[AAASM-6239] 🔧 (dependabot): Group codeql-action bumps so they can merge - #346
Merged
Chisanan232 merged 1 commit intoOct 1, 2026
Merged
Conversation
A split init/analyze bump can never merge: analyze refuses a configuration file written by a different init version, so every language leg fails and the top-level CodeQL check degrades to neutral. Two group entries, because applies-to defaults to version-updates. Refs AAASM-6239 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Chisanan232
deleted the
v0.0.1/AAASM-6239/config/group_codeql_action_bumps
branch
October 1, 2026 04:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of AAASM-6239.
What changed
One file,
.github/dependabot.yml: the existinggithub-actionsupdate entrygains a
groups:block that pulls everygithub/codeql-action*dependencyinto a single pull request. Pure insertion — 21 lines added, 0 removed,
nothing reordered, no other ecosystem touched.
Why
Dependabot treats
github/codeql-action/initandgithub/codeql-action/analyzeas two independent dependencies, so one upstream release opens two pull
requests.
analyzethen refuses to consume a configuration file written by adifferent version of
init, so each half is permanently unmergeable on itsown.
Proven from GitHub's own annotation on a live instance of this split
(
horonomy/fornax-core#199, check run109651309011):Observed check state on both halves of that split:
codeql (actions)codeql (python)codeql (rust)CodeQLThe
CodeQLrow is the part worth naming. It goes neutral, not red, so thepull request page shows a CodeQL entry that is not failing while no analysis
ran at all. A neutral check is not evidence of analysis.
Why two group entries and not one
From GitHub's Dependabot options reference:
A single group would fix the weekly-bump path and leave the
security-advisory path splitting exactly as before — the path that matters
most. Hence
codeql-action(version updates) andcodeql-action-security(security updates), both matching
github/codeql-action*.How this was verified
The patched file was produced by inserting the block and then asserting, in
both directions, that nothing else changed:
The same assertions were run against this repository's live file immediately
before pushing, so the patch cannot have been generated from a stale baseline.
What this does not do
language or path excluded.
Scope
19 repositories across both organizations carry a version-locked
codeql-action pair and none had a group. This is one of them; the rest land
under FORNX-426, HORO-1645 and AAASM-6239.
No screenshots or recordings: this workstation's data-handling policy keeps
visual artifacts local, and the evidence above is complete without them.