Skip to content

Commit f701492

Browse files
fix(ci): actually repoint codeql-action at a SHA that exists (#58)
`github/codeql-action@29b1f65c1f735799893313399435a59f54045865` **exists in no repository** — the GitHub API returns 422 — so CodeQL could not build its run graph and reported `startup_failure` in 0 seconds. This repository has had **no CodeQL scanning at all**. Repointed at `4187e74d05793876e9989daffde9c3e66b4acd07`, what the `v3` tag resolves to (v3.37.3), verified against the API. **Supersedes an earlier attempt** that branched from the local checkout's HEAD rather than `origin/main`. Where the two had drifted, that commit carried an unrelated diff and left the workflow untouched — so the fix appeared to land while `main` still pinned the dead SHA. Caught by verifying `main` estate-wide, not by the merge tally.\n\nThis pass bases explicitly on `origin/main` and verifies the substitution before committing. Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent 99a561d commit f701492

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ jobs:
7272

7373
# Initializes the CodeQL tools for scanning.
7474
- name: Initialize CodeQL
75-
uses: github/codeql-action/init@29b1f65c1f735799893313399435a59f54045865 # v3
75+
uses: github/codeql-action/init@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
7676
with:
7777
languages: ${{ matrix.language }}
7878
build-mode: ${{ matrix.build-mode }}
@@ -101,6 +101,6 @@ jobs:
101101
exit 1
102102
103103
- name: Perform CodeQL Analysis
104-
uses: github/codeql-action/analyze@29b1f65c1f735799893313399435a59f54045865 # v3
104+
uses: github/codeql-action/analyze@4187e74d05793876e9989daffde9c3e66b4acd07 # v3
105105
with:
106106
category: "/language:${{matrix.language}}"

0 commit comments

Comments
 (0)