From 7d0cfb2305f2c28822058e866e7e960bfc7fdf55 Mon Sep 17 00:00:00 2001 From: dirkjink Date: Fri, 2 Oct 2026 20:27:00 +0200 Subject: [PATCH] Group the codeql-action steps into one Dependabot PR Dependabot bumped init, analyze and upload-sarif in separate PRs (#69-#71); CodeQL rejects mixed step versions, so #70 and #71 each failed on their own. Same group as in limesium and legatium. Co-Authored-By: Claude Opus 5.5 --- .github/dependabot.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5203e1a..3d6a1ce 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -13,6 +13,14 @@ updates: directory: / schedule: interval: weekly + # One PR for every github/codeql-action step: CodeQL refuses a workflow + # whose init, analyze and upload-sarif steps run different versions + # ("Loaded a configuration file for version X, but running version Y"), + # so single-step bumps fail on their own (tabellarium #70/#71). + groups: + codeql-action: + patterns: + - github/codeql-action* # The hash-pinned documentation toolchain: pinning keeps a compromised # release out, Dependabot keeps the pin from going stale. - package-ecosystem: pip