Skip to content

chore(deps): update github/codeql-action digest to cdf488f - #84

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest
Open

chore(deps): update github/codeql-action digest to cdf488f#84
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-codeql-action-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action (changelog) action digest f205ea1cdf488f

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 28a1486 to 22ba2f2 Compare August 6, 2026 06:38

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 DevSecOps Renovate sweep (TIM-117) — hard exclusion

This PR modifies .github/workflows/**, which the DevSecOps Renovate autopilot is hard-coded to never auto-merge. Workflow files are a privileged attack surface (supply-chain via pinned actions, permissions:, secrets:, with: injection).

Please review and merge manually if appropriate.

🤖 Automated by DevSecOps autopilot

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot (TIM-119) — flagged for human approval. This PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list for this sweep. Diff is a digest pin update of github/codeql-action, low risk in itself, but any change to GitHub Actions workflow files gets a human gate per DevSecOps policy. Please review and merge manually if accepted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagging for human approval — this PR touches .github/workflows/scorecard.yml (github/codeql-action digest bump f205ea15595cca). Renovate workflow files are on the hard-exclusion list for this autopilot; CI is green but I will not auto-merge changes under .github/workflows/**. Diff is a digest pin update. Please approve + squash after review.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to 5595cca chore(deps): update github/codeql-action digest to ff2f1c6 Aug 13, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 22ba2f2 to 92da7ad Compare August 13, 2026 19:33

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate PR — DevSecOps sweep (2026-08-14).

Hard exclusion: PR diff touches .github/workflows/scorecard.yml. Per sweep policy, any change to GitHub Actions workflow files requires human review and is never auto-merged.

CI green otherwise. Please review and merge manually if appropriate.

@timoa

timoa commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Renovate sweep — skipped, hard exclusion. Digest update (github/codeql-action f205ea1 → ff2f1c6) but the diff touches .github/workflows/scorecard.yml — this is in the hard exclusion list (.github/workflows/**). CI is green but the autopilot policy never auto-merges workflow changes or actions that inject into workflows. Please review and merge manually, or close.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Autopilot: github/codeql-action digest update (f205ea1 → ff2f1c6). Touches .github/workflows/scorecard.yml. This is a hard exclusion for the autopilot (changes to .github/workflows/** require human review only). Please review and merge if happy.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge skipped (DevSecOps sweep): HARD EXCLUSION — this PR modifies .github/workflows/scorecard.yml (digest pin for github/codeql-action). Workflow file changes are excluded from automatic merging per the sweep policy. Please review and merge when ready.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest (f205ea1ff2f1c6). However, the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). CI is fully green. Skipping auto-merge — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep: skipping auto-merge. This PR is a digest bump on github/codeql-action but the diff modifies .github/workflows/scorecard.yml — workflow-file changes are on the hard-exclusion list and require human approval. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), out of scope for autopilot auto-merge. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if wanted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Green CI and the change is only a digest bump of github/codeql-action, but my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to ff2f1c6 chore(deps): update github/codeql-action digest to db488dd Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from 92da7ad to f402b7a Compare August 21, 2026 15:48
@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies .github/workflows/scorecard.yml (codeql-action digest bump), which is in the excluded paths for auto-merge. Skipping auto-merge; please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (f205ea1db488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review — hard exclusion in scope.

PR #84 updates the github/codeql-action digest from f205ea1 to db488dd and modifies .github/workflows/scorecard.yml. Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.

CI is green. Please verify the new digest matches an upstream CodeQL action release and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot: flagged — hard exclusion. PR touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope; please review the github/codeql-action digest update manually.

@renovate renovate Bot changed the title chore(deps): update github/codeql-action digest to db488dd chore(deps): update github/codeql-action digest to cdf488f Aug 26, 2026
@renovate
renovate Bot force-pushed the renovate/github-codeql-action-digest branch from f402b7a to 11b1870 Compare August 26, 2026 23:38

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security. Not auto-merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Flagged for human approval — not auto-merged.

Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest f205ea1cdf488f.
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. The autopilot does not auto-merge workflow changes per policy.

Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily Renovate sweep — flagged for human review.

This PR (digest bump of github/codeql-action) modifies .github/workflows/scorecard.yml, a hard-excluded CI/CD workflow path. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.

No auto-merge performed. Please review the workflow edit and merge manually if approved.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot (daily Renovate sweep). Not auto-merging — the diff touches .github/workflows/scorecard.yml (a Renovate digest update for github/codeql-action, f205ea1cdf488f). Workflow files are on the hard-exclusion path list because CI modifications can change permissions, secrets handling, or execution paths. CI is green and the change looks benign, but please review and merge manually if you're comfortable with it.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot flagged this PR for human approval.

Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.

What this PR does: Updates the github/codeql-action digest from f205ea1cdf488f (action digest bump).

CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check (CodeQL-Build, Detect changes, Lint/Test/Build/Security, CodeQL). The change is a github/codeql-action digest bump (f205ea1 → cdf488f). Low-risk content but workflow edits always need a human review. — tldr: green CI but excluded from auto-merge.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check. The change is a github/codeql-action digest bump (f205ea1 -> cdf488f). Low-risk content but workflow edits always need a human review.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. Modifies .github/workflows/scorecard.yml — hard exclusion for automated merge. Confirm the github/codeql-action digest cdf488f corresponds to the intended upstream release before merging. Other checks are green.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update pins the github/codeql-action digest to cdf488f, CI is green. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update pins the github/codeql-action digest to cdf488f, CI is green. Please review and merge manually if appropriate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant