Skip to content

Resolve merge conflict on PR #836 (pin GitHub Actions to full-length SHAs) - #841

Closed
muracle1 with Copilot wants to merge 3 commits into
mainfrom
copilot/pr-836-resolve-merge-conflict
Closed

muracle1 with Copilot wants to merge 3 commits into
mainfrom
copilot/pr-836-resolve-merge-conflict

Conversation

Copilot AI commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

PR #836 had a merge conflict against main after a dependabot bump (#840) advanced github/codeql-action to v4.38.0 using a mutable tag, while #836 pinned the prior v4.37.8 to a commit SHA.

  • Conflict resolution: In .github/workflows/codeql.yml, kept main's newer v4.38.0 version but pinned it to its full commit SHA, preserving ci: Pin GitHub Actions to full-length commit SHAs #836's security intent without reverting the version bump:
    uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
  • Clean merges: .github/dependabot.yml (cooldown config) and .github/workflows/code-review.yml (checkout SHA pin) merged without conflicts; no unrelated upstream changes were touched.
  • Validation: confirmed all .github/workflows/*.yml and .github/dependabot.yml remain valid YAML, and no uses: reference in the touched files was left on a mutable tag.

…-resolve-merge-conflict

# Conflicts:
#	.github/workflows/codeql.yml

Co-authored-by: muracle1 <257836065+muracle1@users.noreply.github.com>
@muracle1
muracle1 marked this pull request as ready for review September 16, 2026 14:19
@muracle1
muracle1 requested a review from a team as a code owner September 16, 2026 14:19
Copilot AI lite review requested due to automatic review settings September 16, 2026 14:19
@muracle1 muracle1 closed this Sep 16, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review comments remain.

Pull request overview

Resolves the merge conflict while preserving CodeQL v4.38.0 and immutable GitHub Actions pinning.

Changes:

  • Pins CodeQL and checkout actions to full-length SHAs.
  • Corrects the checkout version annotation.
  • Adds a 7-day Dependabot cooldown.
File summaries
File Description
.github/workflows/codeql.yml Pins checkout and CodeQL actions.
.github/workflows/code-review.yml Corrects the checkout SHA annotation.
.github/dependabot.yml Adds a 7-day action update cooldown.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants