chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2#495
chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2#495dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@87557b9...8aad20d) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
) Supersedes 9 individual dependabot PRs (#495–502, #516), consolidated to avoid a CI roundtrip per PR. All bumps applied on one branch and verified together (UI typecheck + 1297 vitest + production build + lint; uv relock). Python (uv.lock): - pyjwt 2.12.1 -> 2.13.0 (#516) npm (ui/package.json + pnpm-lock.yaml) — constraints set to dependabot's targets; pnpm resolved latest-compatible patches (newer than the targets): - next ^16.2.6 -> ^16.2.7 (resolved 16.2.9) (#501) - @tanstack/react-query ~5.100.14 -> ~5.101.0 (+ -devtools in lockstep) (#498) - @radix-ui/react-select ~2.2.6 -> ~2.3.0 (resolved 2.3.1) (#500) - @radix-ui/react-tooltip ~1.2.8 -> ~1.2.9 (resolved 1.2.10) (#502) - @radix-ui/react-popover ~1.1.15 -> ~1.1.16 (resolved 1.1.17) (#499) GitHub Actions (SHA-pinned): - astral-sh/setup-uv v7 -> v8.2.0 (#497) - ossf/scorecard-action v2.4.0 -> v2.4.3 (#496) - github/codeql-action v4 SHA bump (#495) Signed-off-by: SoundMindsAI <eric.starr@soundminds.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Superseded by #579, which consolidated all nine open |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github/codeql-action from 4.36.1 to 4.36.2.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
8aad20dMerge pull request #3949 from github/update-v4.36.2-dcb947ce1f521b08Add additional changelog notes8aeff0fUpdate changelog for v4.36.2dcb947cMerge pull request #3948 from github/update-bundle/codeql-bundle-v2.25.6c251bceAdd changelog note62953c1Update default bundle to codeql-bundle-v2.25.6423b570Merge pull request #3946 from github/dependabot/npm_and_yarn/npm-minor-5d507a...c35d1b1Merge pull request #3947 from github/dependabot/github_actions/dot-github/wor...cb1a588Merge pull request #3937 from github/robertbrignull/waitForProcessing_backoffba47406Merge pull request #3943 from github/henrymercer/cache-cli-version-infoDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)