Skip to content

Update github/codeql-action action to v4.36.0#3488

Merged
plengauer merged 2 commits into
mainfrom
renovate/github-codeql-action-4.x
May 23, 2026
Merged

Update github/codeql-action action to v4.36.0#3488
plengauer merged 2 commits into
mainfrom
renovate/github-codeql-action-4.x

Conversation

@plengauer
Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
github/codeql-action action minor v4.35.5v4.36.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

github/codeql-action (github/codeql-action)

v4.36.0

Compare Source

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #​3894
  • Add support for SHA-256 Git object IDs. #​3893
  • Update default CodeQL bundle version to 2.25.5. #​3926

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@plengauer plengauer requested a review from moflwi as a code owner May 23, 2026 01:06
Copilot AI review requested due to automatic review settings May 23, 2026 01:06
@plengauer plengauer enabled auto-merge (squash) May 23, 2026 01:06
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s GitHub Actions workflows to use the newer github/codeql-action release, affecting both the main CodeQL analysis workflow and the integration test workflow that exercises CodeQL under instrumentation.

Changes:

  • Bump github/codeql-action from v4.35.5 to v4.36.0 in the CodeQL analysis workflow.
  • Bump github/codeql-action from v4.35.5 to v4.36.0 in the GitHub integration workflow’s CodeQL job (JS/TS and Python).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
.github/workflows/test_github.yml Updates CodeQL init/analyze steps used in the integration CodeQL job to v4.36.0.
.github/workflows/analyze.yml Updates CodeQL init/analyze steps used in scheduled/PR CodeQL scanning to v4.36.0.

Comment thread .github/workflows/analyze.yml
Comment thread .github/workflows/test_github.yml
@plengauer plengauer merged commit eea0eca into main May 23, 2026
574 checks passed
@plengauer plengauer deleted the renovate/github-codeql-action-4.x branch May 23, 2026 07:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants