updates the pinned SARIF upload action SHA and version comment.

Reviews (1): Last reviewed commit: "chore(deps): update github/codeql-action..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants