Skip to content

chore(deps): update github/codeql-action action to v4.32.2#444

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/github-codeql-action-4.x
Feb 5, 2026
Merged

chore(deps): update github/codeql-action action to v4.32.2#444
renovate[bot] merged 1 commit intomainfrom
renovate/github-codeql-action-4.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 5, 2026

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v4.32.1v4.32.2

Release Notes

github/codeql-action (github/codeql-action)

v4.32.2

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge February 5, 2026 18:58
@renovate renovate bot merged commit d8e2e11 into main Feb 5, 2026
11 of 13 checks passed
@renovate renovate bot deleted the renovate/github-codeql-action-4.x branch February 5, 2026 18:58
@entelligence-ai-pr-reviews
Copy link

Walkthrough

This PR updates the CodeQL GitHub Action dependency from version v4.32.1 to v4.32.2 across multiple workflow files. The update affects security analysis and scanning workflows, specifically the CodeQL initialization and analysis steps, as well as the Trivy security scan results upload step. The commit SHA references are updated from 6bc82e05fd0ea64601dd4b465378bbcf57de0314 to 45cbd0c69e560cd9e7cd7f8c32362050c9b7ded2. This is a routine maintenance update to incorporate the latest bug fixes and minor improvements in the CodeQL action, with no functional changes to workflow configurations or analysis parameters.

Changes

File(s) Summary
.github/workflows/codeql.yml
.github/workflows/docker.yml
Updated CodeQL GitHub Action from version v4.32.1 to v4.32.2, changing commit SHA from 6bc82e05fd0ea64601dd4b465378bbcf57de0314 to 45cbd0c69e560cd9e7cd7f8c32362050c9b7ded2 across CodeQL initialization, analysis, and SARIF upload steps.

Sequence Diagram

This diagram shows the interactions between components:

sequenceDiagram
    participant Workflow as GitHub Workflow
    participant PNPM as Package Manager
    participant CodeQLInit as CodeQL Init Action v4.32.2
    participant CodeQLAnalyze as CodeQL Analyze Action v4.32.2
    
    Note over Workflow,CodeQLAnalyze: CodeQL Security Scanning Pipeline
    
    Workflow->>PNPM: pnpm install --frozen-lockfile
    activate PNPM
    PNPM-->>Workflow: Dependencies installed
    deactivate PNPM
    
    Workflow->>CodeQLInit: Initialize CodeQL
    activate CodeQLInit
    Note right of CodeQLInit: Configuration:<br/>- languages: matrix.language<br/>- build-mode: matrix.build-mode
    CodeQLInit-->>Workflow: CodeQL initialized
    deactivate CodeQLInit
    
    Note over Workflow: Build/compile steps occur<br/>(excluding test files)
    
    Workflow->>CodeQLAnalyze: Perform CodeQL Analysis
    activate CodeQLAnalyze
    Note right of CodeQLAnalyze: Configuration:<br/>- category: /language:matrix.language<br/>- add-snippets: true
    CodeQLAnalyze-->>Workflow: Analysis complete
    deactivate CodeQLAnalyze
    
    Note over Workflow,CodeQLAnalyze: Version Update: v4.32.1 → v4.32.2
Loading

🔗 Cross-Repository Impact Analysis

Enable automatic detection of breaking changes across your dependent repositories. → Set up now

Learn more about Cross-Repository Analysis

What It Does

  • Automatically identifies repositories that depend on this code
  • Analyzes potential breaking changes across your entire codebase
  • Provides risk assessment before merging to prevent cross-repo issues

How to Enable

  1. Visit Settings → Code Management
  2. Configure repository dependencies
  3. Future PRs will automatically include cross-repo impact analysis!

Benefits

  • 🛡️ Prevent breaking changes across repositories
  • 🔍 Catch integration issues before they reach production
  • 📊 Better visibility into your multi-repo architecture

▶️AI Code Reviews for VS Code, Cursor, Windsurf
Install the extension

Note for Windsurf Please change the default marketplace provider to the following in the windsurf settings:

Marketplace Extension Gallery Service URL: https://marketplace.visualstudio.com/_apis/public/gallery

Marketplace Gallery Item URL: https://marketplace.visualstudio.com/items

Entelligence.ai can learn from your feedback. Simply add 👍 / 👎 emojis to teach it your preferences. More shortcuts below

Emoji Descriptions:

  • ⚠️ Potential Issue - May require further investigation.
  • 🔒 Security Vulnerability - Fix to ensure system safety.
  • 💻 Code Improvement - Suggestions to enhance code quality.
  • 🔨 Refactor Suggestion - Recommendations for restructuring code.
  • ℹ️ Others - General comments and information.

Interact with the Bot:

  • Send a message or request using the format:
    @entelligenceai + *your message*
Example: @entelligenceai Can you suggest improvements for this code?
  • Help the Bot learn by providing feedback on its responses.
    @entelligenceai + *feedback*
Example: @entelligenceai Do not comment on `save_auth` function !

Also you can trigger various commands with the bot by doing
@entelligenceai command

The current supported commands are

  1. config - shows the current config
  2. retrigger_review - retriggers the review

More commands to be added soon.

@codecov
Copy link

codecov bot commented Feb 5, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.41%. Comparing base (df7fc75) to head (3272bfa).
⚠️ Report is 51 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main     #444   +/-   ##
=======================================
  Coverage   92.41%   92.41%           
=======================================
  Files          15       15           
  Lines         725      725           
=======================================
  Hits          670      670           
  Misses         46       46           
  Partials        9        9           
Flag Coverage Δ
backend 92.41% <ø> (ø)
integration 92.41% <ø> (ø)
unittests 90.06% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update df7fc75...3272bfa. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions github-actions bot added the released:v1.2.0 Released in v1.2.0 label Feb 22, 2026
@github-actions
Copy link
Contributor

Released in v1.2.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released:v1.2.0 Released in v1.2.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants