Skip to content

chore(deps): update github/codeql-action action to v4.37.2#441

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/workflows-github-codeql-action-4.x
Jul 22, 2026
Merged

chore(deps): update github/codeql-action action to v4.37.2#441
renovate[bot] merged 1 commit into
masterfrom
renovate/workflows-github-codeql-action-4.x

Conversation

@renovate

@renovate renovate Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v4.37.1v4.37.2

Release Notes

github/codeql-action (github/codeql-action)

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot merged commit f72b88b into master Jul 22, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/workflows-github-codeql-action-4.x branch July 22, 2026 01:11
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/github/codeql-action/upload-sarif e0647621c2984b5ed2f768cb892365bf2a616ad1 UnknownUnknown

Scanned Files

  • .github/workflows/scan.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants