hoverkraft-tech / ci-github-nodejs

Opinionated Github actions and workflows for continuous integration in NodeJs context
MIT License
0 stars 0 forks source link

chore(deps): bump github/codeql-action from 3.22.12 to 3.23.0 #46

Closed dependabot[bot] closed 8 months ago

dependabot[bot] commented 8 months ago

Bumps github/codeql-action from 3.22.12 to 3.23.0.

Changelog

Sourced from github/codeql-action's changelog.

3.23.0 - 08 Jan 2024

  • We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. #2031
  • The CodeQL Action now requires CodeQL version 2.11.6 or later. For more information, see the corresponding changelog entry for CodeQL Action version 2.22.7. #2009
Commits
  • e5f05b8 Merge pull request #2066 from github/update-v3.23.0-fd55bb0b0
  • 48e7b8b Update changelog for v3.23.0
  • fd55bb0 Merge pull request #2065 from github/henrymercer/further-run-queries-cleanup
  • 838a022 Clean up running queries workflow now that the queries are determined by the CLI
  • 8516954 Merge pull request #2062 from github/henrymercer/remove-action-config-parsing
  • a533ec6 Merge branch 'main' into henrymercer/remove-action-config-parsing
  • 08ae9bf Merge pull request #2063 from github/henrymercer/remove-ml-powered-queries-repo
  • 58ff74a Merge pull request #2031 from github/rasmuswl/no-dep-inst-default
  • 9926570 Generate JS
  • 2e27b3c Create helper isPythonDependencyInstallationDisabled
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)