Skip to content

chore: group CodeQL Dependabot updates - #61

Merged
daichunghy merged 2 commits into
mainfrom
codex/dependabot-grouping
Sep 6, 2026
Merged

daichunghy merged 2 commits into
mainfrom
codex/dependabot-grouping

Conversation

@daichunghy

Copy link
Copy Markdown
Owner

Summary

  • group github/codeql-action init and analyze updates in one Dependabot group
  • keep the committed Action bundle aligned with the current source

Why

The current Dependabot PRs #57 and #58 update CodeQL init and analyze separately. Each mixed-version merge ref fails because the CodeQL configuration and runner versions disagree. Grouping the dependency names keeps those actions on one update path for future weekly runs.

This PR does not close or merge #57 or #58.

Validation

  • Dependabot YAML group check passed
  • npm run verify passed
  • 108 core tests, 14 security tests, 32 GitHub integration tests and 6 CLI tests passed
  • npm audit reported 0 vulnerabilities
  • Action bundle clean-room verification passed

@daichunghy
daichunghy merged commit bd8ab1e into main Sep 6, 2026
10 checks passed
@daichunghy
daichunghy deleted the codex/dependabot-grouping branch September 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant