Skip to content

Commit ba05e8c

Browse files
fix(ci): actually repoint codeql-action at a SHA that exists (#48)
`github/codeql-action@29b1f65c1f735799893313399435a59f54045865` **exists in no repository** — the GitHub API returns 422 — so CodeQL could not build its run graph and reported `startup_failure` in 0 seconds. This repository has had **no CodeQL scanning at all**. Repointed at `4187e74d05793876e9989daffde9c3e66b4acd07`, what the `v3` tag resolves to (v3.37.3), verified against the API. **Supersedes an earlier attempt** that branched from the local checkout's HEAD rather than `origin/main`. Where the two had drifted, that commit carried an unrelated diff and left the workflow untouched — so the fix appeared to land while `main` still pinned the dead SHA. Caught by verifying `main` estate-wide, not by the merge tally.\n\nThis pass bases explicitly on `origin/main` and verifies the substitution before committing. Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent 0d27c3a commit ba05e8c

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,12 +40,12 @@ jobs:
4040
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4141

4242
- name: Initialize CodeQL
43-
uses: github/codeql-action/init@29b1f65c1f735799893313399435a59f54045865 # v3
43+
uses: github/codeql-action/init@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
4444
with:
4545
languages: ${{ matrix.language }}
4646
build-mode: ${{ matrix.build-mode }}
4747

4848
- name: Perform CodeQL Analysis
49-
uses: github/codeql-action/analyze@29b1f65c1f735799893313399435a59f54045865 # v3
49+
uses: github/codeql-action/analyze@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
5050
with:
5151
category: "/language:${{ matrix.language }}"

0 commit comments

Comments
 (0)