Skip to content

chore(deps): bump the codeql group with 2 updates - #820

Merged
jbeckwith-oai merged 1 commit into
mainfrom
dependabot/github_actions/codeql-9159e49961
Oct 9, 2026
Merged

jbeckwith-oai merged 1 commit into
mainfrom
dependabot/github_actions/codeql-9159e49961

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the codeql group with 2 updates: github/codeql-action/init and github/codeql-action/analyze.

Updates github/codeql-action/init from 4.38.2 to 4.38.3

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.3

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188
  • Update default CodeQL bundle version to 2.27.2. #4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #4184
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.3 - 08 Oct 2026

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188
  • Update default CodeQL bundle version to 2.27.2. #4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #4184

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

... (truncated)

Commits
  • 24c5418 Merge pull request #4214 from github/update-v4.38.3-e0b52dbdc
  • 69e87c5 Add changelog note for #4184
  • 23b6828 Update changelog for v4.38.3
  • e0b52db Merge pull request #4210 from github/henrymercer/pin-python-for-older-clis-in-ci
  • 6b99698 Pin Python 3.13.15 for older CLI versions in multi-language check
  • 63d3d63 Merge pull request #4203 from github/update-bundle/codeql-bundle-v2.27.2
  • 7377a10 Add changelog note
  • c1a30cd Update default bundle to codeql-bundle-v2.27.2
  • d208ec7 Merge pull request #4200 from github/mbg/esm/migrate-pr-checks
  • a71b0c6 Replace __dirname in sync.ts
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.2 to 4.38.3

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.3

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188
  • Update default CodeQL bundle version to 2.27.2. #4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #4184
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.3 - 08 Oct 2026

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188
  • Update default CodeQL bundle version to 2.27.2. #4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #4184

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

... (truncated)

Commits
  • 24c5418 Merge pull request #4214 from github/update-v4.38.3-e0b52dbdc
  • 69e87c5 Add changelog note for #4184
  • 23b6828 Update changelog for v4.38.3
  • e0b52db Merge pull request #4210 from github/henrymercer/pin-python-for-older-clis-in-ci
  • 6b99698 Pin Python 3.13.15 for older CLI versions in multi-language check
  • 63d3d63 Merge pull request #4203 from github/update-bundle/codeql-bundle-v2.27.2
  • 7377a10 Add changelog note
  • c1a30cd Update default bundle to codeql-bundle-v2.27.2
  • d208ec7 Merge pull request #4200 from github/mbg/esm/migrate-pr-checks
  • a71b0c6 Replace __dirname in sync.ts
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the codeql group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.38.2 to 4.38.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@2892aa5...24c5418)

Updates `github/codeql-action/analyze` from 4.38.2 to 4.38.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@2892aa5...24c5418)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 09:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 9, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T09:38:26.132701Z c6dc3d5 PR opened
🔒 Security Review ✅ Completed 2026-10-09T09:39:45.789829Z c6dc3d5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 5.657s for Ruby SDK PR #820.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 59ms
tests/chat-completions-create.test.ts ✅ Passed 67ms
tests/chat-completions-stream.test.ts ✅ Passed 64ms
tests/files-content-binary.test.ts ✅ Passed 67ms
tests/files-create-multipart.test.ts ✅ Passed 94ms
tests/files-list-pagination.test.ts ✅ Passed 84ms
tests/initialize-config.test.ts ✅ Passed 59ms
tests/instance-isolation.test.ts ✅ Passed 56ms
tests/models-list.test.ts ✅ Passed 98ms
tests/responses-background-lifecycle.test.ts ✅ Passed 63ms
tests/responses-body-method-errors.test.ts ✅ Passed 243ms
tests/responses-cancel-timeout.test.ts ✅ Passed 194ms
tests/responses-cancel.test.ts ✅ Passed 92ms
tests/responses-compact-retries.test.ts ✅ Passed 122ms
tests/responses-compact.test.ts ✅ Passed 69ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 104ms
tests/responses-create-advanced.test.ts ✅ Passed 71ms
tests/responses-create-disconnect.test.ts ✅ Passed 73ms
tests/responses-create-errors.test.ts ✅ Passed 224ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 82ms
tests/responses-create-retries.test.ts ✅ Passed 82ms
tests/responses-create-stream-failures.test.ts ✅ Passed 75ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 211ms
tests/responses-create-stream-wire.test.ts ✅ Passed 1.323s
tests/responses-create-stream.test.ts ✅ Passed 56ms
tests/responses-create-terminal-states.test.ts ✅ Passed 135ms
tests/responses-create-timeout.test.ts ✅ Passed 177ms
tests/responses-create.test.ts ✅ Passed 68ms
tests/responses-delete.test.ts ✅ Passed 85ms
tests/responses-input-items-errors.test.ts ✅ Passed 120ms
tests/responses-input-items-list.test.ts ✅ Passed 87ms
tests/responses-input-items-options.test.ts ✅ Passed 95ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 199ms
tests/responses-input-tokens-count.test.ts ✅ Passed 96ms
tests/responses-malformed-inputs.test.ts ✅ Passed 1.339s
tests/responses-not-found-errors.test.ts ✅ Passed 236ms
tests/responses-parse.test.ts ✅ Passed 65ms
tests/responses-retrieve-retries.test.ts ✅ Passed 76ms
tests/responses-retrieve.test.ts ✅ Passed 82ms
tests/responses-stored-method-errors.test.ts ✅ Passed 341ms
tests/retry-behavior.test.ts ✅ Passed 2.892s
tests/sdk-error-shape.test.ts ✅ Passed 265ms

View OkTest run #37912472049

SDK merge (1c83e7b149ad) · head (c6dc3d56c885) · base (a9e80153b030) · OkTest (505ac0e34283)

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: a9e80153b030395eca41bf4c6cce0b1e7fcea4dd.

✅ No new custom-code files detected.

84 mixed files remain; 0 existing customizations changed.

Compared a9e80153b030 → c6dc3d56c885. Generated baselines verified.

84 existing customizations unchanged
  • lib/openai.rb
  • lib/openai/client.rb
  • lib/openai/models/audio/transcription_create_response.rb
  • lib/openai/models/audio/translation_create_response.rb
  • lib/openai/models/audio/voice_create_params.rb
  • lib/openai/models/beta/agents/vault_status_filter.rb
  • lib/openai/models/chat/chat_completion_message.rb
  • lib/openai/models/chat/chat_completion_message_function_tool_call.rb
  • lib/openai/models/chat/completion_create_params.rb
  • lib/openai/models/image_edit_completed_event.rb
  • lib/openai/models/image_edit_partial_image_event.rb
  • lib/openai/models/image_gen_completed_event.rb
  • lib/openai/models/image_gen_partial_image_event.rb
  • lib/openai/models/images_response.rb
  • lib/openai/models/response_format_json_schema.rb
  • lib/openai/models/responses/function_tool.rb
  • lib/openai/models/responses/response.rb
  • lib/openai/models/responses/response_create_params.rb
  • lib/openai/models/responses/response_format_text_config.rb
  • lib/openai/models/responses/response_format_text_json_schema_config.rb
  • lib/openai/models/responses/response_function_tool_call.rb
  • lib/openai/models/responses/response_function_web_search.rb
  • lib/openai/models/responses/response_output_text.rb
  • lib/openai/models/responses/tool.rb
  • lib/openai/models/webhooks/webhook_endpoint_with_secret.rb
  • lib/openai/resources/audio/transcriptions.rb
  • lib/openai/resources/audio/translations.rb
  • lib/openai/resources/beta/agents/environments/files.rb
  • lib/openai/resources/beta/agents/sessions.rb
  • lib/openai/resources/beta/agents/sessions/artifacts.rb
  • lib/openai/resources/beta/threads.rb
  • lib/openai/resources/chat/completions.rb
  • lib/openai/resources/containers/files.rb
  • lib/openai/resources/files.rb
  • lib/openai/resources/responses.rb
  • lib/openai/resources/vector_stores/file_batches.rb
  • lib/openai/resources/vector_stores/files.rb
  • lib/openai/resources/webhooks.rb
  • rbi/openai/client.rbi
  • rbi/openai/models/audio/transcription_create_response.rbi

44 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37912531303 --repo openai/openai-ruby \
  --name castiron-custom-code-37912531303-1 --dir /tmp/castiron-custom-code-37912531303-1
git apply --stat /tmp/castiron-custom-code-37912531303-1/custom-code.patch
cat /tmp/castiron-custom-code-37912531303-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin a9e80153b030395eca41bf4c6cce0b1e7fcea4dd c6dc3d56c88538f8f5693b96d4e7ed6689e4b5b5
python3 scripts/castiron/custom_code_report.py report \
  --base a9e80153b030395eca41bf4c6cce0b1e7fcea4dd \
  --head c6dc3d56c88538f8f5693b96d4e7ed6689e4b5b5 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-c6dc3d56c885
cat /tmp/castiron-custom-code-c6dc3d56c885/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@jbeckwith-oai
jbeckwith-oai added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 6217f7a Oct 9, 2026
17 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the dependabot/github_actions/codeql-9159e49961 branch October 9, 2026 20:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant