Skip to content

chore(deps): update github/codeql-action digest to cdf488f - #221

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest
Open

chore(deps): update github/codeql-action digest to cdf488f#221
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action (changelog) action digest 5595ccacdf488f

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.13%. Comparing base (e347388) to head (d2d111b).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #221   +/-   ##
=======================================
  Coverage   94.13%   94.13%           
=======================================
  Files          10       10           
  Lines         290      290           
  Branches      105      105           
=======================================
  Hits          273      273           
  Misses          1        1           
  Partials       16       16           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest, but the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). Skipping auto-merge — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep: skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (any change to .github/workflows/** is flagged for human approval). The change itself is a digest bump on github/codeql-action and CI is green, but policy requires a human review for workflow-file edits. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), which is out of scope for autopilot auto-merge regardless of CI state or labels. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if the change is wanted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Even though checks are green and the change is only a digest bump of github/codeql-action, my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to ff2f1c6 chore(deps): update github/codeql-action digest to db488dd Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 43cd070 to 7f63b36 Compare August 21, 2026 14:43
@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which is in the excluded paths for auto-merge. Skipping auto-merge; please review and merge manually if appropriate.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7f63b36 to e9a3057 Compare August 22, 2026 00:03

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (5595ccadb488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review — hard exclusion in scope.

PR #221 modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action). Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.

CI is green and the change is a routine CodeQL action digest update; human reviewer can merge after confirming the new digest matches an upstream release. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagged by DevSecOps autopilot: hard exclusion — touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope. Please review manually and merge when satisfied.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from e9a3057 to 7e75162 Compare August 26, 2026 00:05
@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to db488dd chore(deps): update github/codeql-action digest to cdf488f Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 7e75162 to 5cff28d Compare August 26, 2026 16:09

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security (permissions, secrets, supply-chain). Not auto-merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Flagged for human approval — not auto-merged.

Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest 5595ccacdf488f (scorecard workflow).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. Acceptable, but the autopilot does not auto-merge workflow changes per policy.

Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily Renovate sweep — flagged for human review.

This PR modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action), which falls under the hard-excluded CI/CD workflow paths. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.

No auto-merge performed. Please review the workflow edit and merge manually if approved.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 5cff28d to d2d111b Compare September 1, 2026 00:02

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot flagged this PR for human approval.

Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.

What this PR does: Updates the github/codeql-action digest from 5595ccacdf488f (action digest bump).

CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change itself is a CodeQL action digest bump (5595cca → cdf488f) and looks safe, but workflow changes always need a human to confirm there's no permissions/secrets expansion. Please review and merge if you're comfortable. — tldr: green CI but excluded from auto-merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green. The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review. Please review and merge if you're comfortable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion for automated merge: workflow files execute with repository credentials, so an action digest bump there needs a human to confirm the new digest maps to the intended upstream tag. CI is fully green — this is a policy hold, not a quality problem. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged by the daily Renovate sweep). CI is fully green (CodeQL + Lint/Test/Build/Security + E2E + codecov), so the diff itself looks safe — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a digest bump of github/codeql-action (5595ccacdf488f). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.

This PR updates github/codeql-action digest in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge. Not approving. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant