Skip to content

Pin codeql.yml actions to full commit SHAs#311

Merged
shibayan merged 2 commits intoshibayan-patch-1from
copilot/sub-pr-309-again
Mar 6, 2026
Merged

Pin codeql.yml actions to full commit SHAs#311
shibayan merged 2 commits intoshibayan-patch-1from
copilot/sub-pr-309-again

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 6, 2026

The CodeQL workflow used floating @v4 tags for all actions, diverging from the repo's convention of pinning to immutable commit SHAs for supply chain hardening.

Changes

  • .github/workflows/codeql.yml — replaced all floating tags with pinned SHAs + version comments:
    - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
    - uses: github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
    - uses: github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
    Matches the pattern already established in build.yml and publish.yml.

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update CodeQL workflow for improved clarity Pin codeql.yml actions to full commit SHAs Mar 6, 2026
@shibayan shibayan marked this pull request as ready for review March 6, 2026 07:44
@shibayan shibayan merged commit 53ff43f into shibayan-patch-1 Mar 6, 2026
@shibayan shibayan deleted the copilot/sub-pr-309-again branch March 6, 2026 07:44
shibayan added a commit that referenced this pull request Mar 6, 2026
* Refactor CodeQL workflow for improved clarity

Updated CodeQL workflow to include autobuild mode and removed unnecessary comments.

* Fix CodeQL C# analysis to run on Windows (#312)

* Initial plan

* Fix CodeQL workflow to use windows-latest for C# analysis

Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>

* Pin codeql.yml actions to full commit SHAs (#311)

* Initial plan

* Pin codeql.yml actions to full commit SHAs for supply chain hardening

Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>

* Fix CodeQL workflow: add setup-dotnet for C# autobuild on Windows (#310)

* Initial plan

* Add setup-dotnet step to CodeQL workflow for C# autobuild

Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>
Co-authored-by: Tatsuro Shibamura <me@shibayan.jp>

---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: shibayan <1356444+shibayan@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants