From 1e7f8cb39de2e9a6dfc28c71db22b258fa7230a6 Mon Sep 17 00:00:00 2001 From: Bryant <42397554+Chisanan232@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:18:24 +0800 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=A7=20config(dependabot):=20Group=20gi?= =?UTF-8?q?thub/codeql-action=20bumps=20into=20one=20PR?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A split init/analyze bump can never merge: analyze refuses a configuration file written by a different init version, so every language leg fails and the top-level CodeQL check degrades to neutral. Two group entries, because applies-to defaults to version-updates. Refs AAASM-6239 Co-Authored-By: Claude Opus 5 --- .github/dependabot.yml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index b2109ebf..2d20430b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -15,6 +15,27 @@ updates: - "dependencies" commit-message: prefix: ⬆ + # AAASM-6239: github/codeql-action/init and /analyze are separate + # dependencies to Dependabot, but analyze refuses a configuration file + # written by a different version of init ("Loaded a configuration file for + # version '4.38.2', but running version '4.38.1'"). Ungrouped, one upstream + # release opens one pull request per step and neither can ever merge: every + # language leg fails and the top-level CodeQL check degrades to neutral, so + # the page shows a CodeQL entry that is not red while no analysis ran at + # all. + # + # Both groups are required. applies-to defaults to version-updates, so a + # single entry would leave the security-advisory path splitting exactly as + # before -- which is the path that matters most. + groups: + codeql-action: + applies-to: version-updates + patterns: + - "github/codeql-action*" + codeql-action-security: + applies-to: security-updates + patterns: + - "github/codeql-action*" # Python - package-ecosystem: "pip"