Skip to content

Commit b08efda

Browse files
fix(ci): actually repoint codeql-action at a SHA that exists (#48)
`github/codeql-action@29b1f65c1f735799893313399435a59f54045865` **exists in no repository** — the GitHub API returns 422 — so CodeQL could not build its run graph and reported `startup_failure` in 0 seconds. This repository has had **no CodeQL scanning at all**. Repointed at `4187e74d05793876e9989daffde9c3e66b4acd07`, what the `v3` tag resolves to (v3.37.3), verified against the API. **Supersedes an earlier attempt** that branched from the local checkout's HEAD rather than `origin/main`. Where the two had drifted, that commit carried an unrelated diff and left the workflow untouched — so the fix appeared to land while `main` still pinned the dead SHA. Caught by verifying `main` estate-wide, not by the merge tally.\n\nThis pass bases explicitly on `origin/main` and verifies the substitution before committing. Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent 71e0bda commit b08efda

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,12 +39,12 @@ jobs:
3939
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4040

4141
- name: Initialize CodeQL
42-
uses: github/codeql-action/init@29b1f65c1f735799893313399435a59f54045865 # v3
42+
uses: github/codeql-action/init@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
4343
with:
4444
languages: ${{ matrix.language }}
4545
build-mode: ${{ matrix.build-mode }}
4646

4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@29b1f65c1f735799893313399435a59f54045865 # v3
48+
uses: github/codeql-action/analyze@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
4949
with:
5050
category: "/language:${{ matrix.language }}"

0 commit comments

Comments
 (0)