chaoss / chaoss/CollectOSS

Bump codeql SARIF upload Ci dependency to v4

Open Beginner friendly
#349 0 comments 0 reactions 0 assignees View on GitHub
dependencies devops good first issue
Dominant language
Python
Stars
13
Forks
17
Avg merge
6h 59m
Merged PRs (30d)
1

Description

https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/

We are using this in the bandit scan CI job. itll be deprecated in december

Contributor guide

Open the contributing guide

Research direction

Locate the workflow containing the bandit scan CI job and inspect its CodeQL SARIF upload action. Update that action to v4, then run or inspect the relevant CI workflow to confirm the bandit scan still uploads SARIF successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.