From 247baf291c23f98c13c45cc5de3ddbf71227c3f5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 24 Sep 2026 09:16:07 +0000 Subject: [PATCH 1/2] Bump the actions group with 2 updates Bumps the actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3394928..85f4047 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -153,7 +153,7 @@ jobs: if: matrix.language == 'csharp' with: global-json-file: global.json - - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4 + - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -162,7 +162,7 @@ jobs: run: | dotnet restore ArcNotes.slnx --locked-mode dotnet build ArcNotes.slnx -c Release --no-restore -p:UseSharedCompilation=false - - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4 + - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 with: category: /language:${{ matrix.language }} From f0d6cc5ed7ecd082e2a4308f8e9aae55226a556d Mon Sep 17 00:00:00 2001 From: sammiller Date: Sat, 26 Sep 2026 12:36:27 +0800 Subject: [PATCH 2/2] Record the reviewed CodeQL action update Reseal eng/policy/dependency-review.json for github/codeql-action init/analyze 4.38.0 -> 4.38.1 (annotated tag v4.38.1 = 1c5b675653bb5c22dbe9b12b556ec555138e09fd) Co-Authored-By: Claude Opus 5.5 --- eng/policy/dependency-review.json | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/eng/policy/dependency-review.json b/eng/policy/dependency-review.json index 3bb23cf..28ab167 100644 --- a/eng/policy/dependency-review.json +++ b/eng/policy/dependency-review.json @@ -2,7 +2,7 @@ "schemaVersion": 1, "owner": "ArcNotes", "decision": "approved", - "reviewedOn": "2026-09-21", + "reviewedOn": "2026-09-26", "baselineCommit": "2dee20b0c1d9acaf3d83b20dfd045e1e070e082c", "baselineFrameworkVersions": { "dotnet": "10.0.401", @@ -11,18 +11,18 @@ "frameworkMajorUpgrade": false, "runtimePostureAssessment": "No framework version changes: existing desktop Native AOT and trim posture retained.", "checks": { - "compilation": "Retain required Windows/Linux compilation in the existing CI graph.", - "aot": "Retain Windows x64/ARM64 and Linux x64 AOT publication; no runtime graph changed.", - "compatibility": "No package versions, APIs or generated public contracts changed; prior WP02 stage evidence retained.", - "licence": "Complete locked closure and published cached metadata reviewed; existing source/native notices and provenance gates retained.", - "security": "Existing dependency-review and CodeQL gates remain required; no duplicated scanner or vulnerability-free assertion.", - "sbom": "Existing portable dependencies.json is generated from actual restore assets; no distributed closure changed.", - "localRuntime": "Not run: dependency policy tooling changes do not affect application runtime behavior.", + "compilation": "Workflow-only update: github/codeql-action init/analyze 4.38.0 -> 4.38.1 (Dependabot actions group). Required Windows/Linux compilation runs unchanged in CI.", + "aot": "No project, package or publish input changed; existing Windows x64/ARM64 and Linux x64 AOT publication jobs are unchanged.", + "compatibility": "Patch release within CodeQL action v4 with the same inputs and outputs; no package versions, APIs or generated contracts changed.", + "licence": "GitHub-owned action pinned to the immutable commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd of annotated tag v4.38.1; no distributed closure or notice changed.", + "security": "Immutable SHA pin retained; CodeQL and dependency-review gates stay required; no vulnerability-absence claim.", + "sbom": "No restore closure change; the portable dependencies.json SBOM is unaffected.", + "localRuntime": "Not run: CI-only workflow action update; no application runtime behavior changed.", "performance": "Not applicable: no runtime dependency, executable behavior or performance-sensitive algorithm changed.", "migration": "Not applicable: no persistence format or storage dependency changed." }, "inputs": { - ".github/workflows/ci.yml": "ec5963a454ab794847a07fd4360fd1708b3aef44385b4eeafd3d0137366ec1ab", + ".github/workflows/ci.yml": "a7a84aabb9441717b25c2f88328168ce3d6b8772f3249f2f22cf96df08307f2c", "Directory.Build.props": "90a5954ec7685904894ef8d19fea650f9bcebabbde98b0b94058f8b7c68fb5a4", "Directory.Build.targets": "21da49619dc407ca9de526c9aa75cb9a0e67ca6314bddd4770dd165975405bd4", "Directory.Packages.props": "ef826d5a6865882ae44e02c03a21e2d94e3146a2027a22bdbc6a558aac260321",