chore(deps): update github/codeql-action digest to cdf488f - #84
chore(deps): update github/codeql-action digest to cdf488f#84renovate[bot] wants to merge 1 commit into
Conversation
28a1486 to
22ba2f2
Compare
timoa
left a comment
There was a problem hiding this comment.
🛑 DevSecOps Renovate sweep (TIM-117) — hard exclusion
This PR modifies .github/workflows/**, which the DevSecOps Renovate autopilot is hard-coded to never auto-merge. Workflow files are a privileged attack surface (supply-chain via pinned actions, permissions:, secrets:, with: injection).
Please review and merge manually if appropriate.
🤖 Automated by DevSecOps autopilot
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot (TIM-119) — flagged for human approval. This PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list for this sweep. Diff is a digest pin update of github/codeql-action, low risk in itself, but any change to GitHub Actions workflow files gets a human gate per DevSecOps policy. Please review and merge manually if accepted.
timoa
left a comment
There was a problem hiding this comment.
Flagging for human approval — this PR touches .github/workflows/scorecard.yml (github/codeql-action digest bump f205ea1 → 5595cca). Renovate workflow files are on the hard-exclusion list for this autopilot; CI is green but I will not auto-merge changes under .github/workflows/**. Diff is a digest pin update. Please approve + squash after review.
22ba2f2 to
92da7ad
Compare
timoa
left a comment
There was a problem hiding this comment.
Renovate PR — DevSecOps sweep (2026-08-14).
Hard exclusion: PR diff touches .github/workflows/scorecard.yml. Per sweep policy, any change to GitHub Actions workflow files requires human review and is never auto-merged.
CI green otherwise. Please review and merge manually if appropriate.
|
Renovate sweep — skipped, hard exclusion. Digest update ( |
timoa
left a comment
There was a problem hiding this comment.
Autopilot: github/codeql-action digest update (f205ea1 → ff2f1c6). Touches .github/workflows/scorecard.yml. This is a hard exclusion for the autopilot (changes to .github/workflows/** require human review only). Please review and merge if happy.
timoa
left a comment
There was a problem hiding this comment.
Auto-merge skipped (DevSecOps sweep): HARD EXCLUSION — this PR modifies .github/workflows/scorecard.yml (digest pin for github/codeql-action). Workflow file changes are excluded from automatic merging per the sweep policy. Please review and merge when ready.
timoa
left a comment
There was a problem hiding this comment.
Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates github/codeql-action digest (f205ea1 → ff2f1c6). However, the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). CI is fully green. Skipping auto-merge — please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep: skipping auto-merge. This PR is a digest bump on github/codeql-action but the diff modifies .github/workflows/scorecard.yml — workflow-file changes are on the hard-exclusion list and require human approval. Please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), out of scope for autopilot auto-merge. Diff is a digest pin bump for github/codeql-action; CI is green. Please review and merge manually if wanted.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Green CI and the change is only a digest bump of github/codeql-action, but my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.
92da7ad to
f402b7a
Compare
|
DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies |
timoa
left a comment
There was a problem hiding this comment.
DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the digest bump (f205ea1 → db488dd) is routine, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.
timoa
left a comment
There was a problem hiding this comment.
This PR is auto-flagged for human review — hard exclusion in scope.
PR #84 updates the github/codeql-action digest from f205ea1 to db488dd and modifies .github/workflows/scorecard.yml. Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.
CI is green. Please verify the new digest matches an upstream CodeQL action release and merge manually.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot: flagged — hard exclusion. PR touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope; please review the github/codeql-action digest update manually.
f402b7a to
11b1870
Compare
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security. Not auto-merging.
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):
Flagged for human approval — not auto-merged.
Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps github/codeql-action digest f205ea1 → cdf488f.
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. The autopilot does not auto-merge workflow changes per policy.
Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily Renovate sweep — flagged for human review.
This PR (digest bump of github/codeql-action) modifies .github/workflows/scorecard.yml, a hard-excluded CI/CD workflow path. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green, so once a human approves the change the PR is safe to merge.
No auto-merge performed. Please review the workflow edit and merge manually if approved.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot (daily Renovate sweep). Not auto-merging — the diff touches .github/workflows/scorecard.yml (a Renovate digest update for github/codeql-action, f205ea1 → cdf488f). Workflow files are on the hard-exclusion path list because CI modifications can change permissions, secrets handling, or execution paths. CI is green and the change looks benign, but please review and merge manually if you're comfortable with it.
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot flagged this PR for human approval.
Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk Renovate updates.
What this PR does: Updates the github/codeql-action digest from f205ea1 → cdf488f (action digest bump).
CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.
|
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging. |
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check (CodeQL-Build, Detect changes, Lint/Test/Build/Security, CodeQL). The change is a github/codeql-action digest bump (f205ea1 → cdf488f). Low-risk content but workflow edits always need a human review. — tldr: green CI but excluded from auto-merge.
|
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check. The change is a github/codeql-action digest bump (f205ea1 -> cdf488f). Low-risk content but workflow edits always need a human review. |
timoa
left a comment
There was a problem hiding this comment.
Renovate sweep — not auto-merged. Modifies .github/workflows/scorecard.yml — hard exclusion for automated merge. Confirm the github/codeql-action digest cdf488f corresponds to the intended upstream release before merging. Other checks are green.
timoa
left a comment
There was a problem hiding this comment.
🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update pins the github/codeql-action digest to cdf488f, CI is green. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update pins the github/codeql-action digest to cdf488f, CI is green. Please review and merge manually if appropriate.
This PR contains the following updates:
f205ea1→cdf488fConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.