Skip to content

build(deps): bump github/codeql-action from 4.37.8 to 4.38.1 - #823

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-4.38.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-4.38.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action from 4.37.8 to 4.38.1.

Release notes

Sourced from github/codeql-action's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

v4.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

v4.37.9

  • Update default CodeQL bundle version to 2.26.4. #4106
Changelog

Sourced from github/codeql-action's changelog.

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106
Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.8 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.8...v4.38.1)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from fhussonnois as a code owner September 21, 2026 03:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Security Scan Results

Vulnerabilities detected:


Report Summary

┌───────────────────────────────────────────────────┬───────┬─────────────────┬─────────┐
│                      Target                       │ Type  │ Vulnerabilities │ Secrets │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ cli/pom.xml                                       │  pom  │        2        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ core/pom.xml                                      │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ docs/go.mod                                       │ gomod │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ extension-rest-client/pom.xml                     │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ pom.xml                                           │  pom  │       10        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ processor/pom.xml                                 │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-aiven/pom.xml           │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-aws/pom.xml             │  pom  │        1        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-confluent/pom.xml       │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-core/pom.xml            │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-iceberg/pom.xml         │  pom  │        5        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-kafka-connect/pom.xml   │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-kafka/pom.xml           │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-schema-registry/pom.xml │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ resource-generator/pom.xml                        │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-client/pom.xml                  │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-data/pom.xml                    │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-server/pom.xml                  │  pom  │        2        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ template-jinja/pom.xml                            │  pom  │        0        │    -    │
└───────────────────────────────────────────────────┴───────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.70/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


cli/pom.xml (pom)
=================
Total: 2 (HIGH: 1, CRITICAL: 1)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │ HIGH     │        │ 5.3.4             │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

pom.xml (pom)
=============
Total: 10 (HIGH: 5, CRITICAL: 5)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5    │ CVE-2026-54399 │ HIGH     │        │ 5.4               │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5: Apache           │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via excessive HTTP   │
│                                              │                │          │        │                   │                             │ headers                                                     │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54399                  │
├──────────────────────────────────────────────┼────────────────┤          │        ├───────────────────┤                             ├─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │          │        │ 5.3.4             │                             │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        ├───────────────────┤                             │                                                             │
│                                              │                │          │        │ 5.4               │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.bouncycastle:bcprov-jdk18on              │ CVE-2026-8763  │ CRITICAL │        │ 1.84              │ 1.85                        │ org.bouncycastle/bcprov-jdk15on:                            │
│                                              │                │          │        │                   │                             │ org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java:    │
│                                              │                │          │        │                   │                             │ Name Constraints bypass via trailing dot...                 │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-8763                   │
│                                              ├────────────────┼──────────┤        │                   │                             ├─────────────────────────────────────────────────────────────┤
│                                              │ CVE-2026-13506 │ HIGH     │        │                   │                             │ bouncycastle: Bouncy Castle for Java: Denial of Service via │
│                                              │                │          │        │                   │                             │ lazy ASN.1 sequence...                                      │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-13506                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

providers/jikkou-provider-aws/pom.xml (pom)
===========================================
Total: 1 (HIGH: 0, CRITICAL: 1)

┌────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬───────────────────────────────────────────────────────┐
│        Library         │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                         Title                         │
├────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼───────────────────────────────────────────────────────┤
│ io.netty:netty-handler │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via │
│                        │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...     │
│                        │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595            │
└────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴───────────────────────────────────────────────────────┘

providers/jikkou-provider-iceberg/pom.xml (pom)
===============================================
Total: 5 (HIGH: 3, CRITICAL: 2)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5    │ CVE-2026-54399 │ HIGH     │        │ 5.4               │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5: Apache           │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via excessive HTTP   │
│                                              │                │          │        │                   │                             │ headers                                                     │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54399                  │
├──────────────────────────────────────────────┼────────────────┤          │        │                   │                             ├─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │          │        │                   │                             │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.bouncycastle:bcprov-jdk18on              │ CVE-2026-8763  │ CRITICAL │        │ 1.84              │ 1.85                        │ org.bouncycastle/bcprov-jdk15on:                            │
│                                              │                │          │        │                   │                             │ org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java:    │
│                                              │                │          │        │                   │                             │ Name Constraints bypass via trailing dot...                 │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-8763                   │
│                                              ├────────────────┼──────────┤        │                   │                             ├─────────────────────────────────────────────────────────────┤
│                                              │ CVE-2026-13506 │ HIGH     │        │                   │                             │ bouncycastle: Bouncy Castle for Java: Denial of Service via │
│                                              │                │          │        │                   │                             │ lazy ASN.1 sequence...                                      │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-13506                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

server/jikkou-api-server/pom.xml (pom)
======================================
Total: 2 (HIGH: 1, CRITICAL: 1)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │ HIGH     │        │ 5.3.4             │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

Scanned by Trivy

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #827.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action-4.38.1 branch September 28, 2026 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants