Skip to content

chore(deps): bump github/codeql-action from 4.37.4 to 4.37.8 - #33

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-4.37.8
Closed

chore(deps): bump github/codeql-action from 4.37.4 to 4.37.8#33
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-4.37.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps github/codeql-action from 4.37.4 to 4.37.8.

Release notes

Sourced from github/codeql-action's releases.

v4.37.8

No user facing changes.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085

v4.37.6

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

v4.37.5

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061
Changelog

Sourced from github/codeql-action's changelog.

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061
Commits
  • db488dd Merge pull request #4102 from github/update-v4.37.8-9ee088e13
  • 1845f5b Update changelog for v4.37.8
  • 9ee088e Merge pull request #4080 from github/henrymercer/studious-giggle
  • 1aef003 Address review feedback on overlay disk flags
  • 508b83b Merge main into overlay minimum disk feature branch
  • d97b342 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
  • 47fa622 Make EACCES a ConfigurationError
  • 45693cc Refactor ENOSPC check into isDiskConfigurationError function
  • c2fd8f5 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
  • c56f48e Log unexpected conditions during caching CLI output
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.4 to 4.37.8.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.4...v4.37.8)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@safenestdev

Copy link
Copy Markdown
Contributor

Superseded by #34, which bundles this bump together with the other open dependabot PRs and fixes the CI failure caused by TS7's removal of moduleResolution: node10.

@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/github/codeql-action-4.37.8 branch August 24, 2026 13:03
safenestdev added a commit that referenced this pull request Aug 24, 2026
…script, codeql-action (#34)

Bundles the 4 currently-open dependabot PRs (#30-#33) into one tested
change rather than merging them separately:
  - vitest 4.1.10 -> 4.1.11
  - @types/node 25.9.1 -> 26.2.0
  - typescript 6.0.3 -> 7.0.2
  - github/codeql-action 4.37.4 -> 4.37.8 (workflow-only)

The typescript bump (#32) was failing CI (lint + test 22.x) because
TS 7 removed the `node10` moduleResolution value outright (TS5108).
tsconfig.cjs.json used `"moduleResolution": "node10"` for the CJS
build with `"ignoreDeprecations": "6.0"` silencing the prior
deprecation warning -- TS7 doesn't accept the ignoreDeprecations
escape hatch for a removed option, it's just a hard error now.
Switched to `"moduleResolution": "Bundler"`, which is TS's own
default for a CommonJS module target when the base config's `module`
isn't node16/node18/nodenext (base tsconfig.json uses Node16 for the
ESM build), so this restores the previous effective resolution
behavior rather than changing it.

The other three bumps had no code-visible impact; build, full test
suite, and npm audit all pass unchanged.

Found and left alone (pre-existing, not caused by this bump, not
blocking): dist/cjs/*.js has no dist/cjs/package.json declaring
`"type": "commonjs"`, so under the root package.json's `"type":
"module"`, a plain `require()` against dist/cjs/index.js fails --
confirmed this reproduces identically on typescript@6.0.3 before this
bump. Worth its own fix; not touched here since it's orthogonal to a
dependency-version PR.

Co-authored-by: safenestdev <safenestdev@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant