Fixes a bug in 4.1.2 that would introduce comments in every pull request, regardless of the user's configuration (see actions/dependency-review-action#697).
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between v2 and v3 of the CodeQL Action is the node version they support, with v3 running on node 20 while we continue to release v2 to support running on node 16. For example 3.22.11 was the first v3 release and is functionally identical to 2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.
[UNRELEASED]
No user facing changes.
3.24.5 - 23 Feb 2024
Update default CodeQL bundle version to 2.16.3. #2156
3.24.4 - 21 Feb 2024
Fix an issue where an existing, but empty, /sys/fs/cgroup/cpuset.cpus file always resulted in a single-threaded run. #2151
3.24.3 - 15 Feb 2024
Fix an issue where the CodeQL Action would fail to load a configuration specified by the config input to the init Action. #2147
3.24.2 - 15 Feb 2024
Enable improved multi-threaded performance on larger runners for GitHub Enterprise Server users. This feature is already available to GitHub.com users. #2141
3.24.1 - 13 Feb 2024
Update default CodeQL bundle version to 2.16.2. #2124
The CodeQL action no longer fails if it can't write to the telemetry api endpoint. #2121
3.24.0 - 02 Feb 2024
CodeQL Python analysis will no longer install dependencies on GitHub Enterprise Server, as is already the case for GitHub.com. See release notes for 3.23.0 for more details. #2106
3.23.2 - 26 Jan 2024
On Linux, the maximum possible value for the --threads option now respects the CPU count as specified in cgroup files to more accurately reflect the number of available cores when running in containers. #2083
Update default CodeQL bundle version to 2.16.1. #2096
3.23.1 - 17 Jan 2024
Update default CodeQL bundle version to 2.16.0. #2073
Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. #2079
3.23.0 - 08 Jan 2024
We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. #2031
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the ci-deps group with 9 updates:
3.0.0
3.0.1
4.0.3
4.0.4
2.9.1
2.9.2
4.0.0
4.1.3
0.5.0
0.6.0
4.3.0
4.3.1
4.1.1
4.1.2
1.5.13
1.5.15
3.24.0
3.24.5
Updates
actions/upload-pages-artifact
from 3.0.0 to 3.0.1Release notes
Sourced from actions/upload-pages-artifact's releases.
Commits
56afc60
Merge pull request #94 from SilverRainZ/maind12fdfb
Merge branch 'main' into mainaef5542
Merge pull request #88 from uiolee/patch-129cedd7
Merge branch 'main' into patch-1a69c22e
Merge pull request #92 from actions/dependabot/github_actions/non-breaking-ch...794e304
Group tar's output to prevent it from messing up logs14007f6
Bump the non-breaking-changes group with 1 update0191170
Merge pull request #91 from actions/dependabot-grouping0e7832d
Update Dependabot config to group non-breaking changes1a6d9fa
Update README.mdUpdates
actions/deploy-pages
from 4.0.3 to 4.0.4Release notes
Sourced from actions/deploy-pages's releases.
Commits
decdde0
Merge pull request #295 from lmammino/patch-10b3be6b
Update distributablesc2c861c
Update tests294fbcd
Merge branch 'main' into patch-12a4b535
Merge pull request #298 from SimonSiefke/fix/typo4825f57
Merge branch 'main' into fix/typofa29843
Merge pull request #310 from actions/dependabot/npm_and_yarn/actions/artifact...d005625
Update distributables after Dependabot 🤖636701b
Bump@actions/artifact
from 2.0.1 to 2.1.125b8009
Merge pull request #307 from actions/dependabot-groupingUpdates
JasonEtco/create-an-issue
from 2.9.1 to 2.9.2Release notes
Sourced from JasonEtco/create-an-issue's releases.
Commits
1b14a70
Automatic compilation56fdd2d
Merge pull request #176 from parkerbxyz/node20c92e530
@tsconfig/node-lts
→@tsconfig/recommended
d2f7266
Update TSConfig to use node-ltsd0732be
Update ci.yml to use node20c0e947f
Update action.yml to use node20ee46187
Merge pull request #151 from saerosV/main6d78338
Update setup-node action versionf6aae5d
Update Checkout action versionbf328b8
Merge pull request #147 from IdiosApps/patch-1Updates
actions/dependency-review-action
from 4.0.0 to 4.1.3Release notes
Sourced from actions/dependency-review-action's releases.
Commits
9129d7d
don't set output on every runa1be843
Update stale.yaml587ff57
Don't useif: always()
in examples.be8bc50
Merge branch 'output-comment'cb180bf
Merge pull request #696 from actions/output-commentb2ea187
bumping action versionc94f57b
Add a new image for the example report.124fafe
Merge branch 'issue-250' into output-comment26174d8
Merge branch 'issue-250' of https://github.com/jsoref/dependency-review-actio...a87338a
Update example workflow.Updates
actions/add-to-project
from 0.5.0 to 0.6.0Commits
0609a27
Merge pull request #517 from mattcosta7/patch-19431bea
Update action.yml0008229
Merge pull request #503 from takost/update-to-node-205a5c08a
Update action to node200be3b65
Merge pull request #494 from actions/dependabot/npm_and_yarn/eslint-plugin-je...9c5d7e2
Merge branch 'main' into dependabot/npm_and_yarn/eslint-plugin-jest-27.6.06460bf6
Merge pull request #495 from actions/dependabot/npm_and_yarn/types/node-16.18.60c48fdd4
build(deps-dev): bump@types/node
from 16.18.51 to 16.18.60b953640
Merge pull request #496 from actions/dependabot/npm_and_yarn/types/jest-29.5.7f9db65b
Merge branch 'main' into dependabot/npm_and_yarn/types/jest-29.5.7Updates
actions/upload-artifact
from 4.3.0 to 4.3.1Release notes
Sourced from actions/upload-artifact's releases.
Commits
5d5d22a
Merge pull request #515 from actions/eggyhead/update-artifact-v2.1.1f1e993d
update artifact license4881bfd
updating dist:a30777e
@eggyhead
3a80482
Merge pull request #511 from actions/robherley/migration-docs-typo9d63e3f
Merge branch 'main' into robherley/migration-docs-typodfa1ab2
fix typo with v3 artifact downloads in migration guided00351b
Merge pull request #509 from markmssd/patch-1707f5a7
Update limitation of10
artifacts upload to500
Updates
actions/download-artifact
from 4.1.1 to 4.1.2Release notes
Sourced from actions/download-artifact's releases.
Commits
eaceaf8
Merge pull request #291 from actions/eggyhead/update-artifact-v2.1.181eafdc
update artifact license9ac5cad
updating artifact dependency to version 2.1.13ad8411
Merge pull request #287 from actions/robherley/sync-migration-docs1de4643
Sync migration docs with upload-artifactbb3fa7f
Merge pull request #275 from actions/robherley/better-log-msgsa244de5
ncc355659b
clarify log messages when using pattern/merge-multiple paramsUpdates
EmbarkStudios/cargo-deny-action
from 1.5.13 to 1.5.15Commits
68cd9c5
Add actual testing of the changes in a PR (#72)549bc52
Add manifest-path variable (#70)c86e4a9
Add wasm-oidc-plugin (#69)Updates
github/codeql-action
from 3.24.0 to 3.24.5Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
47b3d88
Merge pull request #2162 from github/update-v3.24.5-a74dcdb0528c2900
Update changelog for v3.24.5a74dcdb
Merge pull request #2160 from github/henrymercer/deptrace-with-build-modeaeb89ef
Enable C++ deptrace when using autobuild build mode2896599
Merge pull request #2060 from github/mbg/go/1.22e3a86ed
Add comment justifying why we setcache: false
5d55901
Use Go 1.22 in workflows908a883
Merge pull request #2158 from github/mergeback/v3.24.4-to-main-e2e140ad9bce06d
Merge branch 'main' into mergeback/v3.24.4-to-main-e2e140adc9f3eed
Update checked-in dependenciesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show