Conversation
The v3 line stopped receiving updates at `3.30.6`, while the v4 line has continued through `4.38.x`, so the scan runs a year-old analyzer with an outdated default CodeQL bundle. The only change at the v4 boundary is the Node 24 runtime, which the GitHub-hosted runners satisfy. `init`, `autobuild` and `analyze` are bumped together, since the action rejects a configuration written by a different version of `init`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5, v6 and v7 releases move the action to the Node 24 runtime, store credentials outside `.git/config`, and refuse to check out fork pull request code from `pull_request_target` and `workflow_run` workflows. None of that changes behavior here: the runners are GitHub-hosted, no step runs authenticated git from a container action, and the single `workflow_run` job checks out `AdaCore/learn-latest-html-pages` at `gh-pages`, which the new guard does not match. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v6 and v7 releases move the action to the Node 24 runtime and to an ESM bundle, and drop the `pip-install` input, which these workflows do not use. The `python-version` input is unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v7 releases move the action to the Node 24 runtime and to an ESM bundle, and change when caching is enabled automatically. Every call site sets `cache: 'pnpm'` and `cache-dependency-path` explicitly, which takes precedence over the automatic behavior. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v7 releases move the action to the Node 24 runtime and to an ESM bundle, and add an `archive` input for uploading a single file unzipped. That default is unchanged, so the artifacts stay zipped, and `if-no-files-found`, `retention-days` and `compression-level` keep their meaning. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v8 releases move the action to the Node 24 runtime and to an ESM bundle, make a digest mismatch fail the run rather than warn, and skip decompression for artifacts that were not uploaded zipped. Neither behavior change affects this workflow: the artifacts are uploaded zipped, and they are downloaded by name, so the v5 change to the output path of single-artifact-by-ID downloads does not apply either. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The workflows pin actions to a moving major tag, which only advances when someone goes looking, and the CodeQL action in particular stops receiving analyzer updates once its major is superseded. Add a `github-actions` entry checking monthly. Minor and patch updates are grouped into one pull request, while a major matches no group and arrives on its own, so it can be reviewed or held back without blocking the rest. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The actions in
.github/workflowshad fallen behind by up to four majorversions, and the CodeQL workflow had drifted from the current template.
Action versions
One commit per action, so any single one can be reverted on its own:
github/codeql-action/*v3 -> v4actions/checkoutv4 -> v7actions/setup-pythonv5 -> v7actions/setup-nodev4 -> v7actions/upload-artifactv4 -> v7actions/download-artifactv4 -> v8CodeQL is the significant one: v3 stopped at
3.30.6while v4 continuedthrough
4.38.x, so the scan ran an outdated analyzer and bundle.The behavior changes in these releases were checked against how the
workflows call them, and none apply: the fork-PR guard in
checkout@v7does not match the one
workflow_runjob, caching is set explicitly forsetup-node,setup-python's removedpip-installinput is unused, andthe artifacts are uploaded zipped and downloaded by name. The required
Node 24 runtime is satisfied by the GitHub-hosted runners.
CodeQL workflow
contents: readandsecurity-events: writeinstead ofinheriting the repository default, which could be tightened to one that
withholds the upload permission.
autobuildreplaced bybuild-mode: none; both languages areinterpreted, so it had nothing to build.
analyzegetscategory: "/language:${{ matrix.language }}", so thematrix legs are matched as separate analyses.
runs-on: ubuntu-latestkept, with a comment on why it differs from theother workflows: the analysis neither builds nor runs the sources.
on: [pull_request]deliberately unchanged.Dependabot
.github/dependabot.ymlis new. It coversgithub-actionsonly, monthly,with
CIas the commit prefix. Minor and patch updates are grouped intoone pull request; a major arrives on its own so it can be reviewed or held
back separately. The
pnpmandpipmanifests are not covered — they arelockfile-pinned and warrant their own discussion.
Validation
Every workflow parses after each commit. The version-bump diff contains no
changed line that is not a
uses:line. The Dependabot file was checkedagainst the documented option schema, and the CodeQL workflow structurally
(no
autobuild,build-modeandcategoryin place, permissions exact,triggers unchanged). The workflows are exercised by this pull request,
which also runs the reworked CodeQL job on both matrix legs.
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com