Skip to content

Conversation

@cpritchett
Copy link

This pull request updates the dependencies used in the CodeQL workflow to improve security and compatibility.

Dependency updates:

  • Updated the github/codeql-action/init and github/codeql-action/analyze actions from version v1 to v4.31.3 in .github/workflows/codeql.yml, ensuring the workflow uses the latest stable versions.

@gemini-code-assist
Copy link

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR modernizes the CodeQL security analysis workflow by updating action versions and enhancing the workflow configuration with improved triggers, permissions, and a matrix strategy.

  • Updates CodeQL action from v1 to v4.31.3 for improved security and features
  • Adds scheduled weekly scans and push event triggers alongside pull request scans
  • Implements matrix strategy for language-based analysis with proper permissions

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cpritchett cpritchett merged commit 6f7b97c into main Nov 17, 2025
3 of 5 checks passed
@cpritchett cpritchett deleted the fix/codeql-action-version branch November 17, 2025 09:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants