ci(codeql): bump codeql-action v3 → v4#864
Merged
jrusso1020 merged 1 commit intoMay 15, 2026
Merged
Conversation
miguel-heygen
approved these changes
May 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Bump pinned SHA for
github/codeql-action/{init,analyze}from v3 → v4 in.github/workflows/codeql.yml.Both
initandanalyzenow point at9e0d7b8d25671d64c341c19c0152d693099fb5ba(v4 tag tip, resolved viagh api repos/github/codeql-action/git/refs/tags/v4).Why
GitHub's deprecation notice landed in the live CodeQL run logs:
v4's other big change is Node.js 24 (v3 still runs on Node 20, which has its own deprecation timer starting June 2026). Bumping now clears both.
Test plan
github/codeql-actionv4 annotated tag at the time of this commit..github/workflows/codeql.ymlsucceeds and no longer emits the v3 deprecation warning.🤖 Generated with Claude Code