chore(deps): update github/codeql-action digest to cdf488f - #221
chore(deps): update github/codeql-action digest to cdf488f#221renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #221 +/- ##
=======================================
Coverage 94.13% 94.13%
=======================================
Files 10 10
Lines 290 290
Branches 105 105
=======================================
Hits 273 273
Misses 1 1
Partials 16 16 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
timoa
left a comment
There was a problem hiding this comment.
Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest, but the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). Skipping auto-merge — please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep: skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is on the hard-exclusion list (any change to .github/workflows/** is flagged for human approval). The change itself is a digest bump on github/codeql-action and CI is green, but policy requires a human review for workflow-file edits. Please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), which is out of scope for autopilot auto-merge regardless of CI state or labels. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if the change is wanted.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Even though checks are green and the change is only a digest bump of github/codeql-action, my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.
43cd070 to
7f63b36
Compare
|
DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies |
7f63b36 to
e9a3057
Compare
timoa
left a comment
There was a problem hiding this comment.
DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (5595cca → db488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.
timoa
left a comment
There was a problem hiding this comment.
This PR is auto-flagged for human review — hard exclusion in scope.
PR #221 modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action). Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.
CI is green and the change is a routine CodeQL action digest update; human reviewer can merge after confirming the new digest matches an upstream release. Please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
Flagged by DevSecOps autopilot: hard exclusion — touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope. Please review manually and merge when satisfied.
e9a3057 to
7e75162
Compare
7e75162 to
5cff28d
Compare
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security (permissions, secrets, supply-chain). Not auto-merging.
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):
Flagged for human approval — not auto-merged.
Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest 5595cca → cdf488f (scorecard workflow).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. Acceptable, but the autopilot does not auto-merge workflow changes per policy.
Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily Renovate sweep — flagged for human review.
This PR modifies .github/workflows/scorecard.yml (digest bump of github/codeql-action), which falls under the hard-excluded CI/CD workflow paths. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.
No auto-merge performed. Please review the workflow edit and merge manually if approved.
5cff28d to
d2d111b
Compare
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot flagged this PR for human approval.
Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.
What this PR does: Updates the github/codeql-action digest from 5595cca → cdf488f (action digest bump).
CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.
|
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging. |
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change itself is a CodeQL action digest bump (5595cca → cdf488f) and looks safe, but workflow changes always need a human to confirm there's no permissions/secrets expansion. Please review and merge if you're comfortable. — tldr: green CI but excluded from auto-merge.
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green. The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review.
|
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. All CI checks are green (CodeQL-Build, Detect changes, Lint/Test/Build/Security, E2E Tests, CodeQL, codecov/patch, codecov/project). The change is a CodeQL action digest bump (5595cca -> cdf488f). Low-risk content but workflow edits always need a human review. Please review and merge if you're comfortable. |
timoa
left a comment
There was a problem hiding this comment.
Renovate sweep — not auto-merged. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion for automated merge: workflow files execute with repository credentials, so an action digest bump there needs a human to confirm the new digest maps to the intended upstream tag. CI is fully green — this is a policy hold, not a quality problem. Please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged by the daily Renovate sweep). CI is fully green (CodeQL + Lint/Test/Build/Security + E2E + codecov), so the diff itself looks safe — please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a digest bump of github/codeql-action (5595cca → cdf488f). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.
This PR updates github/codeql-action digest in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge. Not approving. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.
This PR contains the following updates:
5595cca→cdf488fConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.