You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Correct misleading version annotations on an already pinned CodeQL action. This is comment-only maintenance: it neither upgrades nor downgrades CodeQL and does not change any workflow permissions, trigger, step, matrix or executable content.
The official github/codeql-action annotated tag v4.37.9 points through tag object a35ac6e6798d72df5475948b28efb89edc2e19ca to commit cdf488f595d80d6e07e03d4674febd5ab45fa938. Current ByteFolk templates and consumers label that exact SHA as v4.37.4.
Scope and acceptance
REQ-001 / AC-001: Change only exact uses: github/codeql-action/{init,autobuild,analyze,upload-sarif}@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.4 annotations to # v4.37.9.
REQ-002 / AC-002: Cover .github, digital-employee, mem, doc, roleweave, design-system, and digital-employee-quickstart: 21 annotations across 13 current files. Historical snapshots and other action pins are out of scope.
REQ-003 / AC-003: Parsed YAML and comment-stripped bytes must be identical before and after. File mode, action SHA, permissions and all executable behavior remain unchanged. Each repository receives a separately reviewable PR; no changes are mixed into unrelated feature PRs.
REQ-004 / AC-004: Pass applicable current-head checks and independent review before ordinary protected merge. Missing pre-existing gates are not bypassed. Merge is distinct from product acceptance and release.
Maintenance record
Revision: R1
Status: ready for the bounded annotation correction
Current maintainer instruction authorizes resolving the reported review findings. Local comment-only candidates were prepared and checked before this tracking record; this is not a claim of retrospective review or prior Issue approval.
Validation and rollback
Official GitHub tag metadata was read directly. A replayable verifier checks the exact changed-file allowlist, old blob/line inventory, full expected byte replacement, parsed YAML equality, comment-stripped byte equality, unchanged modes, single-parent commits and clean worktrees. Independent replay passed for all 7 repositories / 13 files / 21 lines. Runtime test results are not inferred from comment equivalence; hosted checks remain separate.
Rollback is a normal revert of the annotation-only commit. No release, tag, account/permission change, branch deletion, force push or protection bypass is requested.
Outcome
Correct misleading version annotations on an already pinned CodeQL action. This is comment-only maintenance: it neither upgrades nor downgrades CodeQL and does not change any workflow permissions, trigger, step, matrix or executable content.
The official
github/codeql-actionannotated tagv4.37.9points through tag objecta35ac6e6798d72df5475948b28efb89edc2e19cato commitcdf488f595d80d6e07e03d4674febd5ab45fa938. Current ByteFolk templates and consumers label that exact SHA asv4.37.4.Scope and acceptance
uses: github/codeql-action/{init,autobuild,analyze,upload-sarif}@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.4annotations to# v4.37.9..github,digital-employee,mem,doc,roleweave,design-system, anddigital-employee-quickstart: 21 annotations across 13 current files. Historical snapshots and other action pins are out of scope.Maintenance record
Validation and rollback
Official GitHub tag metadata was read directly. A replayable verifier checks the exact changed-file allowlist, old blob/line inventory, full expected byte replacement, parsed YAML equality, comment-stripped byte equality, unchanged modes, single-parent commits and clean worktrees. Independent replay passed for all 7 repositories / 13 files / 21 lines. Runtime test results are not inferred from comment equivalence; hosted checks remain separate.
Rollback is a normal revert of the annotation-only commit. No release, tag, account/permission change, branch deletion, force push or protection bypass is requested.