Repository navigation
Bump github/codeql-action/analyze from 4.38.1 to 4.38.2 - #39
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.38.1 to 4.38.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1c5b675...2892aa5) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
mt3hr
added a commit
that referenced
this pull request
Oct 7, 2026
…eql-action)を取り込み、vue-tsc だけ 3.3.11 に据え置く Dependabot が出していた PR 6本(#39〜#44)と、未対応のアラート2件 (GHSA-p98j-92pf-mc4p dompurify / GHSA-gfhx-hw2g-v5hg serialize-javascript、どちらも low)を 1コミットで取り込む。PR はマージせずに閉じる。 ## npm まとめ PR(npm-minor-patch の14本)から vue-tsc を除いた13本と、 serialize-javascript 7.1.1 → 7.1.2(workbox-build 経由の推移依存なので lock だけ)。 主なもの: Vuetify 4.2.1 → 4.2.3、Vite 8.3.0 → 8.3.2、mermaid 12.0.0 → 12.1.0、 vitest 5.0.1 → 5.0.3、ESLint 10.11.0 → 10.12.0、vue-i18n 11.4.12 → 11.4.13、dompurify 3.4.15 → 3.4.16。 **vue-tsc は 3.3.11 に据え置く。** 3.3.12 には、テンプレート内のアロー関数で import した値を 参照すると誤って `.value` を付ける退行があり(vuejs/language-tools#6237。修正 PR は未リリース)、 `:rules="[(v: string) => !!v || i18n.global.t(...)]"` を持つ追加画面 8本と kftl-page の `router.replace` で型検査が落ちる(まとめ PR の CI はこれで赤だった)。 コードを回避形へ書き換えず、修正版を待つ。 dompurify の脆弱性は IN_PLACE とフックの組み合わせに限られ、gkill 自身は文字列を渡す sanitize だけなので直接は当たらない。mermaid が内部で DOMPurify を使うので上げておく。 ## Go modernc.org/sqlite 1.59.0 → 1.60.1(modernc.org/libc 1.77.0 → 1.77.1 を揃える)と go-git/go-billy 5.9.1 → 5.9.2(golang.org/x/net・x/text のセキュリティ更新を含む)を、 src/server と src/plugins/ の7モジュールへ。`go mod tidy` は examples/gkill_example を含む 9モジュールで打ち、go.mod / go.sum の差分は PR と一致した。 ## GitHub Actions codeql-action の init と analyze を 4.38.1 → 4.38.2 へ同時に上げる。Dependabot は2本を 別々の PR で出していたため、どちらも analyze が「Loaded a configuration file for version 4.38.2, but running version 4.38.1」で必ず落ちていた。 ## Dependabot 設定 - Actions を1本の PR にまとめる(groups: actions-all)。codeql-action の init / analyze が 別 PR で来て両方赤くなるのを防ぐ - npm に vue-tsc 3.3.12 の ignore を足す。まとめ PR に混ざると PR 全体の型検査が落ちるため。 3.3.13 以降は通常どおり来る 検証: 型検査(vue-tsc --build --force。増分情報が依存の更新を拾わず検査を省いたので全量で)、 Vite ビルド、ESLint(--max-warnings 0)、test_client_unit 2519 件全件成功(テスト件数)、 test_tools 99 件全件成功(テスト件数)、vet_plugins / test_plugins、test_server、npm run verify_docs OK
Owner
|
main へ直接取り込んだので閉じます(f0b53d5f)。init と analyze を同時に 4.38.2 へ上げました(片方だけだと版不一致で Analyze が落ちるため)。 |
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/github_actions/github/codeql-action/analyze-4.38.2
branch
October 7, 2026 13:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github/codeql-action/analyze from 4.38.1 to 4.38.2.
Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)