Repository navigation
chore(deps): bump CodeQL actions to 4.38.1 - #3974
marcuswood-oai merged 4 commits into
Conversation
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.8 to 4.38.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...1c5b675) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Castiron custom code✅ No new custom-code files detected. 49 mixed files remain; 0 existing customizations changed. Compared 49 existing customizations unchanged
9 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 36919996122 --repo openai/openai-python \
--name castiron-custom-code-36919996122-1 --dir /tmp/castiron-custom-code-36919996122-1
git apply --stat /tmp/castiron-custom-code-36919996122-1/custom-code.patch
cat /tmp/castiron-custom-code-36919996122-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 10f88169b0f3929b4e2528aad7a825df31163156 5e501222d34aa882d989e820598f3e7441730d4d
python3 scripts/castiron/custom_code_report.py report \
--base 10f88169b0f3929b4e2528aad7a825df31163156 \
--head 5e501222d34aa882d989e820598f3e7441730d4d --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-5e501222d34a
cat /tmp/castiron-custom-code-5e501222d34a/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.8 to 4.38.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...1c5b675) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 20d07a5448
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 | ||
| uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 |
There was a problem hiding this comment.
Keep CodeQL init and analyze on the same revision
When the v4.38 per-language-bundle rollout reaches this repository, this job initializes CodeQL with v4.38.1 but still analyzes with v4.37.8 on line 38. The preceding paired update (f95237f) explicitly records that these steps share versioned state, so the older analyze action may not consume the initialization or bundle state produced by this version and can cause CodeQL analysis to fail; update analyze to the same reviewed v4.38.1 SHA.
Useful? React with 👍 / 👎.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Automated Release PR --- ## [3.23.0](openai/openai-python@v3.22.1...v3.23.0) (2026-10-01) ### Features * **agents:** [1/n] return typed answers from session streams ([openai#4007](openai#4007)) ([10f8816](openai@10f8816)) * **agents:** stage files and download turn artifacts ([openai#4009](openai#4009)) ([4fc2438](openai@4fc2438)) * **api:** Add session traces and Realtime translations ([openai#4001](openai#4001)) ([138e3d1](openai@138e3d1)) * **beta:** expose typed application actions as agent tools ([openai#4006](openai#4006)) ([f219c55](openai@f219c55)) * collect final output from beta Agents streams ([157ac4c](openai@157ac4c)) ### Bug Fixes * **api:** allow original image detail in Chat Completions ([openai#4005](openai#4005)) ([8a136c2](openai@8a136c2)) * **api:** correct the eval run cancellation endpoint ([openai#4003](openai#4003)) ([28c5c9a](openai@28c5c9a)) * **api:** retain WebSocket endpoint paths and query parameters ([openai#3999](openai#3999)) ([7f203fd](openai@7f203fd)) * keep Castiron budget results valid when main advances ([openai#4012](openai#4012)) ([73f189b](openai@73f189b)) * **responses:** avoid replaying uncertain typed sends on reconnect ([openai#4011](openai#4011)) ([1dbbf61](openai@1dbbf61)) * **responses:** respect send queue limits during reconnect ([openai#4000](openai#4000)) ([50f95ac](openai@50f95ac)) * use monotonic clock for file processing timeout ([openai#3748](openai#3748)) ([58aca1d](openai@58aca1d)) ### Chores * **api:** retain WebRTC Live session transport types ([openai#4002](openai#4002)) ([5c9ace9](openai@5c9ace9)) * **deps-dev:** bump pyright from 1.1.413 to 1.1.414 ([openai#3902](openai#3902)) ([a91d779](openai@a91d779)) * **deps:** bump astral-sh/setup-uv from 10.0.1 to 10.1.0 ([openai#3976](openai#3976)) ([f15f43c](openai@f15f43c)) * **deps:** bump CodeQL actions to 4.38.1 ([openai#3974](openai#3974)) ([fb70d66](openai@fb70d66)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Update CodeQL
initandanalyzetogether from 4.37.8 to 4.38.1, pinned to the same official release commit. The actions share versioned state and must remain aligned.Includes the matching update from #3975. No workflow permissions or SDK runtime code change; refreshed against current main.