Skip to content

chore(ci): correct CodeQL pinned-version annotations #32

Description

@PeterGuy326

Outcome

Correct misleading version annotations on an already pinned CodeQL action. This is comment-only maintenance: it neither upgrades nor downgrades CodeQL and does not change any workflow permissions, trigger, step, matrix or executable content.

The official github/codeql-action annotated tag v4.37.9 points through tag object a35ac6e6798d72df5475948b28efb89edc2e19ca to commit cdf488f595d80d6e07e03d4674febd5ab45fa938. Current ByteFolk templates and consumers label that exact SHA as v4.37.4.

Scope and acceptance

  • REQ-001 / AC-001: Change only exact uses: github/codeql-action/{init,autobuild,analyze,upload-sarif}@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.4 annotations to # v4.37.9.
  • REQ-002 / AC-002: Cover .github, digital-employee, mem, doc, roleweave, design-system, and digital-employee-quickstart: 21 annotations across 13 current files. Historical snapshots and other action pins are out of scope.
  • REQ-003 / AC-003: Parsed YAML and comment-stripped bytes must be identical before and after. File mode, action SHA, permissions and all executable behavior remain unchanged. Each repository receives a separately reviewable PR; no changes are mixed into unrelated feature PRs.
  • REQ-004 / AC-004: Pass applicable current-head checks and independent review before ordinary protected merge. Missing pre-existing gates are not bypassed. Merge is distinct from product acceptance and release.

Maintenance record

  • Revision: R1
  • Status: ready for the bounded annotation correction
  • Implementation/publication owner: @PeterGuy326
  • Independent review: required; human approval is not implied by this record
  • Source provenance: organization security baseline ci: adopt free security baseline and local data boundary #26 and merged ci: add free security baseline (#26) #27
  • Current maintainer instruction authorizes resolving the reported review findings. Local comment-only candidates were prepared and checked before this tracking record; this is not a claim of retrospective review or prior Issue approval.

Validation and rollback

Official GitHub tag metadata was read directly. A replayable verifier checks the exact changed-file allowlist, old blob/line inventory, full expected byte replacement, parsed YAML equality, comment-stripped byte equality, unchanged modes, single-parent commits and clean worktrees. Independent replay passed for all 7 repositories / 13 files / 21 lines. Runtime test results are not inferred from comment equivalence; hosted checks remain separate.

Rollback is a normal revert of the annotation-only commit. No release, tag, account/permission change, branch deletion, force push or protection bypass is requested.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions