build(deps): bump the github-actions group with 3 updates - #229
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the github-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog). Updates `github/codeql-action/init` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1c5b675...2892aa5) Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1c5b675...2892aa5) Updates `trufflesecurity/trufflehog` from 3.97.5 to 3.97.9 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@f714bf4...4dd8831) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.97.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs changes before merge. Reviewed September 28, 2026, 12:13 PM ET / 16:13 UTC. ClawSweeper reviewWhat this changesUpdates two CodeQL action references and one TruffleHog action reference used by the repository’s security workflows. Merge readiness⛔ Needs changes before merge - 2 items remain This PR remains useful, but it does not complete the TruffleHog update: the workflow still selects the 3.97.5 scanner image. The CodeQL pins resolve to the stated release, and the workflow permissions are unchanged. Priority: P2 Review scores
Verification
How this fits togetherGitHub runs these workflows for pull requests and pushes. CodeQL analyzes code and workflow files, while TruffleHog scans commits for verified secrets; their results appear as security checks. flowchart LR
A[Pull request or push] --> B[Security workflows]
B --> C[CodeQL action]
B --> D[TruffleHog action]
C --> E[Code analysis result]
D --> F[Selected scanner image]
F --> G[Secret scan result]
Before merge
Findings
Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep the action and scanner image on matching reviewed versions, then confirm the secret-scan workflow runs successfully. Do we have a high-confidence way to reproduce the issue? Yes. The workflow passes 3.97.5 to an upstream action that uses that value as the scanner image tag; this is established from source without executing the workflow locally. Is this the best way to solve the issue? No. The CodeQL update is coherent, but the TruffleHog update should also change the explicit scanner image version. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 527bdbc979dd. LabelsLabel changes:
Label justifications:
EvidenceAcceptance criteria:
What I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Bumps the github-actions group with 3 updates: github/codeql-action/init, github/codeql-action/analyze and trufflesecurity/trufflehog.
Updates
github/codeql-action/initfrom 4.38.1 to 4.38.2Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
github/codeql-action/analyzefrom 4.38.1 to 4.38.2Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
trufflesecurity/trufflehogfrom 3.97.5 to 3.97.9Release notes
Sourced from trufflesecurity/trufflehog's releases.
Commits
4dd8831Spruce up Makefile a little (#5347)449d8a3Int 595 auth errors (#5259)bad9901Add version and comment_number lines to SharePoint source metadata (#5348)4b8eb0emake 401s for Basic auth verified false. (#5290)bbf9447Update module github.com/gabriel-vasile/mimetype to v1.4.15 (#5283)16b566bUpdate module github.com/aymanbagabas/go-osc52 to v1.2.2 (#5252)a25ff85ci: scope Smoke timeouts to trufflehog runs, not the build (#5317)ca9d3b3[SCAN-162] Add Err() to JobProgress and JobProgressRef (#5346)a5f3de5Set all verification errors in detectors (#5253)7ee4d49Add per detector verification timing to verification cache (#5341)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions