Commit 2d3beb3
fix(ci): repoint codeql-action at a SHA that exists (#36)
`github/codeql-action@29b1f65c1f735799893313399435a59f54045865` is
pinned here but **exists in no repository** — the GitHub API returns 422
for it.
CodeQL therefore could not start: the run graph fails to build and the
job reports `startup_failure`, so this repository has had **no CodeQL
scanning at all**.
Repointed at `4187e74d05793876e9989daffde9c3e66b4acd07`, which is what
the `v3` tag currently resolves to (v3.37.3), verified against the API.
Found while auditing the estate: the same non-existent SHA was pinned in
**104 repositories**, so CodeQL was dead across nearly all of them.
----
## Summary by Gitar
- **Security and governance:**
- Added estate-wide `SECURITY.md` policy and removed duplicate
governance documentation
- Updated workflow permissions across multiple CI configurations for
security compliance
<sub>This will update automatically on new commits.</sub>
---------
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent 34a52b9 commit 2d3beb3
1 file changed
Lines changed: 14 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
3 | 17 | | |
4 | 18 | | |
5 | 19 | | |
| |||
0 commit comments