Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update CodeQL Action to v3 in ossar.yml #1756

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

sweep-ai[bot]
Copy link
Contributor

@sweep-ai sweep-ai bot commented Feb 5, 2024

PR Feedback (click)

  • 馃憤 Sweep Did Well
  • 馃憥 Sweep Needs Improvement
    I created this PR to fix the failing GitHub Actions.## Description
    This PR addresses the issue of a failing GitHub Actions run due to the use of github/codeql-action/upload-sarif@v2 which is causing an error: "Resource not accessible by integration". Additionally, there's a warning indicating that CodeQL Action v2 will be deprecated on December 5th, 2024.

To resolve this issue and future-proof our workflows, we have updated the CodeQL action version from v2 to v3 in the .github/workflows/ossar.yml file.

Summary of Changes

  • Updated github/codeql-action/upload-sarif@v2 to github/codeql-action/upload-sarif@v3 in .github/workflows/ossar.yml.

These changes ensure that our repository's CI/CD pipeline remains functional and up-to-date with GitHub's best practices and recommendations. This is critical for maintaining the security and efficiency of the code scanning process within the CI/CD pipeline.

Copy link
Contributor Author

sweep-ai bot commented Feb 5, 2024

Rollback Files For Sweep

  • Rollback changes to .github/workflows/ossar.yml
  • Rollback changes to .github/workflows/ossar.yml

@sweep-ai sweep-ai bot added the sweep Assigns Sweep to an issue or pull request. label Feb 5, 2024
@github-actions github-actions bot added the GitHub label Feb 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
GitHub sweep Assigns Sweep to an issue or pull request.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant