See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
2.21.6 - 13 Sep 2023
Better error message when there is a failure to determine the merge base of the code to analysis. #1860
Improve the calculation of default amount of RAM used for query execution on GitHub Enterprise Server. This now reduces in proportion to the runner's total memory to better account for system memory usage, helping to avoid out-of-memory failures on larger runners. This feature is already available to GitHub.com users. #1866
Enable improved file coverage information for GitHub Enterprise Server users. This feature is already available to GitHub.com users. #1867
Update default CodeQL bundle version to 2.14.4. #1873
2.21.5 - 28 Aug 2023
Update default CodeQL bundle version to 2.14.3. #1845
Fixed a bug in CodeQL Action 2.21.3 onwards that affected beta support for Project Lombok when analyzing Java. The environment variable CODEQL_EXTRACTOR_JAVA_RUN_ANNOTATION_PROCESSORS will now be respected if it was manually configured in the workflow. #1844
Enable support for Kotlin 1.9.20 when running with CodeQL CLI v2.13.4 through v2.14.3. #1853
2.21.4 - 14 Aug 2023
Update default CodeQL bundle version to 2.14.2. #1831
Log a warning if the amount of available disk space runs low during a code scanning run. #1825
When downloading CodeQL bundle version 2.13.4 and later, cache these bundles in the Actions tool cache using a simpler version number. #1832
Fix an issue that first appeared in CodeQL Action v2.21.2 that prevented CodeQL invocations from being logged. #1833
We are rolling out a feature in August 2023 that will improve the quality of file coverage information. #1835
2.21.3 - 08 Aug 2023
We are rolling out a feature in August 2023 that will improve multi-threaded performance on larger runners. #1817
We are rolling out a feature in August 2023 that adds beta support for Project Lombok when analyzing Java. #1809
Reduce disk space usage when downloading the CodeQL bundle. #1820
2.21.2 - 28 Jul 2023
Update default CodeQL bundle version to 2.14.1. #1797
Avoid duplicating the analysis summary within the logs. #1811
2.21.1 - 26 Jul 2023
Improve the handling of fatal errors from the CodeQL CLI. #1795
Add the sarif-output output to the analyze action that contains the path to the directory of the generated SARIF. #1799
2.21.0 - 19 Jul 2023
CodeQL Action now requires CodeQL CLI 2.9.4 or later. For more information, see the corresponding changelog entry for CodeQL Action version 2.20.4. #1724
2.20.4 - 14 Jul 2023
... (truncated)
Commits
701f152 Merge pull request #1875 from github/update-v2.21.6-6a6a82470
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps github/codeql-action from 2.21.4 to 2.21.6.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
701f152
Merge pull request #1875 from github/update-v2.21.6-6a6a824701b62990
Fix misplaced changelog entry5462f69
Update changelog for v2.21.66a6a824
Merge pull request #1873 from github/update-bundle/codeql-bundle-v2.14.488c7a5c
Add changelog noteda65035
Update default bundle to codeql-bundle-v2.14.443750fe
Merge pull request #1872 from github/henrymercer/user-errors-for-upload-sarifa7c12a5
Address PR comments7218de5
Merge branch 'main' into henrymercer/user-errors-for-upload-sarif4764dce
Merge pull request #1866 from github/henrymercer/enable-scaling-reserved-ram-...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show