ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d) - #310

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest
Jun 4, 2026
Merged

ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)#310
its-miso[bot] merged 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@its-miso

@its-misoits-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
github/codeql-action (changelog)actiondigest87557b98aad20d

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 4, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit 79145b8 into mainJun 4, 2026
1 check was pending
@its-miso
its-misoBot deleted the renovate/github-codeql-action-digest branch June 4, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

PR #310 — ci(github-action): update action github/codeql-action (87557b9 → 8aad20d)

Recommendation: Approve. This is a routine, low-risk patch-level digest bump of a pinned third-party GitHub Action, fully consistent with the repository's existing pattern for action updates.

Change-by-change findings

  • .github/workflows/image.yaml (line 93): Updates the github/codeql-action/upload-sarif reference from 87557b9c84dde89fdd9b10e88954ac2f4248e463 to 8aad20d150bbac5944a9f9d289da16a4b0d87c1e. The trailing comment # v4 (major version annotation) is preserved.
    • Per the GitHub tags enrichment, the old digest corresponds to v4.36.1 and the new digest corresponds to v4.36.2 — a patch release within the v4 major line. No major-version bump, no breaking changes expected.
    • The step (Upload Trivy results) is the SARIF upload for the Trivy scan and is governed by if: github.event_name != 'pull_request' && hashFiles('trivy-results.sarif') != ''. The with: sarif_file: trivy-results.sarif inputs are unchanged, so the v4.36.1 → v4.36.2 interface should be a drop-in.
    • SHA pinning (supply-chain best practice) is preserved; only the digest advances.

Sources

  • PR diff and file patch (.github/workflows/image.yaml, single-line digest change).
  • Renovate PR body: github/codeql-action digest 87557b98aad20d, automerge enabled, generated by Renovate.
  • GitHub tags enrichment for github/codeql-action mapping 87557b9…v4.36.1 and 8aad20d…v4.36.2; recent v4.x releases show consistent patch progression (v4.36.0 → v4.36.1 → v4.36.2).
  • Repository history: prior commits in this same digest-update lineage include 6fbac56 ci(github-action): update action github/codeql-action (7211b7c → 87557b9) (#300), confirming the established pattern.

Standards Compliance

  • AGENTS.md — GitHub Actions CI section notes that .github/workflows/image.yaml builds and publishes to GHCR and that "Trivy scanning is advisory only (continue-on-error: true)." This update affects only the SARIF upload step, which is part of that advisory flow; it does not alter build, publish, lint, or typecheck gates.
  • AGENTS.md — Code Standards does not mandate any specific SHA-pinning syntax, but the existing workflow convention is uses: <owner>/<repo>/<action>@<sha> # <major>, which this PR preserves (only the SHA advances, the # v4 comment is retained). The PR is consistent with the file's current style and with prior Renovate updates in the same file (PR #300 for the same action, PR #301/#307 for actions/checkout, PR #259 for misospace/pr-reviewer-action).
  • No new secrets, no changes to environment variables, no schema/migrations, no API route or library code touched — none of the AGENTS.md Code Standards (1–6) are implicated.

Linked Issue Fit

  • No linked issue references in the PR body. This is a routine dependency-update PR opened by the Renovate bot (app/its-miso), so no issue-level acceptance criteria apply. There is nothing to misinterpret or miss.

Evidence Provider Findings

  • No evidence providers were configured for this run. There are no provider outputs to evaluate.

Tool Harness Findings

  • Tool harness reported Planned requests: 0 and a planning warning ("Could not parse planning response as JSON"). No actionable tool findings were produced; this does not affect the review.

Unknowns / Needs Verification

  • The compare page for 87557b9…8aad20d could not be fetched ("Could not fetch compare metadata"), so the exact list of commits inside v4.36.2 was not retrieved. However, the tags enrichment confirms 8aad20d… = v4.36.2 and the previous digest maps to v4.36.1, which is sufficient to classify this as a patch release. The CodeQL upload-sarif action's published input contract (sarif_file) is unchanged in scope, and the workflow only passes sarif_file.
  • OCI image digest provenance: N/A — this PR updates a GitHub Action SHA, not a container image. The image digest provenance check correctly reports no image digest changes.

Verdict

Approve. Routine patch-level digest update of a SHA-pinned third-party action, consistent with prior Renovate updates in the same file, no breaking changes, no standards violations, and no linked issue criteria to satisfy.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants