Skip to content

[AAASM-6239] 🔧 (dependabot): Group codeql-action bumps so they can merge - #346

Merged
Chisanan232 merged 1 commit into
mainfrom
v0.0.1/AAASM-6239/config/group_codeql_action_bumps
Oct 1, 2026
Merged

Chisanan232 merged 1 commit into
mainfrom
v0.0.1/AAASM-6239/config/group_codeql_action_bumps

Conversation

@Chisanan232

Copy link
Copy Markdown
Contributor

Part of AAASM-6239.

What changed

One file, .github/dependabot.yml: the existing github-actions update entry
gains a groups: block that pulls every github/codeql-action* dependency
into a single pull request. Pure insertion — 21 lines added, 0 removed,
nothing reordered, no other ecosystem touched.

Why

Dependabot treats github/codeql-action/init and github/codeql-action/analyze
as two independent dependencies, so one upstream release opens two pull
requests. analyze then refuses to consume a configuration file written by a
different version of init, so each half is permanently unmergeable on its
own
.

Proven from GitHub's own annotation on a live instance of this split
(horonomy/fornax-core #199, check run 109651309011):

analyze post-action step failed: Loaded a configuration file for version
'4.38.2', but running version '4.38.1'

warning: 1 issue was detected with this workflow: Not all workflow steps
that use github/codeql-action actions use the same version.

Observed check state on both halves of that split:

check init-only PR analyze-only PR
codeql (actions) FAILURE FAILURE
codeql (python) FAILURE FAILURE
codeql (rust) FAILURE FAILURE
CodeQL NEUTRAL NEUTRAL
other required checks SUCCESS SUCCESS

The CodeQL row is the part worth naming. It goes neutral, not red, so the
pull request page shows a CodeQL entry that is not failing while no analysis
ran at all. A neutral check is not evidence of analysis.

Why two group entries and not one

From GitHub's Dependabot options reference:

applies-to — Specify which type of update the group applies to. When
undefined, defaults to version updates. Supported values: version-updates
or security-updates.

A single group would fix the weekly-bump path and leave the
security-advisory path splitting exactly as before — the path that matters
most. Hence codeql-action (version updates) and codeql-action-security
(security updates), both matching github/codeql-action*.

How this was verified

The patched file was produced by inserting the block and then asserting, in
both directions, that nothing else changed:

parsed-YAML equality   before == after, after popping the new `groups` key   PASS
new key exact match    groups == {codeql-action, codeql-action-security},    PASS
                       each with the expected applies-to and patterns
diff shape             21 insertions, 0 deletions                           PASS
longest inserted line  80 columns

The same assertions were run against this repository's live file immediately
before pushing, so the patch cannot have been generated from a stale baseline.

What this does not do

  • No workflow edit. The pins still move via Dependabot; that is the point.
  • No other ecosystem grouped. Only the version-locked codeql-action family.
  • No required check relaxed, no pin replaced with a floating tag, no analysis
    language or path excluded.

Scope

19 repositories across both organizations carry a version-locked
codeql-action pair and none had a group. This is one of them; the rest land
under FORNX-426, HORO-1645 and AAASM-6239.

No screenshots or recordings: this workstation's data-handling policy keeps
visual artifacts local, and the evidence above is complete without them.

A split init/analyze bump can never merge: analyze refuses a configuration
file written by a different init version, so every language leg fails and
the top-level CodeQL check degrades to neutral. Two group entries, because
applies-to defaults to version-updates.

Refs AAASM-6239

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Chisanan232
Chisanan232 merged commit 7cad098 into main Oct 1, 2026
6 checks passed
@Chisanan232
Chisanan232 deleted the v0.0.1/AAASM-6239/config/group_codeql_action_bumps branch October 1, 2026 04:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant