Sourced from github/codeql-action's releases.
CodeQL Bundle
Bundles CodeQL CLI v2.13.4
Includes the following CodeQL language packs from
github/codeql@codeql-cli/v2.13.4:
codeql/cpp-queries(changelog, source)codeql/cpp-all(changelog, source)codeql/csharp-queries(changelog, source)codeql/csharp-all(changelog, source)codeql/go-queries(changelog, source)codeql/go-all(changelog, source)codeql/java-queries(changelog, source)codeql/java-all(changelog, source)codeql/javascript-queries(changelog, source)codeql/javascript-all(changelog, source)codeql/python-queries(changelog, source)codeql/python-all(changelog, source)codeql/ruby-queries(changelog, source)codeql/ruby-all(changelog, source)codeql/swift-queries(changelog, source)codeql/swift-all(changelog, source)CodeQL Bundle v2.6.0-beta.1
Bundles CodeQL CLI v2.6.0-beta.1
â ï¸ This is a beta release containing a new CodeQL packaging feature. It may not be compatible with existing workflows.
This release contains beta support for CodeQL packs. Please read the documentation below for more information:
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
[UNRELEASED]
No user facing changes.
2.3.6 - 01 Jun 2023
- Update default CodeQL bundle version to 2.13.3. #1698
2.3.5 - 25 May 2023
- Allow invalid URIs to be used as values to
artifactLocation.uriproperties. This reverses a change from #1668 that inadvertently led to stricter validation of some URI values. #1705- Gracefully handle invalid URIs when fingerprinting. #1694
2.3.4 - 24 May 2023
- Updated the SARIF 2.1.0 JSON schema file to the latest from oasis-tcs/sarif-spec. #1668
- We are rolling out a feature in May 2023 that will disable Python dependency installation for new users of the CodeQL Action. This improves the speed of analysis while having only a very minor impact on results. #1676
- We are improving the way that CodeQL bundles are tagged to make it possible to easily identify bundles by their CodeQL semantic version. #1682
- As of CodeQL CLI 2.13.4, CodeQL bundles will be tagged using semantic versions, for example
codeql-bundle-v2.13.4, instead of timestamps, likecodeql-bundle-20230615.- This change does not affect the majority of workflows, and we will not be changing tags for existing bundle releases.
- Some workflows with custom logic that depends on the specific format of the CodeQL bundle tag may need to be updated. For example, if your workflow matches CodeQL bundle tag names against a
codeql-bundle-yyyymmddpattern, you should update it to also recognizecodeql-bundle-vx.y.ztags.- Remove the requirement for
on.pushandon.pull_requestto trigger on the same branches. #16752.3.3 - 04 May 2023
- Update default CodeQL bundle version to 2.13.1. #1664
- You can now configure CodeQL within your code scanning workflow by passing a
configinput to theinitAction. See Using a custom configuration file for more information about configuring code scanning. #15902.3.2 - 27 Apr 2023
No user facing changes.
2.3.1 - 26 Apr 2023
No user facing changes.
2.3.0 - 21 Apr 2023
- Update default CodeQL bundle version to 2.13.0. #1649
- Bump the minimum CodeQL bundle version to 2.8.5. #1618
2.2.12 - 13 Apr 2023
- Include the value of the
GITHUB_RUN_ATTEMPTenvironment variable in the telemetry sent to GitHub. #1640- Improve the ease of debugging failed runs configured using default setup. The CodeQL Action will now upload diagnostic information to Code Scanning from failed runs configured using default setup. You can view this diagnostic information on the tool status page. #1619
2.2.11 - 06 Apr 2023
... (truncated)
cdcdbb5 PR checks: stop setting experimental Swift var for new CLI versions (#1718)8b0f2cf Merge pull request #1717 from github/henrymercer/fix-changeloga35a881 Fix changelog for 2.3.6d866720 Merge pull request #1714 from github/mergeback/v2.3.6-to-main-83f0fe6c926a489 Merge pull request #1712 from github/henrymercer/remove-unused-env-var5c63cc5 Update checked-in dependencies30a3b9a Update changelog and version after v2.3.6dfc31c9 Convert actions-util docs to JSDoc019a40b Inline checks for producing a better error message for Dependabot PRsae005db Merge branch 'main' into henrymercer/remove-unused-env-var