Henry Mercer
96f518a34f
Merge pull request #3042 from github/update-v3.29.10-6ec994ecb
...
Merge main into releases/v3
2025-08-18 12:45:49 +01:00
github-actions[bot]
57a1c6b3e7
Update changelog for v3.29.10
2025-08-18 09:58:01 +00:00
Henry Mercer
6ec994ecba
Merge pull request #3039 from github/mbg/remove-cpp-bmn-check
...
Remove unused C++ BMN FF
2025-08-18 10:53:36 +01:00
Michael B. Gale
3f00c7c1e1
Remove unused C++ BMN FF
2025-08-15 21:10:11 +01:00
Michael B. Gale
141ee4abd8
Remove C++ BMN FF check that is no longer used
2025-08-15 21:10:00 +01:00
Michael B. Gale
233052189b
Merge pull request #3037 from github/henrymercer/failed-upload-logs
...
Bump log visibility for failed analysis upload
2025-08-15 18:47:21 +01:00
Henry Mercer
3966569d06
Merge pull request #3035 from github/henrymercer/fix-cleanup-info
...
Only display `cleanup-info` log when relevant
2025-08-15 18:40:49 +01:00
Michael B. Gale
f7bd70c7fa
Merge branch 'main' into henrymercer/failed-upload-logs
2025-08-15 18:32:32 +01:00
Michael B. Gale
75151c2782
Merge branch 'main' into henrymercer/fix-cleanup-info
2025-08-15 18:28:16 +01:00
Michael B. Gale
4ff91f1080
Merge pull request #3036 from github/mbg/ci/gradle9
...
Add workflow generator option for installing Java
2025-08-15 18:25:11 +01:00
Michael B. Gale
1dafc5cf4c
Fix redundant True / False
2025-08-15 18:10:28 +01:00
Michael B. Gale
3119b35eed
Add template option for installing Java
2025-08-15 17:58:10 +01:00
Henry Mercer
5848d111cd
Bump log visibility for failed analysis upload
...
Make it more obvious that the SARIF file for the unsuccessful execution was successfully uploaded.
2025-08-15 17:57:13 +01:00
Henry Mercer
537405376b
Only display cleanup-info log when relevant
2025-08-15 17:25:17 +01:00
Michael B. Gale
777f9173e8
Merge pull request #3030 from github/mbg/workflow-collections
...
PR checks: support collections of workflows
2025-08-14 13:09:09 +01:00
Michael B. Gale
20c329c963
Sort template files to avoid ordering-issues
2025-08-14 12:08:22 +01:00
Michael B. Gale
bd79bc6b67
Automatically add go-version input if installGo == true
2025-08-14 11:52:35 +01:00
Michael B. Gale
9bd3c14196
Move up workflowsInput initialisation
2025-08-14 11:52:34 +01:00
Michael B. Gale
a592f71173
Allow inputs for workflow_* events, and propagate them through collections
2025-08-14 11:52:34 +01:00
Michael B. Gale
cf7a5d3e11
Add support for named collections of workflows
2025-08-14 11:52:34 +01:00
Michael B. Gale
092bf71d04
Add workflow_call triggers to PR checks
2025-08-14 11:52:34 +01:00
Chuan-kai Lin
7eb43b0788
Merge pull request #3031 from github/cklin/overlay-upload-limit
...
Overlay: add database upload size limit
2025-08-13 07:26:50 -07:00
Chuan-kai Lin
eeeb083a28
Overlay: add database upload size limit
2025-08-12 14:16:46 -07:00
Michael B. Gale
eef4c44f6b
Merge pull request #3029 from github/mbg/copilot/release-process
...
Add Copilot instructions for release PRs
2025-08-12 12:51:16 +01:00
Paolo Tranquilli
60aa58a9e6
Merge pull request #2960 from github/redsun82/rust
...
Rust: remove shipped feature flag
2025-08-12 13:47:14 +02:00
Paolo Tranquilli
df1ceaccd4
Merge branch 'main' into redsun82/rust
2025-08-12 13:33:24 +02:00
Paolo Tranquilli
486a50d837
Capitalize Rust in log
2025-08-12 13:33:21 +02:00
Henry Mercer
9dfbcfd29f
Merge pull request #3025 from github/dependabot/github_actions/actions-b7431406fe
...
Bump the actions group with 3 updates
2025-08-12 12:24:05 +01:00
Michael B. Gale
cd4167966c
Manually edit PR instructions
...
- Conditions all must be true, not just any one of them
- Make it clearer that no files should be reviewed, except for the two listed ones
2025-08-12 11:51:44 +01:00
Michael B. Gale
1813a6cc1c
Fix typo
2025-08-12 11:48:05 +01:00
Michael B. Gale
df1a86546b
Merge pull request #3027 from github/mergeback/v3.29.9-to-main-df559355
...
Mergeback v3.29.9 refs/heads/releases/v3 into main
2025-08-12 11:43:21 +01:00
github-actions[bot]
790022db4c
Update checked-in dependencies
2025-08-12 10:32:26 +00:00
Paolo Tranquilli
a9c4652773
Fix EXPERIMENTAL_FEATURES environment variable
2025-08-12 12:31:02 +02:00
github-actions[bot]
93f2eeca89
Update changelog and version after v3.29.9
2025-08-12 10:30:48 +00:00
Michael B. Gale
df559355d5
Merge pull request #3026 from github/update-v3.29.9-cc722e476
...
Merge main into releases/v3
2025-08-12 11:30:20 +01:00
Michael B. Gale
9065906448
Add Copilot instructions for release PRs
2025-08-12 11:29:13 +01:00
Paolo Tranquilli
aa456a5447
Merge branch 'main' into redsun82/rust
2025-08-12 12:16:56 +02:00
github-actions[bot]
53f255b421
Update changelog for v3.29.9
2025-08-12 10:06:05 +00:00
Michael B. Gale
cc722e476f
Merge pull request #3023 from github/redsun82/rust-test
...
Improve Rust analysis PR check
2025-08-12 11:02:27 +01:00
Henry Mercer
a4cd8fd036
Merge pull request #3024 from github/dependabot/npm_and_yarn/npm-3a4f9bf414
...
Bump the npm group with 6 updates
2025-08-12 10:30:05 +01:00
github-actions[bot]
a1feaf3820
Rebuild
2025-08-12 09:25:28 +00:00
Henry Mercer
136e8b7a95
Update sources of generated workflows
2025-08-12 10:21:02 +01:00
dependabot[bot]
b1bfc45906
Bump the actions group with 3 updates
...
Bumps the actions group with 3 updates: [actions/checkout](https://github.com/actions/checkout ), [actions/download-artifact](https://github.com/actions/download-artifact ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `actions/checkout` from 4 to 5
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
Updates `actions/download-artifact` from 4 to 5
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v4...v5 )
Updates `actions/create-github-app-token` from 2.0.6 to 2.1.1
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.0.6...v2.1.1 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/download-artifact
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/create-github-app-token
dependency-version: 2.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-12 02:10:43 +00:00
github-actions[bot]
542b274f93
Update checked-in dependencies
2025-08-12 02:07:02 +00:00
dependabot[bot]
1a376ca348
Bump the npm group with 6 updates
...
Bumps the npm group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `4.0.3` | `4.0.5` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `1.3.1` | `1.3.2` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.32.0` | `9.33.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.39.0` | `8.39.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.39.0` | `8.39.1` |
| [nock](https://github.com/nock/nock ) | `14.0.8` | `14.0.9` |
Updates `@actions/cache` from 4.0.3 to 4.0.5
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@eslint/compat` from 1.3.1 to 1.3.2
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v1.3.2/packages/compat )
Updates `@eslint/js` from 9.32.0 to 9.33.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.33.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.39.0 to 8.39.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.39.0 to 8.39.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.1/packages/parser )
Updates `nock` from 14.0.8 to 14.0.9
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.8...v14.0.9 )
---
updated-dependencies:
- dependency-name: "@actions/cache"
dependency-version: 4.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/compat"
dependency-version: 1.3.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.33.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.39.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.39.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.9
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-12 02:06:25 +00:00
Paolo Tranquilli
9f966bbbf5
Merge branch 'main' into redsun82/rust-test
2025-08-11 17:01:23 +02:00
Chuan-kai Lin
c6dcdfa33a
Merge pull request #2993 from github/cklin/overlay-pack-check
...
Overlay: check query packs for compatibility
2025-08-11 07:42:07 -07:00
Chuan-kai Lin
821d3bd162
Merge branch 'main' into cklin/overlay-pack-check
2025-08-11 07:10:04 -07:00
Paolo Tranquilli
bf1dd6901d
Move comments up in rust.yml
2025-08-11 15:44:35 +02:00
Paolo Tranquilli
286b9e9d74
Specify the ruamel.yaml version in one place only (sync.sh)
2025-08-11 15:38:32 +02:00
Paolo Tranquilli
2d7401b887
Revert ruamel.yaml back to 0.17.31
...
And revert back related changes
2025-08-11 15:36:42 +02:00
Henry Mercer
f45dfa6abd
Merge pull request #2839 from github/marcogario/clean-up-proxy-workaround
...
Clean-up logic for overriding proxy
2025-08-11 14:23:00 +01:00
Henry Mercer
efcb415657
Merge pull request #3022 from github/henrymercer/improve-pr-template
...
Add risk assessment to PR template
2025-08-11 14:09:01 +01:00
Henry Mercer
be99c61783
Merge branch 'main' into marcogario/clean-up-proxy-workaround
2025-08-11 14:08:12 +01:00
Paolo Tranquilli
28f2516040
Improve Rust analysis PR check
...
Also run the `rust` checks on "milestone" CLI releases, to ensure we
remain backward compatible with those versions. This was prompted by
https://github.com/github/codeql-action/pull/2960#pullrequestreview-3104730221
Running this on current `main` and then on that PR should improve our
confidence we remain backward compatible.
It also turns out a probable `ruamel.yaml` update was changing a lot of
generated workflows, so I've:
* fixed the `ruamel.yaml` version to the latest in `sync.sh`
* added `yaml.width = 120` in `sync.py` to minimize (but not entirely
remove) the number of changes
* checked in the workflows whose formatting was changed by the new
`ruamel.yaml` version
2025-08-11 14:58:50 +02:00
Henry Mercer
916d5bdef0
Merge branch 'main' into henrymercer/improve-pr-template
2025-08-11 13:54:50 +01:00
Henry Mercer
5b6f1d22a1
Merge pull request #3021 from github/henrymercer/cleanup-extract-to-toolcache
...
Cleanup extract to toolcache feature flag
2025-08-11 13:46:30 +01:00
Paolo Tranquilli
bfa52a844d
Address review
2025-08-11 14:38:12 +02:00
Paolo Tranquilli
68da2c5e55
Merge branch 'main' into redsun82/rust
2025-08-11 14:34:45 +02:00
Chuan-kai Lin
e47147711b
build: refresh js files
2025-08-08 10:36:17 -07:00
Chuan-kai Lin
baac9295dc
Check both qlpack.yml and codeql-pack.yml
2025-08-08 10:34:53 -07:00
Chuan-kai Lin
57f4ac5c1b
PR checks: add overlay-init-fallback.yml
2025-08-08 09:57:45 -07:00
Chuan-kai Lin
8dbcef50df
Extract getGeneratedSuitePath()
2025-08-08 08:53:04 -07:00
Chuan-kai Lin
ee698cb5ba
init-action: inhibit non-empty dbLocation warning when restarting
2025-08-08 08:53:04 -07:00
Chuan-kai Lin
bc9c32ed0b
init-action: check packs for overlay compatibility
2025-08-08 08:53:04 -07:00
Chuan-kai Lin
ee7cacdb6b
Inline runInit()
...
This commit inlines runInit(), so that it is easier to repeat the
runDatabaseInitCluster() call when needed.
2025-08-08 08:53:04 -07:00
Chuan-kai Lin
ed9d057cde
Extract runDatabaseInitCluster()
2025-08-08 08:53:04 -07:00
Chuan-kai Lin
c47e1541d8
Add checkPacksForOverlayCompatibility()
2025-08-08 08:53:03 -07:00
Chuan-kai Lin
9d202e0975
Add resolveQueriesStartingPacks()
2025-08-08 08:47:24 -07:00
Chuan-kai Lin
ad19982a1f
Remove packDownload()
2025-08-08 08:47:24 -07:00
Chuan-kai Lin
a71ebf32ea
Remove resolveQueries()
2025-08-08 08:47:24 -07:00
Chuan-kai Lin
da8dabf356
VersionInfo: add overlayVersion field
2025-08-08 08:47:24 -07:00
Chuan-kai Lin
6504a72ad7
Update CODEQL_OVERLAY_MINIMUM_VERSION
2025-08-08 08:47:24 -07:00
Henry Mercer
f3997c21f2
Add risk assessment to PR template
2025-08-08 16:08:42 +01:00
Henry Mercer
1ae99dedc6
Update cleanup-level input description
2025-08-08 15:59:27 +01:00
Henry Mercer
4474150eef
Merge pull request #3020 from github/mergeback/v3.29.8-to-main-76621b61
...
Mergeback v3.29.8 refs/heads/releases/v3 into main
2025-08-08 11:53:05 +01:00
Henry Mercer
84973f707e
Clean up toolcache PR checks
2025-08-08 11:48:29 +01:00
Henry Mercer
01992a9420
Clean up Zstd bundle PR checks
2025-08-08 11:45:43 +01:00
github-actions[bot]
5fabbc2b0d
Update checked-in dependencies
2025-08-08 10:39:10 +00:00
Henry Mercer
c9d51abc0b
Remove blank lines
2025-08-08 11:38:12 +01:00
Henry Mercer
1afa0e7463
Cleanup extract to toolcache feature flag
2025-08-08 11:26:14 +01:00
Henry Mercer
8cec93ae81
Clean up zstd streaming extraction feature flag
2025-08-08 11:18:56 +01:00
Paolo Tranquilli
67812dd611
Rework rust code
2025-08-08 12:10:18 +02:00
github-actions[bot]
9ec8453e11
Update changelog and version after v3.29.8
2025-08-08 10:09:34 +00:00
Henry Mercer
76621b61de
Merge pull request #3019 from github/update-v3.29.8-679a40d33
...
Merge main into releases/v3
2025-08-08 11:09:06 +01:00
Paolo Tranquilli
068f150cb7
Merge branch 'main' into redsun82/rust
2025-08-08 11:49:04 +02:00
Henry Mercer
29ac3cefbb
Add release notes for 3.29.7
2025-08-08 10:46:17 +01:00
github-actions[bot]
737cfdebe6
Update changelog for v3.29.8
2025-08-08 09:36:40 +00:00
Henry Mercer
679a40d337
Merge pull request #3014 from github/henrymercer/rebuild-dispatch
...
Enable rebuilding PRs with conflicts
2025-08-08 09:45:36 +01:00
Henry Mercer
6fe50b283a
Merge pull request #3015 from github/henrymercer/language-autodetection-workaround
...
Fix auto-detection of extractors that aren't languages
2025-08-07 21:28:43 +01:00
Henry Mercer
6bc91d64f6
Add changelog note
2025-08-07 21:13:25 +01:00
Henry Mercer
6b4fedca4f
Bump Action patch version
2025-08-07 21:12:21 +01:00
Henry Mercer
5794ffcb4a
Fix auto-detection of extractors that aren't languages
2025-08-07 21:09:22 +01:00
Henry Mercer
bd62bf449c
Finish in-progress merges
2025-08-07 18:21:57 +01:00
Henry Mercer
2afb4e6f3c
Avoid specifying branch unnecessarily
2025-08-07 17:51:55 +01:00
Henry Mercer
1fd38a4712
Improve logging
2025-08-07 17:50:25 +01:00
Henry Mercer
bf301d1b77
Finish merge if in progress
2025-08-07 17:46:04 +01:00
Henry Mercer
2ee230f7c4
Update .github/workflows/rebuild.yml
2025-08-07 17:34:44 +01:00
Henry Mercer
3425bf931d
Use updated output API
2025-08-07 17:21:48 +01:00
Henry Mercer
ddc8e21357
Allow running rebuild workflow on workflow dispatch
2025-08-07 16:52:41 +01:00
Chuan-kai Lin
afbbdf51df
Merge pull request #3013 from github/mergeback/v3.29.6-to-main-a4e1a019
...
Mergeback v3.29.6 refs/heads/releases/v3 into main
2025-08-07 08:30:35 -07:00
github-actions[bot]
e1be6ef300
Update checked-in dependencies
2025-08-07 15:08:18 +00:00
github-actions[bot]
3c7d12c160
Update changelog and version after v3.29.6
2025-08-07 15:06:41 +00:00
Chuan-kai Lin
a4e1a019f5
Merge pull request #3012 from github/update-v3.29.6-67a6ea72b
...
Merge main into releases/v3
2025-08-07 08:06:12 -07:00
Henry Mercer
4a32399f5f
Merge pull request #3011 from github/henrymercer/prefer-injecting-codeql
...
Prefer providing CodeQL via dependency injection
2025-08-07 15:45:58 +01:00
github-actions[bot]
c587f0a77d
Update changelog for v3.29.6
2025-08-07 14:44:41 +00:00
Henry Mercer
8e6104d51e
Merge branch 'main' into henrymercer/prefer-injecting-codeql
2025-08-07 15:32:20 +01:00
Henry Mercer
67a6ea72bf
Merge pull request #3010 from github/henrymercer/cleanup-for-mrva
...
Clean up the database if it will be uploaded
2025-08-07 15:31:02 +01:00
Paolo Tranquilli
588ff737e7
Merge pull request #3005 from github/redsun82/unsupported-plat
...
Make all errors on an unsupported platform `ConfigurationError`s
2025-08-07 16:24:35 +02:00
Henry Mercer
239ed87059
Fix bad merge
2025-08-07 15:10:28 +01:00
Henry Mercer
8c8bdce638
Update log message for cleanup
2025-08-07 15:09:42 +01:00
Henry Mercer
b7beff905a
Merge branch 'main' into henrymercer/cleanup-for-mrva
2025-08-07 15:06:26 +01:00
Henry Mercer
6422cf7859
Simplify: Remove databaseCleanup
2025-08-07 15:05:29 +01:00
Henry Mercer
eddeaf42e5
Update changelog note
2025-08-07 15:03:03 +01:00
Paolo Tranquilli
739fb03359
Merge branch 'main' into redsun82/unsupported-plat
2025-08-07 15:47:22 +02:00
Paolo Tranquilli
bb56324516
Address review
2025-08-07 15:43:56 +02:00
Michael B. Gale
bc90418e92
Merge pull request #3009 from github/mbg/auto-detect-actions
...
Support auto-detecting Actions workflows
2025-08-07 12:58:47 +01:00
Michael B. Gale
f28436bcbf
Update log message in getRawLanguagesInRepo
2025-08-07 12:43:21 +01:00
Henry Mercer
f8c2086872
Prefer providing CodeQL via dependency injection
2025-08-07 12:16:00 +01:00
Henry Mercer
c7884c6fd8
Clean up the database if it will be uploaded
2025-08-07 11:47:45 +01:00
Michael B. Gale
a625e1693a
Merge pull request #3003 from github/mbg/rewrite-quality-category
...
Rewrite legacy SARIF categories for CQ
2025-08-07 11:30:12 +01:00
Michael B. Gale
5e22b5feee
Merge pull request #3007 from github/dependabot/npm_and_yarn/npm_and_yarn-5a0513363d
...
Bump tmp from 0.2.3 to 0.2.4 in the npm_and_yarn group
2025-08-07 11:25:38 +01:00
Michael B. Gale
0d72a5b371
Check that stats isn't undefined before trying to call isDirectory
2025-08-07 11:25:01 +01:00
Michael B. Gale
43638b10a0
Support auto-detecting Actions workflows
2025-08-07 11:04:21 +01:00
Paolo Tranquilli
1cfc0c2621
Add tests for cli-errors and fix one bug
...
Tests were added with copilot, and uncovered a bug where one of the
regexps looking for `[autobuild]` was not escaping the square brackets.
2025-08-07 09:55:59 +02:00
Paolo Tranquilli
7b33b610d4
Make all errors on an unsupported platform ConfigurationErrors
2025-08-07 09:53:36 +02:00
Chuan-kai Lin
e2b6f0f4a3
Merge pull request #3000 from github/update-bundle/codeql-bundle-v2.22.3
...
Update default bundle to 2.22.3
2025-08-06 13:25:55 -07:00
Chuan-kai Lin
ec8d9c637a
Merge branch 'main' into update-bundle/codeql-bundle-v2.22.3
2025-08-06 10:44:20 -07:00
github-actions[bot]
6db9524876
Update checked-in dependencies
2025-08-06 17:24:01 +00:00
dependabot[bot]
ae2a79254b
Bump tmp from 0.2.3 to 0.2.4 in the npm_and_yarn group
...
Bumps the npm_and_yarn group with 1 update: [tmp](https://github.com/raszi/node-tmp ).
Updates `tmp` from 0.2.3 to 0.2.4
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md )
- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.3...v0.2.4 )
---
updated-dependencies:
- dependency-name: tmp
dependency-version: 0.2.4
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-06 17:23:23 +00:00
Michael B. Gale
2d082457bf
Update src/analyze.ts
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-08-06 16:33:06 +01:00
Michael B. Gale
594623d72f
Fix linter errors
2025-08-06 16:19:09 +01:00
Michael B. Gale
e448add687
Merge branch 'main' into mbg/rewrite-quality-category
2025-08-06 16:16:22 +01:00
Michael B. Gale
1b76c0b9c1
Use withMockedEnv
2025-08-06 12:39:35 +01:00
Henry Mercer
b1228d060c
Merge pull request #3004 from github/mbg/missing-query-pack-config-error
...
Treat missing pack errors as configuration errors
2025-08-06 12:22:06 +01:00
Michael B. Gale
c87fc48ec5
Treat missing pack errors as configuration errors
2025-08-06 12:09:30 +01:00
Michael B. Gale
9fb8f2d0c2
Update src/actions-util.ts
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2025-08-06 10:38:34 +01:00
Michael B. Gale
72770345eb
Fix legacy SARIF categories for CQ in default setup
2025-08-06 10:14:36 +01:00
Michael B. Gale
f5d3601aaa
Make SARIF category a parameter of runInterpretResults
2025-08-06 09:58:48 +01:00
Michael B. Gale
06e521573a
Log qualityAnalysisSummary after analysisSummary
2025-08-06 09:58:31 +01:00
Henry Mercer
60bf7dfc0e
Merge pull request #2914 from github/henrymercer/language-extensibility
...
Allow using new CodeQL languages without updating the CodeQL Action
2025-08-06 09:38:35 +01:00
Henry Mercer
f30d00fe8d
Update Language doc
2025-08-06 09:23:40 +01:00
Paolo Tranquilli
8d19b249dd
Transpile
2025-08-06 06:38:05 +02:00
Paolo Tranquilli
68025974a1
Update comments on rust support in init-action
...
Clarify comments regarding rust support in codeql versions
2025-08-06 06:35:34 +02:00
Paolo Tranquilli
3e4d85617c
Fix typo
2025-08-06 06:33:08 +02:00
Henry Mercer
377976a96e
Improve type of trapCaches now Language is non-exhaustive
2025-08-05 18:09:37 +01:00
Henry Mercer
ea05bf27b6
Use more explicit checks on .length for readability
2025-08-05 17:55:50 +01:00
Henry Mercer
e682065360
Fix docstring in start-proxy
2025-08-05 17:51:51 +01:00
Henry Mercer
fa18cc9db4
Improve docstrings for language types
2025-08-05 17:49:01 +01:00
Henry Mercer
bf692c08e7
Merge branch 'main' into henrymercer/language-extensibility
2025-08-05 13:21:29 +01:00
Henry Mercer
83e92edc4b
Improve detection of Rust in languages input
2025-08-05 11:43:04 +01:00
Henry Mercer
bbfff2f20a
Merge pull request #2999 from github/henrymercer/deprecate-cleanup-level
...
Deprecate the 'cleanup-level' option
2025-08-05 11:22:53 +01:00
Henry Mercer
cfb8d07200
Remove unnecessary String initializations
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-08-05 11:18:46 +01:00
Henry Mercer
87e59d0f95
Improve changelog formatting
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2025-08-05 11:08:19 +01:00
Henry Mercer
c481481d7d
Merge branch 'main' into henrymercer/language-extensibility
2025-08-05 11:07:39 +01:00
Henry Mercer
e37c03628f
Merge pull request #3001 from github/dependabot/npm_and_yarn/npm-5c47c8ab2f
...
Bump the npm group with 5 updates
2025-08-05 11:05:58 +01:00
github-actions[bot]
563cbbb24d
Update checked-in dependencies
2025-08-05 09:51:38 +00:00
Henry Mercer
443f94c758
Bump @types/node
2025-08-05 10:45:17 +01:00
Henry Mercer
a5cdb299bc
Merge pull request #3002 from github/dependabot/github_actions/actions-f69d1f6078
...
Bump ruby/setup-ruby from 1.253.0 to 1.254.0 in the actions group
2025-08-05 10:27:07 +01:00
Henry Mercer
5547ed31c9
Bump version in generated source
2025-08-05 10:14:47 +01:00
dependabot[bot]
69ccd54e34
Bump ruby/setup-ruby from 1.253.0 to 1.254.0 in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.253.0 to 1.254.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](bb6434c747...2a7b30092b )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.254.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-04 23:16:04 +00:00
github-actions[bot]
a3810fa54b
Update checked-in dependencies
2025-08-04 22:26:01 +00:00
dependabot[bot]
a28b9b5e2f
Bump the npm group with 5 updates
...
Bumps the npm group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [follow-redirects](https://github.com/follow-redirects/follow-redirects ) | `1.15.9` | `1.15.11` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.38.0` | `8.39.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.38.0` | `8.39.0` |
| [nock](https://github.com/nock/nock ) | `14.0.7` | `14.0.8` |
| [typescript](https://github.com/microsoft/TypeScript ) | `5.8.3` | `5.9.2` |
Updates `follow-redirects` from 1.15.9 to 1.15.11
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases )
- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.9...v1.15.11 )
Updates `@typescript-eslint/eslint-plugin` from 8.38.0 to 8.39.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.38.0 to 8.39.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.39.0/packages/parser )
Updates `nock` from 14.0.7 to 14.0.8
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.7...v14.0.8 )
Updates `typescript` from 5.8.3 to 5.9.2
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml )
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.8.3...v5.9.2 )
---
updated-dependencies:
- dependency-name: follow-redirects
dependency-version: 1.15.11
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.39.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.39.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.8
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: typescript
dependency-version: 5.9.2
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-08-04 22:25:25 +00:00
github-actions[bot]
fff9bbe33f
Add changelog note
2025-08-04 18:41:52 +00:00
github-actions[bot]
cfa0a4e416
Update default bundle to codeql-bundle-v2.22.3
2025-08-04 18:41:48 +00:00
Henry Mercer
f9d6919415
Add changelog note
2025-08-04 18:00:50 +01:00
Henry Mercer
e95a3a9768
Deprecate the 'cleanup-level' option
2025-08-04 17:52:09 +01:00
Paolo Tranquilli
a58e7d8cef
Simplify rust check
2025-08-04 17:38:29 +02:00
Paolo Tranquilli
662cec85ed
Merge branch 'main' into redsun82/rust
2025-08-04 17:24:20 +02:00
Koen Vlaswinkel
7273f08caa
Merge pull request #2991 from github/koesie10/remove-disable-combine-sarif-files-ff
...
Remove `disable_combine_sarif_files` feature flag
2025-08-01 16:33:16 +02:00
dependabot[bot]
b9b3b12fa2
Bump form-data from 2.5.1 to 2.5.5 in the npm_and_yarn group ( #2982 )
...
* Bump form-data from 2.5.1 to 2.5.5 in the npm_and_yarn group
Bumps the npm_and_yarn group with 1 update: [form-data](https://github.com/form-data/form-data ).
Updates `form-data` from 2.5.1 to 2.5.5
- [Release notes](https://github.com/form-data/form-data/releases )
- [Changelog](https://github.com/form-data/form-data/blob/v2.5.5/CHANGELOG.md )
- [Commits](https://github.com/form-data/form-data/compare/v2.5.1...v2.5.5 )
---
updated-dependencies:
- dependency-name: form-data
dependency-version: 2.5.5
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com >
* Update checked-in dependencies
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Michael B. Gale <mbg@github.com >
2025-07-30 16:14:48 +01:00
Michael B. Gale
20c7f06b9a
Merge pull request #2995 from github/dependabot/github_actions/actions-010b5c0fb1
...
Bump ruby/setup-ruby from 1.247.0 to 1.253.0 in the actions group
2025-07-30 11:31:54 +01:00
Chuan-kai Lin
acdac9e37d
Merge pull request #2998 from github/mergeback/v3.29.5-to-main-51f77329
...
Mergeback v3.29.5 refs/heads/releases/v3 into main
2025-07-29 14:26:29 -07:00
github-actions[bot]
1a4f45d622
Update checked-in dependencies
2025-07-29 21:09:35 +00:00
github-actions[bot]
297691ddab
Update changelog and version after v3.29.5
2025-07-29 21:06:19 +00:00
Chuan-kai Lin
51f77329af
Merge pull request #2997 from github/update-v3.29.5-80a09d7b0
...
Merge main into releases/v3
2025-07-29 14:05:50 -07:00
github-actions[bot]
8e90243ddb
Update changelog for v3.29.5
2025-07-29 20:38:47 +00:00
Michael B. Gale
0521b5facf
Merge branch 'main' into koesie10/remove-disable-combine-sarif-files-ff
2025-07-29 18:27:02 +01:00
Michael B. Gale
84720e2ef6
Update workflow template
2025-07-29 18:26:18 +01:00
Michael B. Gale
80a09d7b0b
Merge pull request #2996 from github/dependabot/npm_and_yarn/npm-240ab9fad0
...
Bump the npm group with 2 updates
2025-07-29 18:24:06 +01:00
Michael B. Gale
8388115dc8
Merge pull request #2994 from github/mergeback/changelog/v3.28.21
...
Update changelog for v3.28.21
2025-07-29 18:22:54 +01:00
Michael B. Gale
401ecaf503
Merge branch 'main' into mergeback/changelog/v3.28.21
2025-07-29 18:10:01 +01:00
Michael B. Gale
45f48a349a
Merge branch 'main' into dependabot/github_actions/actions-010b5c0fb1
2025-07-29 18:09:37 +01:00
Michael B. Gale
ab5c0c5fa5
Merge branch 'main' into dependabot/npm_and_yarn/npm-240ab9fad0
2025-07-29 18:09:06 +01:00
Chuan-kai Lin
cd264d4dcd
Merge pull request #2986 from github/update-bundle/codeql-bundle-v2.22.2
...
Update default bundle to 2.22.2
2025-07-29 10:08:44 -07:00
Chuan-kai Lin
4599055b1e
Merge branch 'main' into update-bundle/codeql-bundle-v2.22.2
2025-07-29 09:55:25 -07:00
Michael B. Gale
fd7ad511e6
Merge pull request #2971 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-07-29 17:49:02 +01:00
Michael B. Gale
ac0c9bfe1e
Merge branch 'main' into update-supported-enterprise-server-versions
2025-07-29 17:31:16 +01:00
Chuan-kai Lin
88d99b3033
Stop testing stable-v2.16.6
2025-07-29 09:14:16 -07:00
Chuan-kai Lin
409486919c
Merge branch 'main' into update-bundle/codeql-bundle-v2.22.2
2025-07-29 07:36:07 -07:00
Michael B. Gale
abbda19c1d
Update README
2025-07-29 06:14:17 +01:00
Michael B. Gale
eb90c18c83
Update version constants
2025-07-29 06:05:45 +01:00
github-actions[bot]
12e4b97fba
Update checked-in dependencies
2025-07-28 22:01:01 +00:00
dependabot[bot]
264ce42cbb
Bump the npm group with 2 updates
...
Bumps the npm group with 2 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) and [nock](https://github.com/nock/nock ).
Updates `@eslint/js` from 9.31.0 to 9.32.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.32.0/packages/js )
Updates `nock` from 14.0.6 to 14.0.7
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.6...v14.0.7 )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.32.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.7
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-28 22:00:18 +00:00
dependabot[bot]
d8be08468e
Bump ruby/setup-ruby from 1.247.0 to 1.253.0 in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.247.0 to 1.253.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](4727905401...bb6434c747 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.253.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-28 19:59:14 +00:00
Michael B. Gale
9b6aeca680
Update changelog for v3.28.21
2025-07-28 16:21:05 +01:00
Koen Vlaswinkel
a005f73253
Remove disable_combine_sarif_files feature flag
2025-07-24 11:12:32 +02:00
Michael B. Gale
701df0e49d
Merge pull request #2990 from github/mergeback/v3.29.4-to-main-4e828ff8
...
Mergeback v3.29.4 refs/heads/releases/v3 into main
2025-07-23 14:31:38 +01:00
github-actions[bot]
06bb1e016c
Update checked-in dependencies
2025-07-23 13:17:48 +00:00
github-actions[bot]
264c5cf3c9
Update changelog and version after v3.29.4
2025-07-23 13:16:22 +00:00
Michael B. Gale
4e828ff8d4
Merge pull request #2989 from github/update-v3.29.4-37264dc0b
...
Merge main into releases/v3
2025-07-23 14:15:56 +01:00
github-actions[bot]
b3114b8965
Update changelog for v3.29.4
2025-07-23 13:00:50 +00:00
Koen Vlaswinkel
37264dc0b3
Merge pull request #2988 from github/koesie10/disable-combine-single-file
...
Disable combining runs within a single file
2025-07-23 14:17:59 +02:00
Koen Vlaswinkel
5a29823d01
Merge remote-tracking branch 'origin/main' into koesie10/disable-combine-single-file
2025-07-23 14:03:16 +02:00
Michael B. Gale
5a2327a6fd
Merge pull request #2987 from github/mbg/combine-sarif-error
...
Treat processing error for multiple runs with the same category as configuration error
2025-07-23 13:02:32 +01:00
Koen Vlaswinkel
287d421cf3
Disable combining runs within a single file
2025-07-23 13:51:13 +02:00
Michael B. Gale
43afe6ec0b
Treat processing error for multiple runs with the same category as configuration error
...
This will result in it being reported as a user error rather than a failure
2025-07-23 12:48:44 +01:00
github-actions[bot]
0f549a757b
Add changelog note
2025-07-23 11:07:01 +00:00
github-actions[bot]
f67ceea75b
Update default bundle to codeql-bundle-v2.22.2
2025-07-23 11:06:57 +00:00
Michael B. Gale
8f2e63676d
Merge pull request #2981 from github/dependabot/npm_and_yarn/npm-fe13dfda46
...
Bump the npm group with 5 updates
2025-07-23 09:29:24 +01:00
Michael B. Gale
76bf77db0b
Merge pull request #2980 from github/dependabot/github_actions/actions-504b6cee34
...
Bump ruby/setup-ruby from 1.245.0 to 1.247.0 in the actions group
2025-07-22 18:24:17 +01:00
Michael B. Gale
9e7d13dd99
Merge pull request #2983 from github/koesie10/update-changelog-link
...
Update combining SARIF runs changelog post URL
2025-07-22 18:09:52 +01:00
Michael B. Gale
2b952be91d
Update workflow template
2025-07-22 13:31:35 +01:00
Koen Vlaswinkel
48ce740f61
Update combining SARIF runs changelog post URL
2025-07-22 11:51:12 +02:00
github-actions[bot]
4749491b98
Update checked-in dependencies
2025-07-21 19:50:38 +00:00
dependabot[bot]
b7a5452764
Bump the npm group with 5 updates
...
Bumps the npm group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [@types/node-forge](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node-forge ) | `1.3.12` | `1.3.13` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.30.1` | `9.31.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.35.1` | `8.38.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.35.1` | `8.38.0` |
| [nock](https://github.com/nock/nock ) | `14.0.5` | `14.0.6` |
Updates `@types/node-forge` from 1.3.12 to 1.3.13
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node-forge )
Updates `@eslint/js` from 9.30.1 to 9.31.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.31.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.35.1 to 8.38.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.38.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.35.1 to 8.38.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.38.0/packages/parser )
Updates `nock` from 14.0.5 to 14.0.6
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.5...v14.0.6 )
---
updated-dependencies:
- dependency-name: "@types/node-forge"
dependency-version: 1.3.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.31.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.38.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.38.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.6
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-21 19:49:59 +00:00
dependabot[bot]
20477a3fe1
Bump ruby/setup-ruby from 1.245.0 to 1.247.0 in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.245.0 to 1.247.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](a4effe49ee...4727905401 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.247.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-21 18:34:27 +00:00
Chuan-kai Lin
eefe1b5db9
Merge pull request #2975 from github/cklin/overlay-telemetry
...
Overlay: report telemetry
2025-07-21 06:23:15 -07:00
Koen Vlaswinkel
b6332872af
Merge pull request #2979 from github/koesie10/v3.28.20-changelog
...
Add changelog entry for v3.28.20 backport
2025-07-21 14:56:14 +02:00
Koen Vlaswinkel
8e442bc480
Merge pull request #2978 from github/mergeback/v3.29.3-to-main-d6bbdef4
...
Mergeback v3.29.3 refs/heads/releases/v3 into main
2025-07-21 13:49:06 +02:00
Koen Vlaswinkel
a7cb1b8b39
Add changelog entry for v3.28.20 backport
2025-07-21 13:38:40 +02:00
github-actions[bot]
b195e1bfc6
Update checked-in dependencies
2025-07-21 11:35:49 +00:00
github-actions[bot]
df82387698
Update changelog and version after v3.29.3
2025-07-21 11:33:16 +00:00
Koen Vlaswinkel
d6bbdef45e
Merge pull request #2977 from github/update-v3.29.3-7710ed11e
...
Merge main into releases/v3
2025-07-21 13:32:49 +02:00
github-actions[bot]
210cc9bfa2
Update changelog for v3.29.3
2025-07-21 09:29:13 +00:00
Chuan-kai Lin
39b0524b50
build: refresh js files
2025-07-18 07:45:45 -07:00
Chuan-kai Lin
c3bbcab41b
Add downloadOverlayBaseDatabaseFromCache tests
2025-07-18 07:44:43 -07:00
Chuan-kai Lin
e37b293334
Overlay: report overlay-base database stats
2025-07-18 07:44:22 -07:00
Chuan-kai Lin
19075c4376
Overlay: report overlay analysis mode
2025-07-18 07:18:38 -07:00
Chuan-kai Lin
7710ed11e3
Merge pull request #2970 from github/cklin/diff-informed-feature-enable
...
Enable Feature.DiffInformedQueries
2025-07-17 08:21:08 -07:00
Chuan-kai Lin
6a49a8cbce
build: refresh js files
2025-07-17 06:17:30 -07:00
Chuan-kai Lin
3aef4108d1
Add diff-informed-analysis-utils.test.ts
2025-07-17 06:14:37 -07:00
Chuan-kai Lin
614b64c6ec
Diff-informed analysis: disable for GHES below 3.19
2025-07-17 06:10:14 -07:00
Chuan-kai Lin
aefb854fe5
Feature.DiffInformedQueries: default to true
2025-07-17 06:03:52 -07:00
Chuan-kai Lin
03a2a17e75
Merge pull request #2967 from github/cklin/overlay-feature-flags
...
Overlay: additional feature flags
2025-07-17 05:54:21 -07:00
Koen Vlaswinkel
07455ed3c3
Merge pull request #2972 from github/koesie10/ghes-satisfies
...
Ignore pre-release parts when comparing GHES versions
2025-07-17 10:35:33 +02:00
Chuan-kai Lin
3fb562ddcc
build: refresh js files
2025-07-16 07:10:40 -07:00
Chuan-kai Lin
709cf22a66
Limit Code Scanning API to 25 features per request
2025-07-16 07:07:44 -07:00
Chuan-kai Lin
3eaefb4deb
Replicate "too many feature flags" error in test
2025-07-16 07:06:52 -07:00
Koen Vlaswinkel
e30db30685
Ignore pre-release parts when comparing GHES versions
2025-07-16 11:51:53 +02:00
Arthur Baars
0d17ea4843
Merge pull request #2963 from github/dependabot/npm_and_yarn/npm-d16eacb461
...
Bump the npm group across 1 directory with 7 updates
2025-07-15 14:45:25 +02:00
Arthur Baars
38fdaed818
npm run build
2025-07-15 07:33:26 +00:00
github-actions[bot]
37e3c3113a
Update checked-in dependencies
2025-07-15 07:33:26 +00:00
Arthur Baars
15605b194f
Make eslint happy
2025-07-15 07:31:22 +00:00
Arthur Baars
0b8d278f47
Run: npx update-browserslist-db@latest
2025-07-15 07:30:36 +00:00
Arthur Baars
ca53360d04
Fix tests
2025-07-15 07:25:49 +00:00
Arthur Baars
bbf184bd4c
Update ava
2025-07-15 07:25:49 +00:00
github-actions[bot]
b419190c59
Update supported GitHub Enterprise Server versions
2025-07-15 00:18:48 +00:00
dependabot[bot]
0c2ac60444
Bump the npm group across 1 directory with 7 updates
...
Bumps the npm group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@types/node-forge](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node-forge ) | `1.3.11` | `1.3.12` |
| [@ava/typescript](https://github.com/avajs/typescript ) | `4.1.0` | `6.0.0` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `1.1.1` | `1.3.1` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.28.0` | `9.30.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.33.1` | `8.35.1` |
| [sinon](https://github.com/sinonjs/sinon ) | `20.0.0` | `21.0.0` |
Updates `@types/node-forge` from 1.3.11 to 1.3.12
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node-forge )
Updates `@ava/typescript` from 4.1.0 to 6.0.0
- [Release notes](https://github.com/avajs/typescript/releases )
- [Commits](https://github.com/avajs/typescript/compare/v4.1.0...v6.0.0 )
Updates `@eslint/compat` from 1.1.1 to 1.3.1
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v1.3.1/packages/compat )
Updates `@eslint/js` from 9.28.0 to 9.30.1
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.30.1/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.33.1 to 8.35.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.35.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.33.1 to 8.35.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.35.1/packages/parser )
Updates `sinon` from 20.0.0 to 21.0.0
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/commits )
---
updated-dependencies:
- dependency-name: "@types/node-forge"
dependency-version: 1.3.12
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@ava/typescript"
dependency-version: 6.0.0
dependency-type: direct:development
update-type: version-update:semver-major
dependency-group: npm
- dependency-name: "@eslint/compat"
dependency-version: 1.3.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.30.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.35.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.35.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: sinon
dependency-version: 21.0.0
dependency-type: direct:development
update-type: version-update:semver-major
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-07-14 20:52:48 +00:00
Koen Vlaswinkel
6f936b5c2d
Merge pull request #2969 from github/koesie10/fix-ghes-version-parsing
...
Fix parsing of GHES pre-release versions
2025-07-14 13:42:48 +02:00
Koen Vlaswinkel
c6a6c1490f
Move comment to JSDoc
2025-07-14 13:18:38 +02:00
Michael B. Gale
4e20239e7b
Merge pull request #2951 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-07-14 10:39:53 +01:00
Koen Vlaswinkel
59d67fc4bf
Fix parsing of GHES pre-release versions
2025-07-14 11:25:20 +02:00
Chuan-kai Lin
b37e7e2c5d
Move initializeFeatures() to testing-utils
...
This change eliminates the need for setup-codeql.test to import from
feature-flags.test, which makes the former run all tests defined in the
latter.
2025-07-11 09:54:40 -07:00
Chuan-kai Lin
90d7727554
Overlay: check code-scanning features
2025-07-10 14:16:19 -07:00
Chuan-kai Lin
fb771764cb
Extract generateCodeScanningConfig()
2025-07-10 14:14:46 -07:00
Chuan-kai Lin
d799ff5e6a
Overlay: check per-language features
2025-07-10 14:14:14 -07:00
Chuan-kai Lin
9f70a5fc86
Overlay: define language-specific features
2025-07-10 11:09:28 -07:00
Chuan-kai Lin
55cb6b8b94
Extract isOverlayAnalysisFeatureEnabled()
2025-07-10 10:48:43 -07:00
Chuan-kai Lin
4bdb7fe04f
Overlay database mode tests: list features
...
Before we introduce additional features for controlling overlay analysis
enablement, change the unit tests to specify features directly instead
of through a isFeatureEnabled boolean field.
2025-07-10 10:46:32 -07:00
Chuan-kai Lin
64fce5856f
Use exclude-from-incremental also for overlay analysis
2025-07-09 14:32:05 -07:00
Chuan-kai Lin
fe7205c739
Move getOverlayDatabaseMode() call into initConfig()
...
In an upcoming change, getOverlayDatabaseMode() will depend on the
contents of Config. As a result, getOverlayDatabaseMode() needs to be
called after the rest of Config has already been populated.
This commit performs the refactoring to move the
getOverlayDatabaseMode() into initConfig(), after the rest of Config has
already been populated.
2025-07-09 14:32:05 -07:00
Chuan-kai Lin
4cd7a721f7
Remove loadConfig()
...
The loadConfig() function is mostly the same as getDefaultConfig(),
except that it calls loadUserConfig() and stores the results in
originalUserInput.
This refactoring commit replaces the loadConfig() call with
getDefaultConfig() and loadUserConfig(), which allows deleting a large
amount of duplicated code.
2025-07-09 14:32:05 -07:00
Chuan-kai Lin
f4358b38d1
Extract loadUserConfig()
2025-07-09 14:32:05 -07:00
Koen Vlaswinkel
f53ec7c550
Merge pull request #2961 from github/koesie10/disable-combine-sarif-files-ghes
...
Unconditionally disable combining SARIF files for GHES 3.18
2025-07-08 10:01:06 +02:00
Chuan-kai Lin
624d0bca90
Merge pull request #2945 from github/cklin/overlay-analysis
...
Basic support for overlay PR analysis
2025-07-07 08:41:24 -07:00
Chuan-kai Lin
ec836d6b8a
build: refresh js files
2025-07-07 08:15:20 -07:00
Chuan-kai Lin
95a1b7e2bf
Add getOverlayDatabaseMode() tests
2025-07-07 08:14:41 -07:00
Chuan-kai Lin
8c5122ea75
Add getPullRequestBranches() tests
2025-07-07 08:13:06 -07:00
Koen Vlaswinkel
aafbeb29bc
Unconditionally disable combining SARIF files for GHES 3.18
2025-07-04 15:24:36 +02:00
Chuan-kai Lin
6a51e635a5
Add "overlay" to SARIF incrementalMode run property
2025-07-03 12:35:25 -07:00
Chuan-kai Lin
42835b3971
Override cleanup-level for overlay-base database
2025-07-03 12:35:25 -07:00
Chuan-kai Lin
2fc04c80cc
Download overlay-base database from actions cache
2025-07-03 12:35:25 -07:00
Chuan-kai Lin
b95402dae1
Extract checkOverlayBaseDatabase()
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
6ca06f41c4
Upload overlay-base database to actions cache
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
d42ce71087
Add AugmentationProperties.useOverlayDatabaseCaching
...
This commit adds useOverlayDatabaseCaching to AugmentationProperties to
indicate whether the action should upload overlay-base databases to the
actions cache and to download a cached overlay-base database when
creating an overlay database.
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
b4425372ef
Limit OverlayAnalysis to internal repos
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
93e8729640
getOverlayDatabaseMode: use Feature.OverlayAnalysis
...
This commit changes getOverlayDatabaseMode so that, when
Feature.OverlayAnalysis is enabled, it calculates the overlay database
mode automatically based on analysis metadata. If we are analyzing the
default branch, use OverlayBase, and if we are analyzing a PR, use
Overlay.
If CODEQL_OVERLAY_DATABASE_MODE is set to a valid overlay database mode,
that environment variable still takes precedence.
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
da758dc0cd
Add Feature.OverlayAnalysis
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
60a2a7d623
Add isAnalyzingPullRequest()
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
a336faa497
databaseInitCluster: use overlayDatabaseMode from config
...
This commit changes databaseInitCluster() to use overlayDatabaseMode
from AugmentationProperties instead of the overlayDatabaseMode
parameter. There is no behavior change because both overlayDatabaseMode
values are computed the same way.
The commit then cleans up the overlayDatabaseMode parameter and the code
paths that feed into it.
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
ee8a8c4e0b
config-utils: populate getOverlayDatabaseMode()
...
This commit populates getOverlayDatabaseMode() in config-utils with the
same code from getOverlayDatabaseMode() in init.
2025-07-03 12:35:24 -07:00
Chuan-kai Lin
9022c7382c
Add AugmentationProperties.overlayDatabaseMode
...
This commit adds overlayDatabaseMode to AugmentationProperties and
creates a placeholder getOverlayDatabaseMode() function, with the
necessary inputs, to populate it.
2025-07-03 12:35:24 -07:00
Paolo Tranquilli
34786468fa
Rust: remove shipped feature flag
2025-07-03 15:43:01 +02:00
Michael B. Gale
b69421388d
Merge pull request #2956 from github/mbg/start-proxy/validation-improvements
...
Improve JSON validation in `start-proxy` action
2025-07-03 12:23:56 +01:00
Koen Vlaswinkel
33f84897c3
Merge pull request #2959 from github/koesie10/remove-combine-runs
...
Remove support for combining SARIF runs with non-unique categories
2025-07-02 14:34:01 +02:00
Koen Vlaswinkel
612df8d91c
Remove support for combining SARIF runs with non-unique categories
2025-07-01 15:20:28 +02:00
Michael B. Gale
dcc1a6637b
Merge pull request #2958 from github/mergeback/v3.29.2-to-main-181d5eef
...
Mergeback v3.29.2 refs/heads/releases/v3 into main
2025-06-30 14:15:46 +01:00
github-actions[bot]
144d3b8f62
Update checked-in dependencies
2025-06-30 13:02:41 +00:00
github-actions[bot]
6881d2cdc1
Update changelog and version after v3.29.2
2025-06-30 13:01:12 +00:00
Michael B. Gale
181d5eefc2
Merge pull request #2957 from github/update-v3.29.2-4c57370d0
...
Merge main into releases/v3
2025-06-30 14:00:45 +01:00
Michael B. Gale
c77386a9db
Fix changelog PR number
2025-06-30 13:48:01 +01:00
github-actions[bot]
8d43d4ecec
Update changelog for v3.29.2
2025-06-30 12:44:54 +00:00
Michael B. Gale
9281048a40
Include goproxy_server in configuration filtering tests
2025-06-27 14:32:16 +01:00
Michael B. Gale
6b83dc33ed
Check for null in addition to undefined; extend tests accordingly
2025-06-27 14:32:16 +01:00
Michael B. Gale
ca0540d370
Check that individual proxy configurations are objects
2025-06-27 14:32:16 +01:00
Michael B. Gale
e9938e34d5
Check that proxy configurations are an array
2025-06-27 14:32:15 +01:00
Michael B. Gale
4c57370d03
Merge pull request #2935 from github/mbg/interpret-cq-results
...
Produce separate SARIF file for `quality-queries` alerts
2025-06-27 14:03:38 +01:00
Michael B. Gale
2830b750e5
Add changelog entry
2025-06-27 13:49:45 +01:00
Michael B. Gale
aa72ddaead
Merge branch 'main' into mbg/interpret-cq-results
2025-06-27 13:45:51 +01:00
Michael B. Gale
65d1e45f0b
Rename SARIF_UPLOAD_ENDPOINT members
2025-06-27 13:45:14 +01:00
Michael B. Gale
362ebf85da
Check both SARIF files in quality-queries.yml test
2025-06-27 12:32:56 +01:00
Michael B. Gale
10a3e4b17d
Fix formatting
2025-06-27 12:32:56 +01:00
Arthur Baars
8593ea65e2
Merge pull request #2954 from github/mergeback/v3.29.1-to-main-39edc492
...
Mergeback v3.29.1 refs/heads/releases/v3 into main
2025-06-27 13:11:54 +02:00
Michael B. Gale
3e95091e3b
Add test workflow for upload-sarif with quality results
2025-06-27 12:11:12 +01:00
Michael B. Gale
7b3d150883
Use findSarifFilesInDir in upload-sarif to avoid error when there are no quality.sarif files
2025-06-27 12:08:40 +01:00
github-actions[bot]
2e3a72539c
Update checked-in dependencies
2025-06-27 10:52:35 +00:00
github-actions[bot]
baf20c9b52
Update changelog and version after v3.29.1
2025-06-27 10:44:54 +00:00
Arthur Baars
39edc492db
Merge pull request #2953 from github/update-v3.29.1-428aea55f
...
Merge main into releases/v3
2025-06-27 12:44:25 +02:00
github-actions[bot]
27c4fb1eef
Update changelog for v3.29.1
2025-06-27 10:15:45 +00:00
Mads Navntoft
428aea55f5
Merge pull request #2952 from github/redsun82/fix-swift-test
...
Swift: recreate a default Swift package to fix test
2025-06-27 07:27:03 +02:00
Paolo Tranquilli
973250f3d2
Swift: recreate a default Swift package to fix test
2025-06-26 17:41:45 +02:00
Michael B. Gale
ad6046ff97
Avoid default arguments with historical values
2025-06-26 13:51:08 +01:00
Michael B. Gale
9ec0bb9605
Fix incorrect getSarifFilePaths call in upload-sarif action
2025-06-26 12:22:08 +01:00
Arthur Baars
8ef17824cf
Merge pull request #2950 from github/update-bundle/codeql-bundle-v2.22.1
...
Update default bundle to 2.22.1
2025-06-26 12:53:13 +02:00
Michael B. Gale
08955dbc0d
Move .sarif predicates into UploadTarget instances and rename
2025-06-26 11:43:36 +01:00
Michael B. Gale
71dd63398f
Rename SARIF_UPLOAD_TARGET
2025-06-26 11:38:45 +01:00
Michael B. Gale
27db6cb5d6
Document queries parameter for databaseRunQueries
2025-06-26 11:37:10 +01:00
Michael B. Gale
768fc170da
Rename resolveQuerySuiteAlias parameter
2025-06-26 11:32:48 +01:00
Michael B. Gale
79049d92c6
Fix config-queries.qls location
2025-06-25 14:42:24 +01:00
Michael B. Gale
e382508853
Prototyping adding quality queries when running queries
2025-06-25 14:24:34 +01:00
Michael B. Gale
2c76207fa4
Upload .quality.sarif files to CQ service in upload-sarif action
2025-06-25 13:43:39 +01:00
github-actions[bot]
83de9b082b
Update supported GitHub Enterprise Server versions
2025-06-25 00:17:41 +00:00
github-actions[bot]
f3bfb98603
Add changelog note
2025-06-24 14:13:14 +00:00
github-actions[bot]
2b4afc20b6
Update default bundle to codeql-bundle-v2.22.1
2025-06-24 14:13:10 +00:00
Michael B. Gale
86f47e8b74
Add some more comments
2025-06-24 13:59:46 +01:00
Michael B. Gale
9b9286a835
Add test for resolveQuerySuiteAlias
2025-06-24 13:42:52 +01:00
Michael B. Gale
af32bc6d6f
Add test for modified validateUniqueCategory
2025-06-24 13:26:34 +01:00
Michael B. Gale
51891595a7
Add test for modified findSarifFilesInDir
2025-06-24 13:24:04 +01:00
Michael B. Gale
f7fbaa019f
Support all default query suites and resolve them
2025-06-24 13:08:56 +01:00
Michael B. Gale
9b02dc2f60
Merge pull request #2928 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-06-24 12:42:08 +01:00
Michael B. Gale
7ab92d0295
Merge pull request #2948 from github/mbg/copilot-instructions
...
Add initial Copilot instructions
2025-06-24 12:41:11 +01:00
Michael B. Gale
2cae828745
Merge pull request #2947 from github/dependency-proxy/codeql-bundle-v2.22.0
...
Update release used by `start-proxy` to `codeql-bundle-v2.22.0`
2025-06-24 12:28:40 +01:00
Michael B. Gale
6b78c6eca2
Update .github/copilot-instructions.md
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-06-24 12:27:18 +01:00
Michael B. Gale
f7258be256
Add initial Copilot instructions
2025-06-24 12:26:04 +01:00
github-actions[bot]
35083eedc1
Update release used by start-proxy action
2025-06-24 11:09:10 +00:00
Michael B. Gale
80e2dc47d8
Merge pull request #2941 from github/mbg/update-proxy-binaries
...
Add workflow for updating release used by `start-proxy`
2025-06-24 12:07:32 +01:00
Michael B. Gale
2e3b93fe41
Remove push trigger that was used for testing
2025-06-24 11:34:13 +01:00
Michael B. Gale
bbfc5bef5b
Replace inline expressions with environment variables
2025-06-24 11:30:24 +01:00
Michael B. Gale
6abacdb184
Fix getSarifFilePaths not using right filter
2025-06-23 18:19:43 +01:00
Michael B. Gale
f1834221f2
Allow the same category once for each type of upload
2025-06-23 18:19:43 +01:00
Michael B. Gale
45b3bec064
Upload quality SARIFs to CQ endpoint
2025-06-23 18:19:42 +01:00
Michael B. Gale
22444a650f
Add ability to use different filters in findSarifFilesInDir
2025-06-23 18:19:42 +01:00
Michael B. Gale
320f7b0fd6
Resolve code-quality alias
2025-06-23 18:19:42 +01:00
Michael B. Gale
3a7544ea8f
Check SARIF with quality results for expected configuration
2025-06-23 18:19:42 +01:00
Michael B. Gale
aba8788d12
Upload both SARIF files in quality-queries check
2025-06-23 18:19:42 +01:00
Michael B. Gale
3963bf423a
Interpret results for quality queries and store as separate SARIF file
2025-06-23 18:19:40 +01:00
Michael B. Gale
6e22e41a25
Add reminder to mark PR as ready for review to trigger CI
2025-06-23 17:57:53 +01:00
Michael B. Gale
0cec254fa1
Use --dry-run for non-workflow_dispatch events
2025-06-23 17:57:52 +01:00
Michael B. Gale
6a3692d673
Construct target branch name in checks step
2025-06-23 17:57:52 +01:00
Michael B. Gale
9ee60a6e32
Run on Ubuntu
2025-06-23 17:57:52 +01:00
Michael B. Gale
cce0287569
Check that the release exists
2025-06-23 17:57:52 +01:00
Michael B. Gale
e044b152ab
Check that the release tag has the expected format
2025-06-23 17:57:51 +01:00
Michael B. Gale
46cafbca67
Add missing v to regex
2025-06-23 12:56:13 +01:00
Michael B. Gale
fcd0ad43d5
Start with main
2025-06-23 12:47:58 +01:00
Michael B. Gale
c55fb0ab89
Fix pr_body contents
2025-06-23 12:46:45 +01:00
Michael B. Gale
37a3fcc3af
Improve PR title formatting
2025-06-23 12:45:26 +01:00
Michael B. Gale
7ca4105454
Fix branch name
2025-06-23 12:45:06 +01:00
Michael B. Gale
286556a968
Fix pr_title quotes
2025-06-23 12:41:56 +01:00
Michael B. Gale
e8ad3afb1e
Add push trigger for testing
2025-06-23 12:39:21 +01:00
Michael B. Gale
0180811a94
Use environment variable to store release tag
2025-06-23 12:34:21 +01:00
Michael B. Gale
6b9b66d6f9
Add workflow for updating release used by start-proxy
2025-06-23 12:31:20 +01:00
Michael B. Gale
ac30a39d8c
Merge pull request #2931 from github/mbg/fail-build.sh-on-error
...
Fail `build.sh` if any command in it fails
2025-06-20 11:04:42 +01:00
Chuan-kai Lin
66d72553a2
Merge pull request #2938 from github/cklin/default-query-filters
...
Keep user-provided query filters first
2025-06-19 13:46:30 -07:00
Chuan-kai Lin
65abb79a75
build: refresh js files
2025-06-19 12:19:33 -07:00
Chuan-kai Lin
0b8d151adc
Keep user-provided query filters first
2025-06-19 12:19:33 -07:00
Chuan-kai Lin
f5304e7bf5
Rename defaultQueryFilters
...
This commit renames AugmentationProperties.defaultQueryFilters to
extraQueryExclusions, and changes its type to ExcludeQueryFilter[]. It
matters whether we are adding query inclusions or exclusions, and this
renaming makes that distinction clearer.
2025-06-19 12:19:28 -07:00
Chuan-kai Lin
1764e3d1c2
Use defaultAugmentationProperties in tests
...
Using defaultAugmentationProperties to generated expected test output
eliminates the need to change individual tests when we add a new field
to AugmentationProperties.
2025-06-19 10:57:34 -07:00
Michael B. Gale
ef36b69c6d
Merge pull request #2936 from github/dependabot/github_actions/actions-aae69f6766
...
build(deps): bump ruby/setup-ruby from 1.244.0 to 1.245.0 in the actions group
2025-06-17 00:48:14 +01:00
Michael B. Gale
4cb21ac46b
Update workflow source file
2025-06-17 00:33:02 +01:00
dependabot[bot]
dee9f91810
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.244.0 to 1.245.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](13e7a03dc3...a4effe49ee )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.245.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-16 19:15:31 +00:00
Michael B. Gale
3de706a4a3
Merge pull request #2917 from github/mbg/use-cq-endpoint
...
Add new `quality-queries` input
2025-06-16 13:54:01 +01:00
Michael B. Gale
0fb9447fd1
Mark quality-queries input as "Internal" for now
2025-06-16 13:25:01 +01:00
Michael B. Gale
6b66390454
De-duplicate query array in generateCodeScanningConfig
2025-06-16 13:17:57 +01:00
Michael B. Gale
22b1968d7c
Add test for security and quality query inputs
2025-06-16 13:17:57 +01:00
Michael B. Gale
7e3bc059bb
Add basic check that resulting SARIF contains quality-queries queries
2025-06-16 13:17:57 +01:00
Michael B. Gale
f4c96f59d9
Pass quality queries to CLI
2025-06-16 13:17:57 +01:00
Michael B. Gale
87c547189e
Read and parse quality-queries input
2025-06-16 13:17:55 +01:00
Michael B. Gale
f10997b601
Add new quality-queries input to init action
2025-06-16 13:17:21 +01:00
Michael B. Gale
8f71d47b93
Add installGo input for adding setup-go step in sync.py
2025-06-16 12:28:23 +01:00
Michael B. Gale
ece6bb6fe7
Merge pull request #2934 from kgangulyvibe/patch-1
...
Update README.md
2025-06-16 12:12:53 +01:00
Kaushaya G.
3f8ca3519d
Update README.md
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2025-06-16 20:56:41 +10:00
Michael B. Gale
04b73050b2
Merge branch 'main' into update-supported-enterprise-server-versions
2025-06-16 11:08:09 +01:00
Michael B. Gale
2847b7f7ab
Merge pull request #2930 from github/mbg/start-proxy/mask-tokens
...
Register credentials extracted from proxy configuration as secrets
2025-06-16 10:59:24 +01:00
Kaushaya G.
3c60275a04
Update README.md
...
Build mode `none` is in public preview for C/C++. Readme updated.
2025-06-16 14:42:03 +10:00
Paolo Tranquilli
be30325fa6
Merge pull request #2929 from github/redsun82/rust
...
Prepare action for public rust support
2025-06-13 09:12:27 +02:00
Michael B. Gale
429b71ea4b
Fail build.sh if any command in it fails
2025-06-12 15:07:58 +01:00
Paolo Tranquilli
3d4b4d2241
Fix typo
2025-06-12 14:24:24 +02:00
Michael B. Gale
bbab10229f
Register credentials extracted from proxy configuration as secrets to mask in logs
2025-06-12 13:16:39 +01:00
Paolo Tranquilli
de1f97ca1d
Prepare action for public rust support
2025-06-12 12:59:58 +02:00
github-actions[bot]
e74e30ba7f
Update supported GitHub Enterprise Server versions
2025-06-12 00:17:16 +00:00
Chuan-kai Lin
466d6ce584
Merge pull request #2927 from github/mergeback/v3.29.0-to-main-ce28f5bb
...
Mergeback v3.29.0 refs/heads/releases/v3 into main
2025-06-11 12:57:26 -07:00
github-actions[bot]
853b3397ce
Update checked-in dependencies
2025-06-11 19:06:11 +00:00
github-actions[bot]
eaadd985c8
Update changelog and version after v3.29.0
2025-06-11 19:00:06 +00:00
Chuan-kai Lin
ce28f5bb42
Merge pull request #2926 from github/update-v3.29.0-e8799281c
...
Merge main into releases/v3
2025-06-11 11:59:41 -07:00
github-actions[bot]
bc251b7932
Update changelog for v3.29.0
2025-06-11 18:29:08 +00:00
Chuan-kai Lin
e8799281c8
Merge pull request #2925 from github/update-bundle/codeql-bundle-v2.22.0
...
Update default bundle to 2.22.0
2025-06-11 08:37:30 -07:00
Chuan-kai Lin
efd43b3097
Merge branch 'main' into update-bundle/codeql-bundle-v2.22.0
2025-06-10 06:56:41 -07:00
Michael B. Gale
7cb9b16051
Merge pull request #2912 from github/henrymercer/bump-minimum-codeql-2.16.6
...
Bump minimum CodeQL version to 2.16.6
2025-06-09 22:43:41 +01:00
github-actions[bot]
3855117ba1
Add changelog note
2025-06-09 20:28:37 +00:00
github-actions[bot]
f5d4e2a7ca
Update default bundle to codeql-bundle-v2.22.0
2025-06-09 20:28:33 +00:00
Arthur Baars
22deae890c
Update package-lock.json
2025-06-05 13:43:46 +02:00
Arthur Baars
df2a830ca4
Merge branch 'main' into henrymercer/bump-minimum-codeql-2.16.6
2025-06-05 13:41:07 +02:00
Michael B. Gale
b1e4dc3db5
Merge pull request #2916 from github/dependabot/npm_and_yarn/npm-5cdccdc43f
...
build(deps): bump the npm group with 5 updates
2025-06-04 21:51:29 +01:00
Michael B. Gale
72be4b6df6
Merge pull request #2922 from github/mbg/fix/sanitizeArtifactName
...
Fix backslashes being accepted by `sanitizeArtifactName`
2025-06-04 21:46:46 +01:00
Michael B. Gale
1eab40885f
Fix backslashes being accepted by sanitizeArtifactName
2025-06-04 12:28:25 +01:00
Arthur Baars
075e08aca6
Merge pull request #2919 from github/mergeback/v3.28.19-to-main-fca7ace9
...
Mergeback v3.28.19 refs/heads/releases/v3 into main
2025-06-03 15:28:32 +02:00
github-actions[bot]
be60d9f5f9
Update checked-in dependencies
2025-06-03 13:11:09 +00:00
github-actions[bot]
a28627ae8f
Update changelog and version after v3.28.19
2025-06-03 13:08:53 +00:00
Arthur Baars
fca7ace96b
Merge pull request #2918 from github/update-v3.28.19-4a00331d4
...
Merge main into releases/v3
2025-06-03 15:08:22 +02:00
github-actions[bot]
1dcd2bebbb
Update changelog for v3.28.19
2025-06-03 12:37:58 +00:00
github-actions[bot]
313daefcef
Update checked-in dependencies
2025-06-02 17:50:04 +00:00
dependabot[bot]
55ff016766
build(deps): bump the npm group with 5 updates
...
Bumps the npm group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [octokit](https://github.com/octokit/octokit.js ) | `5.0.2` | `5.0.3` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.27.0` | `9.28.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.32.1` | `8.33.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.32.1` | `8.33.1` |
| [nock](https://github.com/nock/nock ) | `14.0.4` | `14.0.5` |
Updates `octokit` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/octokit/octokit.js/releases )
- [Commits](https://github.com/octokit/octokit.js/compare/v5.0.2...v5.0.3 )
Updates `@eslint/js` from 9.27.0 to 9.28.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.28.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.32.1 to 8.33.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.33.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.32.1 to 8.33.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.33.1/packages/parser )
Updates `nock` from 14.0.4 to 14.0.5
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.4...v14.0.5 )
---
updated-dependencies:
- dependency-name: octokit
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.28.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.33.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.33.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-06-02 17:48:34 +00:00
Arthur Baars
4a00331d4e
Merge pull request #2910 from github/update-bundle/codeql-bundle-v2.21.4
...
Update default bundle to 2.21.4
2025-06-02 13:38:25 +02:00
github-actions[bot]
c0a821da11
Add changelog note
2025-06-02 13:23:20 +02:00
github-actions[bot]
d6216866b4
Update default bundle to codeql-bundle-v2.21.4
2025-06-02 13:23:20 +02:00
Paolo Tranquilli
dc138d4f51
Merge pull request #2913 from github/henrymercer/win-2019-deprecated
...
Stop running CI on `windows-2019`
2025-06-02 09:13:58 +02:00
Henry Mercer
a28197c30c
Fix early return for no autobuild languages
2025-05-30 18:11:05 +01:00
Henry Mercer
1d22e8316c
Rust: Set experimental features variable before language parsing
2025-05-30 18:09:25 +01:00
Henry Mercer
932be8feda
Rename Language enum and use generic Language where possible
2025-05-30 18:02:15 +01:00
Henry Mercer
e303175b83
Use CodeQL CLI to parse languages
2025-05-30 18:02:14 +01:00
Henry Mercer
fa0b6fff20
Clarify meaning of Language enum
2025-05-30 17:58:20 +01:00
Henry Mercer
3b57965c44
Remove per-language hardcoded traced/scanned info
2025-05-30 17:58:19 +01:00
Henry Mercer
3201e46e26
Stop running CI on windows-2019
...
There are scheduled brownouts for this runner image. Replace it with `windows-2025`, and start running on `macos-15` too.
2025-05-30 17:57:28 +01:00
Henry Mercer
d54c5e2206
Add changelog note
2025-05-30 17:52:01 +01:00
Henry Mercer
36121ec458
Bump minor version number
2025-05-30 17:52:01 +01:00
Henry Mercer
7419bc61b3
Update CodeQL versions in generated workflows
2025-05-30 17:52:01 +01:00
Henry Mercer
c7f3c79ac0
Remove guards for fully enabled tool features
2025-05-30 17:52:01 +01:00
Henry Mercer
0be24c0c9a
Remove redundant code based on CLI version number
2025-05-30 17:11:02 +01:00
Henry Mercer
fb70a8a3d6
Bump minimum CodeQL version to 2.16.6
2025-05-30 17:05:33 +01:00
Henry Mercer
7fd62151d9
Merge pull request #2911 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-05-28 11:36:35 +01:00
github-actions[bot]
31eae5e821
Update supported GitHub Enterprise Server versions
2025-05-28 00:17:14 +00:00
Henry Mercer
bc02a25f64
Merge pull request #2908 from github/henrymercer/dependabot
...
Dependabot: Remove deprecated `reviewers` config
2025-05-27 16:48:31 +01:00
Henry Mercer
1a67b5df99
Merge pull request #2905 from github/dependabot/github_actions/actions-92be4e1609
...
build(deps): bump ruby/setup-ruby from 1.242.0 to 1.244.0 in the actions group
2025-05-27 13:51:23 +01:00
Henry Mercer
97fbf51190
Merge pull request #2907 from github/dependabot/npm_and_yarn/npm-41871dd9e3
...
build(deps): bump the npm group across 1 directory with 2 updates
2025-05-27 13:49:38 +01:00
Henry Mercer
eaed21baf2
Dependabot: Remove deprecated reviewers config
...
This field will soon be ignored
2025-05-27 13:40:01 +01:00
github-actions[bot]
655a969b7c
Update checked-in dependencies
2025-05-27 12:34:30 +00:00
dependabot[bot]
3934d2b758
build(deps): bump the npm group across 1 directory with 2 updates
...
Bumps the npm group with 2 updates in the / directory: [@octokit/types](https://github.com/octokit/types.ts ) and [octokit](https://github.com/octokit/octokit.js ).
Updates `@octokit/types` from 14.0.0 to 14.1.0
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v14.0.0...v14.1.0 )
Updates `octokit` from 4.1.3 to 5.0.2
- [Release notes](https://github.com/octokit/octokit.js/releases )
- [Commits](https://github.com/octokit/octokit.js/compare/v4.1.3...v5.0.2 )
---
updated-dependencies:
- dependency-name: "@octokit/types"
dependency-version: 14.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: octokit
dependency-version: 5.0.2
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-27 12:33:52 +00:00
Henry Mercer
0abe43cb59
Update generated workflow source
2025-05-27 13:33:09 +01:00
dependabot[bot]
83a4df546f
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.242.0 to 1.244.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](cb0fda56a3...13e7a03dc3 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.244.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-26 17:29:05 +00:00
Henry Mercer
7b0fb5a4ac
Merge pull request #2899 from github/dependabot/github_actions/actions-999e423561
...
build(deps): bump ruby/setup-ruby from 1.230.0 to 1.242.0 in the actions group
2025-05-22 16:05:07 +01:00
Henry Mercer
23262aef80
Merge pull request #2898 from github/dependabot/npm_and_yarn/npm-aa8c6e63b8
...
build(deps-dev): bump @eslint/js from 9.26.0 to 9.27.0 in the npm group
2025-05-22 15:52:32 +01:00
Henry Mercer
5239ab193d
Merge pull request #2787 from github/dbartol/remove-actions-extractor
...
Remove bundled copy of `actions` extractor
2025-05-22 15:52:03 +01:00
Henry Mercer
bcaa06bbb4
Update generated workflow source to match
2025-05-22 15:48:29 +01:00
Henry Mercer
b63847bb99
Update version number in changelog
2025-05-22 15:37:50 +01:00
Andrew Eisenberg
54a7f3b869
Merge branch 'main' into dbartol/remove-actions-extractor
2025-05-21 23:38:42 -04:00
dependabot[bot]
ba7fabd835
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.230.0 to 1.242.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](e5ac7b085f...cb0fda56a3 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.242.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-19 18:11:59 +00:00
github-actions[bot]
cae4996048
Update checked-in dependencies
2025-05-19 18:02:02 +00:00
dependabot[bot]
566c8dfa81
build(deps-dev): bump @eslint/js from 9.26.0 to 9.27.0 in the npm group
...
Bumps the npm group with 1 update: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ).
Updates `@eslint/js` from 9.26.0 to 9.27.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.27.0/packages/js )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.27.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-19 18:01:21 +00:00
Henry Mercer
396fd27c30
Merge pull request #2895 from github/dependabot/npm_and_yarn/npm_and_yarn-87115a91ec
...
build(deps): bump undici from 5.28.5 to 5.29.0 in the npm_and_yarn group
2025-05-19 12:31:15 +01:00
Chris Smowton
57eebf61a2
Merge pull request #2897 from github/mergeback/v3.28.18-to-main-ff0a06e8
...
Mergeback v3.28.18 refs/heads/releases/v3 into main
2025-05-16 11:33:31 +01:00
github-actions[bot]
4428f8e35c
Update checked-in dependencies
2025-05-16 10:17:48 +00:00
github-actions[bot]
655a335537
Update changelog and version after v3.28.18
2025-05-16 10:15:17 +00:00
Chris Smowton
ff0a06e83c
Merge pull request #2896 from github/update-v3.28.18-b86edfc27
...
Merge main into releases/v3
2025-05-16 11:14:47 +01:00
github-actions[bot]
a41e0844be
Update changelog for v3.28.18
2025-05-16 09:36:50 +00:00
github-actions[bot]
99ec5f3dd6
Update checked-in dependencies
2025-05-15 16:31:59 +00:00
dependabot[bot]
c07c4ee026
build(deps): bump undici from 5.28.5 to 5.29.0 in the npm_and_yarn group
...
Bumps the npm_and_yarn group with 1 update: [undici](https://github.com/nodejs/undici ).
Updates `undici` from 5.28.5 to 5.29.0
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v5.28.5...v5.29.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 5.29.0
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-15 16:31:22 +00:00
Chris Smowton
b86edfc27a
Merge pull request #2893 from github/update-bundle/codeql-bundle-v2.21.3
...
Update default bundle to 2.21.3
2025-05-15 12:40:00 +01:00
Henry Mercer
e93b90025f
Merge branch 'main' into update-bundle/codeql-bundle-v2.21.3
2025-05-14 19:57:41 +01:00
Henry Mercer
510dfa3460
Merge pull request #2894 from github/henrymercer/skip-validating-codeql-sarif
...
Skip validating SARIF produced by CodeQL
2025-05-14 19:55:03 +01:00
Henry Mercer
492d783245
Merge branch 'main' into henrymercer/skip-validating-codeql-sarif
2025-05-14 19:16:54 +01:00
Henry Mercer
83bdf3b7f9
Merge pull request #2859 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-05-14 19:15:31 +01:00
Andrew Eisenberg
cffc916774
Merge pull request #2891 from austinpray-mixpanel/patch-1
...
Allow configuring CODEQL_THREADS with an env var
2025-05-14 14:00:23 -04:00
Henry Mercer
4420887272
Add deprecation warning for CodeQL 2.16.5 and earlier
2025-05-14 17:13:10 +01:00
Henry Mercer
4e178c5841
Update supported versions table in README
2025-05-14 17:12:44 +01:00
Henry Mercer
05446e4bbf
Merge branch 'main' into update-supported-enterprise-server-versions
2025-05-14 16:58:40 +01:00
Austin Pray
bb9fc01aa6
Update CHANGELOG.md
2025-05-14 10:44:35 -05:00
Austin Pray
3dce55ac70
rebuild
2025-05-14 15:41:39 +00:00
github-actions[bot]
bacf5fe7c2
Rebuild
2025-05-14 14:23:08 +00:00
Henry Mercer
15f19ac220
Improve docstring
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-05-14 15:21:38 +01:00
Henry Mercer
f7ab654551
Add changelog note
2025-05-14 15:12:22 +01:00
Henry Mercer
2f70a988e7
Skip validating SARIF produced by CodeQL
2025-05-14 15:11:16 +01:00
Henry Mercer
f681ad69a7
Add utility function to get testing environment
2025-05-14 14:10:19 +01:00
github-actions[bot]
15447f393e
Add changelog note
2025-05-13 22:28:13 +00:00
github-actions[bot]
ded79fc5fd
Update default bundle to codeql-bundle-v2.21.3
2025-05-13 22:28:10 +00:00
Austin Pray
77ae18dc82
Revert "threads defaults to CODEQL_THREADS env var"
...
This reverts commit df7d681f04 .
2025-05-13 22:19:47 +00:00
Austin Pray
df7d681f04
threads defaults to CODEQL_THREADS env var
2025-05-13 20:13:00 +00:00
Nick Fyson
15bce5bb14
Merge pull request #2892 from github/dependabot/npm_and_yarn/npm-9a9ecb9151
...
build(deps): bump the npm group across 1 directory with 4 updates
2025-05-13 11:35:20 +01:00
Nick Fyson
c64095f75e
Merge pull request #2889 from github/dependabot/github_actions/actions-b37916a4ef
...
build(deps): bump the actions group with 2 updates
2025-05-13 11:16:24 +01:00
nickfyson
07dbe6f6f7
update generated workflows
2025-05-13 11:02:59 +01:00
github-actions[bot]
3d97729508
Update checked-in dependencies
2025-05-12 18:01:08 +00:00
dependabot[bot]
d5e9ae3f8b
build(deps): bump the npm group across 1 directory with 4 updates
...
Bumps the npm group with 4 updates in the / directory: [semver](https://github.com/npm/node-semver ), [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `semver` from 7.7.1 to 7.7.2
- [Release notes](https://github.com/npm/node-semver/releases )
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md )
- [Commits](https://github.com/npm/node-semver/compare/v7.7.1...v7.7.2 )
Updates `@eslint/js` from 9.25.1 to 9.26.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.26.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.31.1 to 8.32.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.32.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.31.1 to 8.32.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.32.1/packages/parser )
---
updated-dependencies:
- dependency-name: semver
dependency-version: 7.7.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.26.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.32.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.32.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-12 18:00:33 +00:00
Austin Pray
c41b278fa8
Allow configuring CODEQL_THREADS with an env var
...
ref https://github.com/github/codeql-action/issues/2890
2025-05-05 21:28:43 -05:00
dependabot[bot]
7657741c79
build(deps): bump the actions group with 2 updates
...
Bumps the actions group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.230.0 to 1.237.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](e5ac7b085f...eaecf785f6 )
Updates `actions/create-github-app-token` from 2.0.2 to 2.0.6
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.0.2...v2.0.6 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.237.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: actions/create-github-app-token
dependency-version: 2.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-05-05 18:27:10 +00:00
Nick Rolfe
5eb3ed6614
Merge pull request #2887 from github/mergeback/v3.28.17-to-main-60168efe
...
Mergeback v3.28.17 refs/heads/releases/v3 into main
2025-05-02 11:26:39 +01:00
github-actions[bot]
213a8a5a44
Update checked-in dependencies
2025-05-02 09:30:05 +00:00
github-actions[bot]
c46165d67e
Update changelog and version after v3.28.17
2025-05-02 09:27:21 +00:00
Nick Rolfe
60168efe1c
Merge pull request #2886 from github/update-v3.28.17-97a2bfd2a
...
Merge main into releases/v3
2025-05-02 10:26:47 +01:00
github-actions[bot]
0d5a3115da
Update changelog for v3.28.17
2025-05-02 09:10:30 +00:00
Nick Rolfe
97a2bfd2a3
Merge pull request #2872 from github/update-bundle/codeql-bundle-v2.21.2
...
Update default bundle to 2.21.2
2025-05-01 13:31:16 +01:00
Nick Rolfe
9aba20e4c9
Merge branch 'main' into update-bundle/codeql-bundle-v2.21.2
2025-05-01 13:16:31 +01:00
Henry Mercer
81a9508deb
Merge pull request #2876 from github/henrymercer/fix-diff-informed-multiple-analyze
...
Do not fail diff informed analyses when analyze is run twice in the same job
2025-05-01 13:07:58 +01:00
Henry Mercer
1569f4c145
Disable diff-informed queries in code scanning config tests
2025-05-01 12:14:34 +01:00
Henry Mercer
62fbeb66b3
Merge branch 'main' into henrymercer/fix-diff-informed-multiple-analyze
2025-05-01 12:05:02 +01:00
Henry Mercer
f122d1dc9e
Address test failures from computing temporary directory too early
...
These relied on the RUNNER_TEMP environment variable that does not necessarily exist when running locally.
2025-05-01 12:01:22 +01:00
Henry Mercer
083772aae4
Do not fail diff informed analyses when analyze is run twice in the same job
2025-05-01 12:00:46 +01:00
Nick Rolfe
5db14d0471
Merge branch 'main' into update-bundle/codeql-bundle-v2.21.2
2025-05-01 10:28:59 +01:00
Andrew Eisenberg
40e16edda1
Merge pull request #2874 from github/aeisenberg/add-actions-telemetry
...
Add actions-specific telemetry fields
2025-04-30 08:02:38 -07:00
Andrew Eisenberg
3ca9a88941
Add actions-specific telemetry fields
2025-04-29 16:14:46 -07:00
Henry Mercer
ed51cb5abd
Merge pull request #2873 from github/dependabot/npm_and_yarn/npm-a5e2fd638a
...
build(deps-dev): bump the npm group with 2 updates
2025-04-29 11:36:38 +01:00
Andrew Eisenberg
8ccb6b16a6
Merge pull request #2861 from github/dependabot/github_actions/actions-0553007f0f
...
build(deps): bump ruby/setup-ruby from 1.229.0 to 1.230.0 in the actions group
2025-04-29 03:21:43 -07:00
github-actions[bot]
1817a33c8b
Update checked-in dependencies
2025-04-28 18:49:27 +00:00
dependabot[bot]
6893d12604
build(deps-dev): bump the npm group with 2 updates
...
Bumps the npm group with 2 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@typescript-eslint/eslint-plugin` from 8.31.0 to 8.31.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.31.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.31.0 to 8.31.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.31.1/packages/parser )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.31.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.31.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-28 18:48:49 +00:00
Henry Mercer
83605b3ce2
Merge pull request #2864 from github/dependabot/npm_and_yarn/npm-cac24ffe08
...
build(deps): bump the npm group across 1 directory with 7 updates
2025-04-28 18:34:13 +01:00
github-actions[bot]
6a3cfab0e9
Add changelog note
2025-04-28 15:20:43 +00:00
github-actions[bot]
4b7eecf8a7
Update default bundle to codeql-bundle-v2.21.2
2025-04-28 15:20:40 +00:00
Michael B. Gale
018ac1a585
Merge pull request #2834 from github/mbg/private-registry/goproxy
...
Go: Support `GOPROXY` via the Dependabot proxy
2025-04-28 11:11:41 +01:00
Michael B. Gale
6ad5d99ccc
Add goproxy_server to LANGUAGE_TO_REGISTRY_TYPE
2025-04-25 16:56:36 +01:00
Michael B. Gale
f843d94177
Merge pull request #2869 from github/mbg/proxy/use-2.21.1-artifacts
...
Use proxy artifacts for `v2.21.1`
2025-04-25 16:50:50 +01:00
Michael B. Gale
2264a4ecc1
Merge branch 'main' into mbg/proxy/use-2.21.1-artifacts
2025-04-25 14:25:57 +01:00
Michael B. Gale
d3b65fcaf0
Merge pull request #2870 from github/mbg/ci/retire-ubuntu-20.04
...
Remove ubuntu-20.04 and add ubuntu-24.04
2025-04-25 14:25:40 +01:00
Michael B. Gale
eea52ddc4e
Remove ubuntu-20.04 and add ubuntu-24.04
2025-04-25 13:03:25 +01:00
Michael B. Gale
6ef9b921b1
Use proxy artifacts for v2.21.1
2025-04-24 18:20:31 +01:00
Ian Lynagh
4ffa2364a0
Merge pull request #2867 from github/mergeback/v3.28.16-to-main-28deaeda
...
Mergeback v3.28.16 refs/heads/releases/v3 into main
2025-04-23 13:34:31 +01:00
github-actions[bot]
7e00290d34
Update checked-in dependencies
2025-04-23 12:17:11 +00:00
github-actions[bot]
259434501f
Update changelog and version after v3.28.16
2025-04-23 12:10:49 +00:00
Ian Lynagh
28deaeda66
Merge pull request #2865 from github/update-v3.28.16-2a8cbadc0
...
Merge main into releases/v3
2025-04-23 13:10:18 +01:00
github-actions[bot]
03c5d71c11
Update changelog for v3.28.16
2025-04-23 10:40:48 +00:00
Ian Lynagh
2a8cbadc02
Merge pull request #2863 from github/update-bundle/codeql-bundle-v2.21.1
...
Update default bundle to 2.21.1
2025-04-22 12:30:12 +01:00
github-actions[bot]
95d52b7807
Update checked-in dependencies
2025-04-21 18:01:41 +00:00
dependabot[bot]
c9f0d30a86
build(deps): bump the npm group across 1 directory with 7 updates
...
Bumps the npm group with 7 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@octokit/types](https://github.com/octokit/types.ts ) | `13.10.0` | `14.0.0` |
| [long](https://github.com/dcodeIO/long.js ) | `5.3.1` | `5.3.2` |
| [octokit](https://github.com/octokit/octokit.js ) | `4.1.2` | `4.1.3` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.24.0` | `9.25.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.29.0` | `8.31.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.29.0` | `8.31.0` |
| [nock](https://github.com/nock/nock ) | `14.0.3` | `14.0.4` |
Updates `@octokit/types` from 13.10.0 to 14.0.0
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v13.10.0...v14.0.0 )
Updates `long` from 5.3.1 to 5.3.2
- [Release notes](https://github.com/dcodeIO/long.js/releases )
- [Commits](https://github.com/dcodeIO/long.js/compare/v5.3.1...v5.3.2 )
Updates `octokit` from 4.1.2 to 4.1.3
- [Release notes](https://github.com/octokit/octokit.js/releases )
- [Commits](https://github.com/octokit/octokit.js/compare/v4.1.2...v4.1.3 )
Updates `@eslint/js` from 9.24.0 to 9.25.1
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.25.1/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.29.0 to 8.31.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.31.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.29.0 to 8.31.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.31.0/packages/parser )
Updates `nock` from 14.0.3 to 14.0.4
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.3...v14.0.4 )
---
updated-dependencies:
- dependency-name: "@octokit/types"
dependency-version: 14.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: npm
- dependency-name: long
dependency-version: 5.3.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: octokit
dependency-version: 4.1.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-version: 9.25.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.31.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.31.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-21 18:01:03 +00:00
github-actions[bot]
f76eaf51a6
Add changelog note
2025-04-16 16:54:18 +00:00
github-actions[bot]
e63b3f5166
Update default bundle to codeql-bundle-v2.21.1
2025-04-16 16:54:11 +00:00
Andrew Eisenberg
c0cffae534
Update checks file
2025-04-14 14:00:02 -07:00
dependabot[bot]
7eaba0dbc6
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.229.0 to 1.230.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](354a1ad156...e5ac7b085f )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.230.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-14 17:57:59 +00:00
Marco Gario
a3e50f3d11
Clean-up logic for overriding proxy
2025-04-11 12:05:03 +00:00
github-actions[bot]
d1c7d49753
Update supported GitHub Enterprise Server versions
2025-04-11 00:16:14 +00:00
Andrew Eisenberg
4c3e536282
Merge pull request #2853 from github/dependabot/npm_and_yarn/npm-7d84c66b66
...
build(deps-dev): bump the npm group with 3 updates
2025-04-10 16:31:21 -07:00
Nick Fyson
56dd02f26d
Merge pull request #2852 from github/dependabot/github_actions/actions-4575878e06
...
build(deps): bump actions/create-github-app-token from 1.12.0 to 2.0.2 in the actions group
2025-04-09 17:18:03 +01:00
Nick Fyson
192406dd84
Merge branch 'main' into dependabot/github_actions/actions-4575878e06
2025-04-09 16:59:59 +01:00
Nick Fyson
c7dbb2084e
Merge pull request #2857 from github/nickfyson/address-vulns
...
move use of input variables into env vars
2025-04-09 16:05:04 +01:00
nickfyson
9a45cd8c50
move use of input variables into env vars
2025-04-09 14:13:35 +01:00
Andrew Eisenberg
d26c46acea
Merge pull request #2855 from github/mergeback/v3.28.15-to-main-45775bd8
...
Mergeback v3.28.15 refs/heads/releases/v3 into main
2025-04-07 14:48:19 -07:00
github-actions[bot]
51c83e1588
Update checked-in dependencies
2025-04-07 21:34:58 +00:00
github-actions[bot]
8774e3f945
Update changelog and version after v3.28.15
2025-04-07 21:32:19 +00:00
Andrew Eisenberg
45775bd823
Merge pull request #2854 from github/update-v3.28.15-a35ae8c38
...
Merge main into releases/v3
2025-04-07 14:31:50 -07:00
Andrew Eisenberg
dd78aab407
Update CHANGELOG.md with bug fix details
2025-04-07 14:15:05 -07:00
github-actions[bot]
e40af59174
Update changelog for v3.28.15
2025-04-07 21:05:03 +00:00
Chuan-kai Lin
a35ae8c380
Merge pull request #2843 from github/cklin/diff-informed-compat
...
Set checkPresence in diff-range data extension
2025-04-07 13:29:16 -07:00
github-actions[bot]
5bddbeb2bf
Update checked-in dependencies
2025-04-07 17:59:50 +00:00
dependabot[bot]
c7102cdca1
build(deps-dev): bump the npm group with 3 updates
...
Bumps the npm group with 3 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [nock](https://github.com/nock/nock ) and [typescript](https://github.com/microsoft/TypeScript ).
Updates `@eslint/js` from 9.23.0 to 9.24.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.24.0/packages/js )
Updates `nock` from 14.0.2 to 14.0.3
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.2...v14.0.3 )
Updates `typescript` from 5.8.2 to 5.8.3
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml )
- [Commits](https://github.com/microsoft/TypeScript/commits )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.24.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-version: 14.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: typescript
dependency-version: 5.8.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-07 17:59:17 +00:00
dependabot[bot]
a1ca4846bc
build(deps): bump actions/create-github-app-token in the actions group
...
Bumps the actions group with 1 update: [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `actions/create-github-app-token` from 1.12.0 to 2.0.2
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v1.12.0...v2.0.2 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 2.0.2
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-07 17:53:11 +00:00
Andrew Eisenberg
bb59df6c17
Merge pull request #2842 from github/henrymercer/zip64
...
Raise the file limit for debug artifacts by producing zip64 files where necessary
2025-04-07 10:50:46 -07:00
Arthur Baars
4b508f5964
Merge pull request #2845 from github/mergeback/v3.28.14-to-main-fc7e4a0f
...
Mergeback v3.28.14 refs/heads/releases/v3 into main
2025-04-07 13:04:29 +02:00
github-actions[bot]
ca00afb5f1
Update checked-in dependencies
2025-04-07 09:33:21 +00:00
github-actions[bot]
2969c78ce0
Update changelog and version after v3.28.14
2025-04-07 09:27:28 +00:00
Arthur Baars
fc7e4a0fa0
Merge pull request #2844 from github/update-v3.28.14-362ef4ce2
...
Merge main into releases/v3
2025-04-07 11:26:56 +02:00
github-actions[bot]
be0175c800
Update changelog for v3.28.14
2025-04-07 09:09:01 +00:00
Andrew Eisenberg
a8be43c24e
Don't throw error for ENOENT
2025-04-04 13:42:00 -07:00
Chuan-kai Lin
94102d99b0
Set checkPresence in diff-range data extension
...
This commit updates the diff-range data extension to use the new
checkPresence field being introduced in CodeQL CLI 2.21.0, so that
diff-informed analysis no longer fails when a query pack does not have
the restrictAlertsTo extensible predicate.
2025-04-04 08:41:50 -07:00
github-actions[bot]
fd8685f16e
Update checked-in dependencies
2025-04-04 13:46:53 +00:00
Henry Mercer
56feaac968
Raise file limit in debug artifacts by using zip64
2025-04-04 14:40:53 +01:00
Arthur Baars
362ef4ce20
Merge pull request #2838 from github/update-bundle/codeql-bundle-v2.21.0
...
Update default bundle to 2.21.0
2025-04-03 15:40:24 +02:00
Arthur Baars
2b85c00718
Merge branch 'main' into update-bundle/codeql-bundle-v2.21.0
2025-04-03 15:28:09 +02:00
Angela P Wen
41aa437638
Merge pull request #2841 from github/angelapwen/log-init-post-telemetry
...
Add logs around status report telemetry in `init-post` step
2025-04-03 14:51:03 +02:00
Angela P Wen
92864f48b0
Add logs around status report telemetry in init-post step
2025-04-03 14:37:27 +02:00
Andrew Eisenberg
46fbf563e6
Merge branch 'main' into dbartol/remove-actions-extractor
2025-04-02 12:40:53 -07:00
Fotis Koutoulakis
e13fe0dd2d
Merge pull request #2833 from github/NlightNFotis/reclassify_upload_sarif_issues
...
feat: further error re-classification
2025-04-02 20:09:36 +01:00
Andrew Eisenberg
4a19b5125b
Merge branch 'main' into dbartol/remove-actions-extractor
2025-04-02 11:14:54 -07:00
Fotis Koutoulakis
06703ce3e5
Merge branch 'main' into NlightNFotis/reclassify_upload_sarif_issues
2025-04-02 19:06:45 +01:00
Fotis Koutoulakis (@NlightNFotis)
676a422916
review-comments: nest validateSariFileSchema into try-catch block to better discriminate error thrown
2025-04-02 19:06:31 +01:00
Fotis Koutoulakis (@NlightNFotis)
498c7f37e8
review-comments: unwrap error in upload-sarif-action and re-classify as ConfigurationError if in known error category
2025-04-02 15:20:03 +01:00
Fotis Koutoulakis (@NlightNFotis)
efd29bef22
refactor: revert getActionsStatus taking an extra argument
2025-04-02 15:13:00 +01:00
Angela P Wen
dab8a02091
Merge pull request #2836 from github/dependabot/github_actions/actions-02c935407f
...
build(deps): bump the actions group with 2 updates
2025-04-02 14:57:29 +02:00
Angela P Wen
10771737a9
Merge pull request #2840 from github/dependabot/npm_and_yarn/npm-05c8aca45e
...
build(deps-dev): bump the npm group across 1 directory with 4 updates
2025-04-02 14:56:55 +02:00
Angela P Wen
17379bcd20
Manually update PR check workflow
2025-04-02 14:43:55 +02:00
github-actions[bot]
dbb232a3d8
Update checked-in dependencies
2025-04-02 12:43:14 +00:00
dependabot[bot]
4b72bef651
build(deps-dev): bump the npm group across 1 directory with 4 updates
...
Bumps the npm group with 4 updates in the / directory: [@types/semver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/semver ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [nock](https://github.com/nock/nock ).
Updates `@types/semver` from 7.5.8 to 7.7.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver )
Updates `@typescript-eslint/eslint-plugin` from 8.28.0 to 8.29.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.29.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.28.0 to 8.29.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.29.0/packages/parser )
Updates `nock` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.1...v14.0.2 )
---
updated-dependencies:
- dependency-name: "@types/semver"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: nock
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-04-02 12:42:37 +00:00
Fotis Koutoulakis (@NlightNFotis)
b53826d56d
review-comments: remove syntax-error handling for SARIF from upload-lib
2025-04-01 15:10:16 +01:00
Fotis Koutoulakis (@NlightNFotis)
55ee663d5f
review-comments: refactor getActionsStatus to accept an extra parameter designating if the analysis is third-party
2025-04-01 14:58:59 +01:00
github-actions[bot]
a27e401674
Add changelog note
2025-04-01 13:51:07 +00:00
github-actions[bot]
a69f5113b7
Update default bundle to codeql-bundle-v2.21.0
2025-04-01 13:51:03 +00:00
dependabot[bot]
b6f76bd566
build(deps): bump the actions group with 2 updates
...
Bumps the actions group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.227.0 to 1.229.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](1a615958ad...354a1ad156 )
Updates `actions/create-github-app-token` from 1.11.7 to 1.12.0
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v1.11.7...v1.12.0 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: actions/create-github-app-token
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-31 17:16:14 +00:00
Fotis Koutoulakis (@NlightNFotis)
01f1a1f2c9
Merge branch 'main' into NlightNFotis/reclassify_upload_sarif_issues
2025-03-31 16:29:02 +01:00
Chuan-kai Lin
efffb483ec
Merge pull request #2831 from github/cklin/diff-informed-query-filtering
...
Respect `exclude-from-incremental` query tag for diff-informed analysis
2025-03-31 08:00:50 -07:00
Fotis Koutoulakis (@NlightNFotis)
f21cf0bbd7
feat: reclassify InvalidSarifUploadError as a user-error when final status report is produced
2025-03-31 12:22:18 +01:00
Fotis Koutoulakis (@NlightNFotis)
72a2b1295e
feat: classify some observed SARIF errors as InvalidSarifUploadError
2025-03-31 12:17:23 +01:00
Fotis Koutoulakis (@NlightNFotis)
a022653e2d
feat: classify more HTTP errors as configuration errors in api-client
2025-03-31 11:54:16 +01:00
Fotis Koutoulakis (@NlightNFotis)
3c42562190
fix: update comment for test to state correct expected outcome
2025-03-31 11:51:11 +01:00
Chuan-kai Lin
e4ca874973
build: refresh js files
2025-03-28 12:30:40 -07:00
Chuan-kai Lin
e7f67e2e61
Redefine shouldPerformDiffInformedAnalysis()
...
This commit renames the original shouldPerformDiffInformedAnalysis(),
which returns `PullRequestBranches | undefined`, to
getDiffInformedAnalysisBranches(). It also adds a new
shouldPerformDiffInformedAnalysis() function that returns boolean.
Separating these two functions makes it clear what the intended uses and
return values should be for each.
2025-03-28 12:29:28 -07:00
Fotis Koutoulakis
9f45e7498b
Merge pull request #2832 from github/NlightNFotis/fix_config_error_classification
...
fix: change regex matching for API error to not contain regex boundaries
2025-03-28 15:18:02 +00:00
Fotis Koutoulakis (@NlightNFotis)
73c938dbc0
fix: fix issue where wrapApiConfigurationError would fail to regex match a string due to boundary constraints on the regex
2025-03-28 14:38:06 +00:00
Fotis Koutoulakis (@NlightNFotis)
2be6da694a
test: add tests for the wrapApiConfigurationError function
2025-03-28 14:37:10 +00:00
Fotis Koutoulakis (@NlightNFotis)
76f9ed9cd9
test: add tests to validate getActionsStatus' behaviour
2025-03-28 14:37:10 +00:00
Chuan-kai Lin
71ab101d38
Set default query filter for diff-informed analysis
2025-03-27 14:06:40 -07:00
Chuan-kai Lin
da967b1ade
AugmentationProperties: add defaultQueryFilters
...
This commit adds a defaultQueryFilters field to AugmentationProperties
and incorporates its value into the augmented Code Scanning config.
However, in this commit defaultQueryFilters is always empty, so there is
not yet any actual behavior change.
2025-03-27 13:44:47 -07:00
Chuan-kai Lin
3c4533916b
Call shouldPerformDiffInformedAnalysis() outside setupDiffInformedQueryRun()
2025-03-27 10:27:24 -07:00
Chuan-kai Lin
1994ea768e
Move shouldPerformDiffInformedAnalysis()
2025-03-27 10:27:24 -07:00
Chuan-kai Lin
534bc63d5e
Rename diff-filtering-utils.ts to diff-informed-analysis-utils.ts
2025-03-27 10:27:23 -07:00
Chuan-kai Lin
3fbee52426
Extract shouldPerformDiffInformedAnalysis()
2025-03-27 10:27:23 -07:00
Chuan-kai Lin
9bd18b486f
Merge pull request #2830 from github/cklin/code-scanning-repo
...
getFileDiffsWithBasehead(): use CODE_SCANNING_REPOSITORY if present
2025-03-27 10:25:27 -07:00
Chuan-kai Lin
0afd488dc1
build: refresh js files
2025-03-27 08:50:55 -07:00
Chuan-kai Lin
c1fc897eb2
getFileDiffsWithBasehead(): use CODE_SCANNING_REPOSITORY if present
2025-03-27 08:50:31 -07:00
Chuan-kai Lin
f88459c0a3
Use getRepositoryNwo()
2025-03-26 10:18:40 -07:00
Chuan-kai Lin
b22f3341fe
Add getRepositoryNwo() helper functions
2025-03-26 08:11:16 -07:00
Henry Mercer
486ab5a292
Merge pull request #2827 from github/dependabot/npm_and_yarn/npm-6956921c2d
...
build(deps): bump the npm group with 8 updates
2025-03-24 21:40:41 +00:00
github-actions[bot]
5275714183
Update checked-in dependencies
2025-03-24 21:18:42 +00:00
dependabot[bot]
08e5c8d618
build(deps): bump the npm group with 8 updates
...
Bumps the npm group with 8 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `4.0.2` | `4.0.3` |
| [@octokit/types](https://github.com/octokit/types.ts ) | `13.8.0` | `13.10.0` |
| [@eslint/eslintrc](https://github.com/eslint/eslintrc ) | `3.3.0` | `3.3.1` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.22.0` | `9.23.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.26.1` | `8.28.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.26.1` | `8.28.0` |
| [eslint-import-resolver-typescript](https://github.com/import-js/eslint-import-resolver-typescript ) | `3.8.3` | `3.8.7` |
| [sinon](https://github.com/sinonjs/sinon ) | `19.0.2` | `20.0.0` |
Updates `@actions/cache` from 4.0.2 to 4.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@octokit/types` from 13.8.0 to 13.10.0
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v13.8.0...v13.10.0 )
Updates `@eslint/eslintrc` from 3.3.0 to 3.3.1
- [Release notes](https://github.com/eslint/eslintrc/releases )
- [Changelog](https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslintrc/compare/v3.3.0...v3.3.1 )
Updates `@eslint/js` from 9.22.0 to 9.23.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.23.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.26.1 to 8.28.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.28.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.26.1 to 8.28.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.28.0/packages/parser )
Updates `eslint-import-resolver-typescript` from 3.8.3 to 3.8.7
- [Release notes](https://github.com/import-js/eslint-import-resolver-typescript/releases )
- [Changelog](https://github.com/import-js/eslint-import-resolver-typescript/blob/master/CHANGELOG.md )
- [Commits](https://github.com/import-js/eslint-import-resolver-typescript/compare/v3.8.3...v3.8.7 )
Updates `sinon` from 19.0.2 to 20.0.0
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v19.0.2...v20.0.0 )
---
updated-dependencies:
- dependency-name: "@actions/cache"
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@octokit/types"
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@eslint/eslintrc"
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@eslint/js"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: eslint-import-resolver-typescript
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: sinon
dependency-type: direct:development
update-type: version-update:semver-major
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-24 21:18:05 +00:00
Andrew Eisenberg
be853de3b7
Merge pull request #2822 from github/dependabot/github_actions/actions-cbe19e082f
...
build(deps): bump the actions group with 2 updates
2025-03-24 12:03:54 -07:00
Andrew Eisenberg
502426aa6b
Also update checks/rubocop-multi-language.yml
2025-03-24 11:50:24 -07:00
github-actions[bot]
4cdde5c397
Rebuild
2025-03-24 18:43:49 +00:00
dependabot[bot]
6ceaf4460c
build(deps): bump the actions group with 2 updates
...
Bumps the actions group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.226.0 to 1.227.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](922ebc4c52...1a615958ad )
Updates `actions/create-github-app-token` from 1.11.6 to 1.11.7
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v1.11.6...v1.11.7 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: actions/create-github-app-token
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-24 18:06:50 +00:00
Chuan-kai Lin
f15aac3db1
Merge pull request #2820 from github/mergeback/v3.28.13-to-main-1b549b92
...
Mergeback v3.28.13 refs/heads/releases/v3 into main
2025-03-24 07:41:49 -07:00
github-actions[bot]
e149e39832
Update checked-in dependencies
2025-03-24 13:48:13 +00:00
github-actions[bot]
f313d62247
Update changelog and version after v3.28.13
2025-03-24 13:43:41 +00:00
Chuan-kai Lin
1b549b9259
Merge pull request #2819 from github/update-v3.28.13-e0ea14102
...
Merge main into releases/v3
2025-03-24 06:42:41 -07:00
github-actions[bot]
82630c85f3
Update changelog for v3.28.13
2025-03-24 13:18:07 +00:00
Chuan-kai Lin
e0ea141027
Merge pull request #2818 from github/cklin/empty-pr-diff-range
...
Diff-informed analysis: fix empty PR handling
2025-03-21 16:04:38 -07:00
Chuan-kai Lin
b361a91508
Diff-informed analysis: fix empty PR handling
2025-03-21 14:18:25 -07:00
Chuan-kai Lin
bd1d9ab4ed
Merge pull request #2816 from github/cklin/overlay-file-list
...
Overlay databases: use --overlay-changes
2025-03-21 12:30:26 -07:00
Chuan-kai Lin
b98ae6ca52
Add overlay-database-utils tests
2025-03-21 11:31:28 -07:00
Chuan-kai Lin
9825184a0a
Add getFileOidsUnderPath() tests
2025-03-21 10:53:21 -07:00
Chuan-kai Lin
ac67cffe5c
Merge pull request #2817 from github/cklin/default-setup-diff-informed
...
Support diff-informed queries under Default Setup
2025-03-21 09:47:20 -07:00
Chuan-kai Lin
9c674ba4f5
build: refresh js files
2025-03-21 09:25:30 -07:00
Chuan-kai Lin
d109dd5d33
Detect PR branches for Default Setup
2025-03-21 09:25:08 -07:00
Chuan-kai Lin
3e5446c3d2
Introduce PullRequestBranches
2025-03-21 09:24:16 -07:00
Chuan-kai Lin
6adda79888
Move PR branch detection into setupDiffInformedQueryRun()
2025-03-20 09:51:17 -07:00
Chuan-kai Lin
6be6984cc1
Overlay databases: use --overlay-changes
...
This commit changes overlay database creation to use the
--overlay-changes flag. It also implements Git-based file change
detection to generate the list of files to extract for the overlay
database.
2025-03-19 11:38:45 -07:00
Andrew Eisenberg
c50c157cc3
Merge pull request #2813 from github/NlightNFotis/enhance_justfile
...
build: sync some utility just instructions I had locally
2025-03-19 10:57:36 -07:00
Fotis Koutoulakis
c74c378e29
Update justfile
...
Co-authored-by: Andrew Eisenberg <aeisenberg@github.com >
2025-03-19 17:11:02 +00:00
Fotis Koutoulakis
d271bde0ec
Update justfile
...
Co-authored-by: Andrew Eisenberg <aeisenberg@github.com >
2025-03-19 17:10:52 +00:00
Chris Smowton
df9f80e0f0
Merge pull request #2815 from github/mergeback/v3.28.12-to-main-5f8171a6
...
Mergeback v3.28.12 refs/heads/releases/v3 into main
2025-03-19 13:42:24 +00:00
github-actions[bot]
46371933a7
Update checked-in dependencies
2025-03-19 12:43:51 +00:00
github-actions[bot]
ee6a063cbd
Update changelog and version after v3.28.12
2025-03-19 12:41:18 +00:00
Chris Smowton
5f8171a638
Merge pull request #2814 from github/update-v3.28.12-6349095d1
...
Merge main into releases/v3
2025-03-19 12:40:51 +00:00
github-actions[bot]
bb59f7707d
Update changelog for v3.28.12
2025-03-19 12:17:24 +00:00
Fotis Koutoulakis (@NlightNFotis)
8b0dccd066
build: sync some utility just instructions I had locally
2025-03-19 11:56:11 +00:00
Chris Smowton
6349095d19
Merge pull request #2810 from github/update-bundle/codeql-bundle-v2.20.7
...
Update default bundle to 2.20.7
2025-03-18 12:35:37 +00:00
github-actions[bot]
d7d03fda12
Add changelog note
2025-03-18 12:21:54 +00:00
github-actions[bot]
4e3a5342c5
Update default bundle to codeql-bundle-v2.20.7
2025-03-18 12:21:54 +00:00
Michael B. Gale
55f023701c
Merge pull request #2802 from github/mbg/dependency-caching/java-buildless
...
Set and cache dependency directory for Java `build-mode: none`
2025-03-18 10:28:36 +00:00
Angela P Wen
6a151cd774
Merge pull request #2811 from github/dependabot/github_actions/actions-c2c311daa1
...
build(deps): bump ruby/setup-ruby from 1.222.0 to 1.226.0 in the actions group
2025-03-17 12:15:27 -07:00
Angela P Wen
7866bcdb1b
Manually bump workflow to match autogenerated file
2025-03-17 12:00:05 -07:00
dependabot[bot]
611289e0b0
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.222.0 to 1.226.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](277ba2a127...922ebc4c52 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-17 18:11:32 +00:00
Michael B. Gale
4c409a5b66
Remove temporary dependency directory in analyze post action
2025-03-17 11:34:09 +00:00
Andrew Eisenberg
70df9def86
Merge pull request #2808 from github/aeisenberg/fix-dependabot
...
Fix dependabot errors
2025-03-14 13:49:58 -07:00
Andrew Eisenberg
5f98c40063
Fix dependabot errors
...
I explicitly had to downgrade "@octokit/plugin-retry" to "^6.0.0". Other
dependencies were upgraded.
2025-03-14 13:13:56 -07:00
Chuan-kai Lin
f338ec87a3
Merge pull request #2806 from github/cklin/delete-unused-git-utils
...
git-utils: deleted unused functions
2025-03-13 11:51:05 -07:00
Chuan-kai Lin
c31f6c89e8
git-utils: deleted unused functions
2025-03-13 10:45:14 -07:00
Michael B. Gale
251c7fdf5d
Update changelog
2025-03-13 11:50:11 +00:00
Michael B. Gale
afa3ed33bb
Add more documentation
2025-03-13 11:45:27 +00:00
Michael B. Gale
f8367fb063
Set and cache dependency directory for Java build-mode: none
2025-03-13 11:39:39 +00:00
Andrew Eisenberg
dc49dcabdb
Merge pull request #2800 from github/aeisenberg/remove-minimatch
...
Minimally remove micromatch
2025-03-11 16:01:07 -07:00
Andrew Eisenberg
7254660adc
Merge pull request #2804 from github/dependabot/github_actions/actions-96d25c356e
...
build(deps): bump ruby/setup-ruby from 1.221.0 to 1.222.0 in the actions group
2025-03-11 08:53:45 -07:00
Chuan-kai Lin
13f2f96cdd
Merge pull request #2801 from github/cklin/overlay-databases
...
Basic support for overlay databases
2025-03-11 08:33:33 -07:00
Chuan-kai Lin
0efe12d12c
build: refresh js files
2025-03-10 13:31:46 -07:00
Chuan-kai Lin
ff5f0b9efd
Support overlay database creation
...
This commit adds support for creating overlay-base and overlay
databases, controlled via the CODEQL_OVERLAY_DATABASE_MODE environment
variable.
2025-03-10 13:25:46 -07:00
Chuan-kai Lin
270886f805
Pass overlay mode into databaseInitCluster()
...
This commit adds a OverlayDatabaseMode parameter to
databaseInitCluster(). The parameter controls the "codeql database init"
flags concerning overlay database creation.
There is no behavior change in this commit because we always pass
OverlayDatabaseMode.None to databaseInitCluster(). That will change in
the next commit.
2025-03-10 13:22:24 -07:00
Andrew Eisenberg
d3762699d1
Update pr-check
2025-03-10 11:22:58 -07:00
Henry Mercer
b46b37a8a3
Merge pull request #2803 from github/dependabot/npm_and_yarn/npm-129f0c3752
...
build(deps-dev): bump the npm group with 3 updates
2025-03-10 18:01:08 +00:00
dependabot[bot]
aecf01557d
build(deps): bump ruby/setup-ruby in the actions group
...
Bumps the actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.221.0 to 1.222.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](32110d4e31...277ba2a127 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-10 17:57:35 +00:00
github-actions[bot]
053e2184a0
Update checked-in dependencies
2025-03-10 17:42:57 +00:00
dependabot[bot]
248ab9b811
build(deps-dev): bump the npm group with 3 updates
...
Bumps the npm group with 3 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@eslint/js` from 9.21.0 to 9.22.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.22.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.26.0 to 8.26.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.26.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.26.0 to 8.26.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.26.1/packages/parser )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-03-10 17:42:05 +00:00
Chuan-kai Lin
d76f393713
Do not set --expect-discarded-cache on "cleanup-level: overlay"
...
When a user specifies "cleanup-level: overlay", it suggests that the
user wishes to preserve the evaluation cache for future use. So in this
case we should not set --expect-discarded-cache when running queries.
2025-03-10 10:32:13 -07:00
Andrew Eisenberg
88676f2b14
Minimally remove micromatch
2025-03-07 10:07:08 -08:00
Chuan-kai Lin
b2e6519679
Merge pull request #2799 from github/mergeback/v3.28.11-to-main-6bb031af
...
Mergeback v3.28.11 refs/heads/releases/v3 into main
2025-03-07 08:34:57 -08:00
github-actions[bot]
ff91c9db25
Update checked-in dependencies
2025-03-07 16:12:00 +00:00
github-actions[bot]
d1b3f740d8
Update changelog and version after v3.28.11
2025-03-07 16:09:54 +00:00
Chuan-kai Lin
6bb031afdd
Merge pull request #2798 from github/update-v3.28.11-56b25d5d5
...
Merge main into releases/v3
2025-03-07 08:09:23 -08:00
github-actions[bot]
6bca7dd940
Update changelog for v3.28.11
2025-03-07 14:28:04 +00:00
Chuan-kai Lin
56b25d5d52
Merge pull request #2793 from github/update-bundle/codeql-bundle-v2.20.6
...
Update default bundle to 2.20.6
2025-03-06 07:12:12 -08:00
Chuan-kai Lin
256aa16582
Merge branch 'main' into update-bundle/codeql-bundle-v2.20.6
2025-03-06 06:59:38 -08:00
Nick Fyson
911d845ab6
Merge pull request #2796 from github/nickfyson/adjust-rate-error-string
...
adjust string for handling rate limit error
2025-03-06 10:45:00 +00:00
nickfyson
7b7ed63503
adjust string for handling rate limit error
2025-03-06 10:33:25 +00:00
Henry Mercer
608ccd6cd9
Merge pull request #2794 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-03-05 14:41:52 +00:00
github-actions[bot]
35d04d3627
Update supported GitHub Enterprise Server versions
2025-03-05 00:15:30 +00:00
Chuan-kai Lin
ec3b22164b
Update supported GitHub Enterprise Server versions
2025-03-03 13:06:35 -08:00
github-actions[bot]
8dc01f6342
Add changelog note
2025-03-03 20:54:07 +00:00
github-actions[bot]
b378daf0bc
Update default bundle to codeql-bundle-v2.20.6
2025-03-03 20:54:03 +00:00
Dave Bartolomeo
c7c9a57be6
Add changelog entry
2025-02-27 13:18:18 -05:00
Dave Bartolomeo
c29cab9aac
Remove bundled copy of actions extractor
2025-02-27 12:46:11 -05:00