Skip to content

chore(deps): bump CodeQL actions to 4.38.1 - #3974

Merged
marcuswood-oai merged 4 commits into
mainfrom
dependabot/github_actions/github/codeql-action/init-4.38.1
Oct 1, 2026
Merged

marcuswood-oai merged 4 commits into
mainfrom
dependabot/github_actions/github/codeql-action/init-4.38.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Update CodeQL init and analyze together from 4.37.8 to 4.38.1, pinned to the same official release commit. The actions share versioned state and must remain aligned.

Includes the matching update from #3975. No workflow permissions or SDK runtime code change; refreshed against current main.

Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.8 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@db488dd...1c5b675)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 28, 2026 09:36
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@openai-sdks

openai-sdks Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 11.862s for Python SDK PR #3974.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 181ms
tests/chat-completions-create.test.ts ✅ Passed 244ms
tests/chat-completions-stream.test.ts ✅ Passed 316ms
tests/files-content-binary.test.ts ✅ Passed 202ms
tests/files-create-multipart.test.ts ✅ Passed 193ms
tests/files-list-pagination.test.ts ✅ Passed 276ms
tests/initialize-config.test.ts ✅ Passed 159ms
tests/instance-isolation.test.ts ✅ Passed 175ms
tests/models-list.test.ts ✅ Passed 257ms
tests/responses-background-lifecycle.test.ts ✅ Passed 230ms
tests/responses-body-method-errors.test.ts ✅ Passed 388ms
tests/responses-cancel-timeout.test.ts ✅ Passed 240ms
tests/responses-cancel.test.ts ✅ Passed 176ms
tests/responses-compact-retries.test.ts ✅ Passed 324ms
tests/responses-compact.test.ts ✅ Passed 235ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 164ms
tests/responses-create-advanced.test.ts ✅ Passed 224ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.228s
tests/responses-create-errors.test.ts ✅ Passed 172ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 227ms
tests/responses-create-retries.test.ts ✅ Passed 244ms
tests/responses-create-stream-failures.test.ts ✅ Passed 828ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 256ms
tests/responses-create-stream-wire.test.ts ✅ Passed 3.502s
tests/responses-create-stream.test.ts ✅ Passed 275ms
tests/responses-create-terminal-states.test.ts ✅ Passed 261ms
tests/responses-create-timeout.test.ts ✅ Passed 235ms
tests/responses-create.test.ts ✅ Passed 545ms
tests/responses-delete.test.ts ✅ Passed 197ms
tests/responses-input-items-errors.test.ts ✅ Passed 429ms
tests/responses-input-items-list.test.ts ✅ Passed 346ms
tests/responses-input-items-options.test.ts ✅ Passed 278ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 276ms
tests/responses-input-tokens-count.test.ts ✅ Passed 197ms
tests/responses-malformed-inputs.test.ts ✅ Passed 2.549s
tests/responses-not-found-errors.test.ts ✅ Passed 393ms
tests/responses-parse.test.ts ✅ Passed 228ms
tests/responses-retrieve-retries.test.ts ✅ Passed 221ms
tests/responses-retrieve.test.ts ✅ Passed 199ms
tests/responses-stored-method-errors.test.ts ✅ Passed 864ms
tests/retry-behavior.test.ts ✅ Passed 3.209s
tests/sdk-error-shape.test.ts ✅ Passed 354ms

View OkTest run #36919479958

SDK merge (61bbaef10913) · head (5e501222d34a) · base (10f88169b0f3) · OkTest (e7cf6535e0ca)

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

49 mixed files remain; 0 existing customizations changed.

Compared 10f88169b0f3 → 5e501222d34a. Generated baselines verified.

49 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/openai/init.py
  • src/openai/_client.py
  • src/openai/resources/audio/transcriptions.py
  • src/openai/resources/audio/translations.py
  • src/openai/resources/beta/agents/sessions/sessions.py
  • src/openai/resources/beta/beta.py
  • src/openai/resources/beta/responses/responses.py
  • src/openai/resources/beta/threads/runs/runs.py
  • src/openai/resources/beta/threads/threads.py
  • src/openai/resources/chat/completions/completions.py
  • src/openai/resources/embeddings.py
  • src/openai/resources/files.py
  • src/openai/resources/live/forks.py
  • src/openai/resources/live/live.py
  • src/openai/resources/live/sideband.py
  • src/openai/resources/realtime/api.md
  • src/openai/resources/realtime/realtime.py
  • src/openai/resources/responses/responses.py
  • src/openai/resources/uploads/uploads.py
  • src/openai/resources/vector_stores/file_batches.py
  • src/openai/resources/vector_stores/files.py
  • src/openai/resources/videos.py
  • src/openai/resources/webhooks/init.py
  • src/openai/resources/webhooks/webhooks.py
  • src/openai/types/beta/agent_session_message.py
  • src/openai/types/beta/session_turn_error.py
  • src/openai/types/chat/init.py
  • src/openai/types/chat/chat_completion_message_tool_call.py
  • src/openai/types/fine_tuning/fine_tuning_job_integration.py
  • src/openai/types/realtime/conversation_item_input_audio_transcription_delta_event.py
  • src/openai/types/realtime/realtime_error_event.py
  • src/openai/types/responses/init.py
  • src/openai/types/responses/response.py
  • src/openai/types/responses/response_function_web_search.py
  • src/openai/types/responses/response_function_web_search_param.py
  • src/openai/types/responses/responses_client_event.py

9 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 36919996122 --repo openai/openai-python \
  --name castiron-custom-code-36919996122-1 --dir /tmp/castiron-custom-code-36919996122-1
git apply --stat /tmp/castiron-custom-code-36919996122-1/custom-code.patch
cat /tmp/castiron-custom-code-36919996122-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 10f88169b0f3929b4e2528aad7a825df31163156 5e501222d34aa882d989e820598f3e7441730d4d
python3 scripts/castiron/custom_code_report.py report \
  --base 10f88169b0f3929b4e2528aad7a825df31163156 \
  --head 5e501222d34aa882d989e820598f3e7441730d4d --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-5e501222d34a
cat /tmp/castiron-custom-code-5e501222d34a/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.8 to 4.38.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@db488dd...1c5b675)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 20d07a5448

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".


- name: Initialize CodeQL
uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep CodeQL init and analyze on the same revision

When the v4.38 per-language-bundle rollout reaches this repository, this job initializes CodeQL with v4.38.1 but still analyzes with v4.37.8 on line 38. The preceding paired update (f95237f) explicitly records that these steps share versioned state, so the older analyze action may not consume the initialization or bundle state produced by this version and can cause CodeQL analysis to fail; update analyze to the same reviewed v4.38.1 SHA.

Useful? React with 👍 / 👎.

@marcuswood-oai marcuswood-oai changed the title chore(deps): bump github/codeql-action/init from 4.37.8 to 4.38.1 chore(deps): bump CodeQL actions to 4.38.1 Oct 1, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T20:10:41.542225Z 5e50122 New commits
🔒 Security Review ✅ Completed 2026-10-01T20:11:14.207939Z 5e50122 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@marcuswood-oai
marcuswood-oai added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit fb70d66 Oct 1, 2026
28 checks passed
@marcuswood-oai
marcuswood-oai deleted the dependabot/github_actions/github/codeql-action/init-4.38.1 branch October 1, 2026 20:52
@openai-sdks openai-sdks Bot mentioned this pull request Oct 1, 2026
gh-actions-shared Bot pushed a commit to xf-qubit/openai-python that referenced this pull request Oct 1, 2026
Automated Release PR
---


##
[3.23.0](openai/openai-python@v3.22.1...v3.23.0)
(2026-10-01)


### Features

* **agents:** [1/n] return typed answers from session streams
([openai#4007](openai#4007))
([10f8816](openai@10f8816))
* **agents:** stage files and download turn artifacts
([openai#4009](openai#4009))
([4fc2438](openai@4fc2438))
* **api:** Add session traces and Realtime translations
([openai#4001](openai#4001))
([138e3d1](openai@138e3d1))
* **beta:** expose typed application actions as agent tools
([openai#4006](openai#4006))
([f219c55](openai@f219c55))
* collect final output from beta Agents streams
([157ac4c](openai@157ac4c))


### Bug Fixes

* **api:** allow original image detail in Chat Completions
([openai#4005](openai#4005))
([8a136c2](openai@8a136c2))
* **api:** correct the eval run cancellation endpoint
([openai#4003](openai#4003))
([28c5c9a](openai@28c5c9a))
* **api:** retain WebSocket endpoint paths and query parameters
([openai#3999](openai#3999))
([7f203fd](openai@7f203fd))
* keep Castiron budget results valid when main advances
([openai#4012](openai#4012))
([73f189b](openai@73f189b))
* **responses:** avoid replaying uncertain typed sends on reconnect
([openai#4011](openai#4011))
([1dbbf61](openai@1dbbf61))
* **responses:** respect send queue limits during reconnect
([openai#4000](openai#4000))
([50f95ac](openai@50f95ac))
* use monotonic clock for file processing timeout
([openai#3748](openai#3748))
([58aca1d](openai@58aca1d))


### Chores

* **api:** retain WebRTC Live session transport types
([openai#4002](openai#4002))
([5c9ace9](openai@5c9ace9))
* **deps-dev:** bump pyright from 1.1.413 to 1.1.414
([openai#3902](openai#3902))
([a91d779](openai@a91d779))
* **deps:** bump astral-sh/setup-uv from 10.0.1 to 10.1.0
([openai#3976](openai#3976))
([f15f43c](openai@f15f43c))
* **deps:** bump CodeQL actions to 4.38.1
([openai#3974](openai#3974))
([fb70d66](openai@fb70d66))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant