Skip to content

fix(ci): actually repoint codeql-action at a SHA that exists - #61

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/codeql-sha-v2
Jul 28, 2026
Merged

fix(ci): actually repoint codeql-action at a SHA that exists#61
hyperpolymath merged 1 commit into
mainfrom
fix/codeql-sha-v2

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

github/codeql-action@29b1f65c1f735799893313399435a59f54045865 exists in no repository — the GitHub API returns 422 — so CodeQL could not build its run graph and reported startup_failure in 0 seconds. This repository has had no CodeQL scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, what the v3 tag resolves to (v3.37.3), verified against the API.

Supersedes an earlier attempt that branched from the local checkout's HEAD rather than origin/main. Where the two had drifted, that commit carried an unrelated diff and left the workflow untouched — so the fix appeared to land while main still pinned the dead SHA. Caught by verifying main estate-wide, not by the merge tally.\n\nThis pass bases explicitly on origin/main and verifies the substitution before committing.

github/codeql-action@29b1f65 exists in no repository -- the
GitHub API returns 422 -- so CodeQL could not build its run graph and
reported startup_failure in 0 seconds. This repository has had no CodeQL
scanning at all.

Repointed at 4187e74d05793876e9989daffde9c3e66b4acd07, what the v3 tag resolves to
(v3.37.3), verified against the API.

Supersedes an earlier attempt that branched from the local checkout's HEAD
rather than origin/main. Where the two had drifted, that commit carried an
unrelated diff and left the workflow untouched, so the fix appeared to land
while main still pinned the dead SHA.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Repoints the CodeQL action to a valid, verified release SHA to restore CI scanning. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Jul 28, 2026

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@hyperpolymath
hyperpolymath merged commit ecdaa78 into main Jul 28, 2026
31 of 35 checks passed
@hyperpolymath
hyperpolymath deleted the fix/codeql-sha-v2 branch July 28, 2026 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant