diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5c3949f5..e6592430 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -22,3 +22,11 @@ updates: commit-message: prefix: "ci" include: "scope" + # codeql-action is a monorepo (init/analyze/upload-sarif share one release). + # Bumping them in separate PRs leaves mismatched versions in security.yml and + # CodeQL hard-fails "init and analyze must be the same version". Group them so + # every codeql-action bump lands as a single PR that moves all paths together. + groups: + codeql-action: + patterns: + - "github/codeql-action*" diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 966c64e0..cc2b46fb 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -42,7 +42,7 @@ jobs: security-events: write steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - - uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 + - uses: github/codeql-action/init@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4.36.3 with: languages: python - - uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 + - uses: github/codeql-action/analyze@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4.36.3