On Linux, the maximum possible value for the --threads option now respects the CPU count as specified in cgroup files to more accurately reflect the number of available cores when running in containers. #2083
Update default CodeQL bundle version to 2.16.1. #2096
3.23.1 - 17 Jan 2024
Update default CodeQL bundle version to 2.16.0. #2073
Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. #2079
3.23.0 - 08 Jan 2024
We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. #2031
Update default CodeQL bundle version to 2.15.5. #2047
3.22.11 - 13 Dec 2023
[v3+ only] The CodeQL Action now runs on Node.js v20. #2006
2.22.10 - 12 Dec 2023
Update default CodeQL bundle version to 2.15.4. #2016
2.22.9 - 07 Dec 2023
No user facing changes.
2.22.8 - 23 Nov 2023
Update default CodeQL bundle version to 2.15.3. #2001
2.22.7 - 16 Nov 2023
Add a deprecation warning for customers using CodeQL version 2.11.5 and earlier. These versions of CodeQL were discontinued on 8 November 2023 alongside GitHub Enterprise Server 3.7, and will be unsupported by CodeQL Action v2.23.0 and later. #1993
If you are using one of these versions, please update to CodeQL CLI version 2.11.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
Alternatively, if you want to continue using a version of the CodeQL CLI between 2.10.5 and 2.11.5, you can replace github/codeql-action/*@v2 by github/codeql-action/*@v2.22.7 in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
2.22.6 - 14 Nov 2023
Customers running Python analysis on macOS using version 2.14.6 or earlier of the CodeQL CLI should upgrade to CodeQL CLI version 2.15.0 or later. If you do not wish to upgrade the CodeQL CLI, ensure that you are using Python version 3.11 or earlier, as CodeQL version 2.14.6 and earlier do not support Python 3.12. You can achieve this by adding a setup-python step to your code scanning workflow before the step that invokes github/codeql-action/init.
Update default CodeQL bundle version to 2.15.2. #1978
In scope of this release, we change Nodejs runtime from node16 to node20 (actions/setup-go#421). Moreover, we update some dependencies to the latest versions (actions/setup-go#445).
In scope of this release, slow installation on Windows was fixed by @dsame in actions/setup-go#393 and OS version was added to primaryKey for Ubuntu runners to avoid conflicts (actions/setup-go#383)
Bugfix: Pass custom token as input argument to action by @mre in lycheeverse/lychee-action#222
Previously, the name of the token was incorrect, leading to no token being used if the user specified with: [token: ...].
Thanks to @tobon4 for pointing this out.
Bumps the github-actions group with 15 updates:
3
4
6
7
2
3
3
4
4
5
1.2.0
1.3.0
1.8.0
1.9.3
4
5
4
5
0.8.3
0.9.0
3
4
3.1.2
3.3.0
0.14.3
0.15.6
23
25
8
9
Updates
peter-evans/create-or-update-comment
from 3 to 4Release notes
Sourced from peter-evans/create-or-update-comment's releases.
... (truncated)
Commits
71345be
feat: update runtime to node 20 (#306)d41bfe3
build(deps-dev): bump prettier from 3.2.3 to 3.2.4 (#305)73b4b9e
build(deps-dev): bump@types/node
from 18.19.7 to 18.19.8 (#304)b865fac
build(deps-dev): bump@types/node
from 18.19.6 to 18.19.7 (#303)52b668a
build(deps-dev): bump eslint-plugin-jest from 27.6.1 to 27.6.3 (#302)974f56a
build(deps-dev): bump prettier from 3.1.1 to 3.2.3 (#301)2cbfe8b
build(deps-dev): bump@types/node
from 18.19.4 to 18.19.6 (#300)761872a
build(deps-dev): bump eslint-plugin-prettier from 5.1.2 to 5.1.3 (#299)72c3238
build(deps-dev): bump@types/node
from 18.19.3 to 18.19.4 (#298)07daf7b
build(deps-dev): bump eslint-plugin-jest from 27.6.0 to 27.6.1 (#297)Updates
actions/github-script
from 6 to 7Release notes
Sourced from actions/github-script's releases.
... (truncated)
Commits
60a0d83
Merge pull request #440 from actions/joshmgross/v7.0.1b7fb200
Update version to 7.0.112e22ed
Merge pull request #439 from actions/joshmgross/avoid-setting-base-urld319f8f
Avoid settingbaseUrl
to undefined when input is not providede69ef54
Merge pull request #425 from actions/joshmgross/node-20ee0914b
Update licensesd6fc56f
Use@types/node
for Node 20384d6cf
Fix quotations in tests8472492
Only validate GraphQLpreviews
84903f5
Removenode-fetch
from typeUpdates
github/codeql-action
from 2 to 3Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
e86ee7f
fix typo in comment4f9fb97
update wording of deprecation warninga854253
ensure deprecation warning is only shown once per jobf72cffc
add v2 deprecation warningd13ca04
Merge pull request #2090 from github/mergeback/v3.23.1-to-main-0b21cf24475e2af
Update checked-in dependenciesUpdates
actions/dependency-review-action
from 3 to 4Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
4cd9eb2
Updating docs to point to v4.4901385
bump to 4.0.0dbf82a4
Merge pull request #639 from takost/takost/update-to-node-2078aeb2a
Merge pull request #663 from actions/dependabot/npm_and_yarn/typescript-eslin...4e51000
Bump@typescript-eslint/parser
from 6.18.0 to 6.18.19560737
Merge pull request #661 from actions/dependabot/npm_and_yarn/typescript-eslin...4125f47
Merge pull request #660 from actions/dependabot/npm_and_yarn/types/node-16.18.7007cc93e
Bump@typescript-eslint/eslint-plugin
from 6.18.0 to 6.18.1e2c203b
Bump@types/node
from 16.18.62 to 16.18.70f0b304d
Merge pull request #653 from actions/dependabot/npm_and_yarn/got-14.0.0Updates
actions/setup-go
from 4 to 5Release notes
Sourced from actions/setup-go's releases.
Commits
0c52d54
Update dependencies for node20 (#445)bfd2fb3
Merge pull request #421 from chenrui333/node20-runtime3d65fa5
feat: bump to use actions/checkout@v48a505c9
feat: bump to use node20 runtime883490d
Merge pull request #417 from artemgavrilov/maind45ebba
Rephrase sentence317c661
Replacewildcards
term withglobs
.f90673a
Merge pull request #1 from artemgavrilov/caching-docs-improvement8018234
Improve documentation regarding dependencies cachind085b4f
Merge pull request #411 from galargh/fix/windows-hostedtoolcacheUpdates
actions/first-interaction
from 1.2.0 to 1.3.0Release notes
Sourced from actions/first-interaction's releases.
Commits
34f15e8
Merge pull request #288 from actions/allanguigou/bump-minor-version3c71ce7
1.3.0001cc8d
Merge pull request #287 from actions/bump-node-to-v18625b194
Update to node 20.103aee370
Update license to MITf3836b2
Update licensed cachec23c7ec
Update base image to node:18.18.2-buster-slimUpdates
lycheeverse/lychee-action
from 1.8.0 to 1.9.3Release notes
Sourced from lycheeverse/lychee-action's releases.
... (truncated)
Commits
c053181
Pass customtoken
as input argument to action (#222)eeb9cb6
Bump to lychee 0.14.20fa791a
Bump peter-evans/create-issue-from-file from 4 to 5 (#223)8c9a282
Bump actions/cache from 3 to 4 (#221)c3089c7
Bump to lychee 0.14.1fdea703
Update secure git hash for 1.9.022134d3
Bump version to 1.9.0Superseded by #104.