396.md (8787B)
1 # PR #396 Bump github/codeql-action from 2.1.39 to 2.2.8 2 3 - **Status:** closed 4 - **Author:** @dependabot[bot] 5 - **Created:** 2023-03-27T09:05:04Z 6 - **Branch:** dependabot/github_actions/github/codeql-action-2.2.8 → main 7 - **Closed:** 2023-04-03T09:03:03Z 8 - **Labels:** dependencies, github_actions 9 - **Assignees:** @MTRNord 10 - **Reviewers:** @MTRNord 11 - **Diff:** [396.diff](./396.diff) 12 13 --- 14 15 Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.39 to 2.2.8. 16 <details> 17 <summary>Changelog</summary> 18 <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's changelog</a>.</em></p> 19 <blockquote> 20 <h1>CodeQL Action Changelog</h1> 21 <h2>[UNRELEASED]</h2> 22 <p>No user facing changes.</p> 23 <h2>2.2.8 - 22 Mar 2023</h2> 24 <ul> 25 <li>Update default CodeQL bundle version to 2.12.5. <a href="https://redirect.github.com/github/codeql-action/pull/1585">#1585</a></li> 26 <li>Customers post-processing the SARIF output of the <code>analyze</code> Action before uploading it to Code Scanning will benefit from an improved debugging experience. <a href="https://redirect.github.com/github/codeql-action/pull/1598">#1598</a> 27 <ul> 28 <li>The CodeQL Action will now upload a SARIF file with debugging information to Code Scanning on failed runs for customers using <code>upload: false</code>. Previously, this was only available for customers using the default value of the <code>upload</code> input.</li> 29 <li>The <code>upload</code> input to the <code>analyze</code> Action now accepts the following values: 30 <ul> 31 <li><code>always</code> is the default value, which uploads the SARIF file to Code Scanning for successful and failed runs.</li> 32 <li><code>failure-only</code> is recommended for customers post-processing the SARIF file before uploading it to Code Scanning. This option uploads debugging information to Code Scanning for failed runs to improve the debugging experience.</li> 33 <li><code>never</code> avoids uploading the SARIF file to Code Scanning even if the code scanning run fails. This is not recommended for external users since it complicates debugging.</li> 34 <li>The legacy <code>true</code> and <code>false</code> options will be interpreted as <code>always</code> and <code>failure-only</code> respectively.</li> 35 </ul> 36 </li> 37 </ul> 38 </li> 39 </ul> 40 <h2>2.2.7 - 15 Mar 2023</h2> 41 <p>No user facing changes.</p> 42 <h2>2.2.6 - 10 Mar 2023</h2> 43 <ul> 44 <li>Update default CodeQL bundle version to 2.12.4. <a href="https://redirect.github.com/github/codeql-action/pull/1561">#1561</a></li> 45 </ul> 46 <h2>2.2.5 - 24 Feb 2023</h2> 47 <ul> 48 <li>Update default CodeQL bundle version to 2.12.3. <a href="https://redirect.github.com/github/codeql-action/pull/1543">#1543</a></li> 49 </ul> 50 <h2>2.2.4 - 10 Feb 2023</h2> 51 <p>No user facing changes.</p> 52 <h2>2.2.3 - 08 Feb 2023</h2> 53 <ul> 54 <li>Update default CodeQL bundle version to 2.12.2. <a href="https://redirect.github.com/github/codeql-action/pull/1518">#1518</a></li> 55 </ul> 56 <h2>2.2.2 - 06 Feb 2023</h2> 57 <ul> 58 <li>Fix an issue where customers using the CodeQL Action with the <a href="https://docs.github.com/en/enterprise-server@3.7/admin/code-security/managing-github-advanced-security-for-your-enterprise/configuring-code-scanning-for-your-appliance#configuring-codeql-analysis-on-a-server-without-internet-access">CodeQL Action sync tool</a> would not be able to obtain the CodeQL tools. <a href="https://redirect.github.com/github/codeql-action/pull/1517">#1517</a></li> 59 </ul> 60 <h2>2.2.1 - 27 Jan 2023</h2> 61 <p>No user facing changes.</p> 62 <h2>2.2.0 - 26 Jan 2023</h2> 63 <ul> 64 <li>Improve stability when choosing the default version of CodeQL to use in code scanning workflow runs on Actions on GitHub.com. <a href="https://redirect.github.com/github/codeql-action/pull/1475">#1475</a> 65 <ul> 66 <li>This change addresses customer reports of code scanning alerts on GitHub.com being closed and reopened during the rollout of new versions of CodeQL in the GitHub Actions <a href="https://github.com/actions/runner-images">runner images</a>.</li> 67 <li><strong>No change is required for the majority of workflows</strong>, including:</li> 68 </ul> 69 </li> 70 </ul> 71 <!-- raw HTML omitted --> 72 </blockquote> 73 <p>... (truncated)</p> 74 </details> 75 <details> 76 <summary>Commits</summary> 77 <ul> 78 <li><a href="https://github.com/github/codeql-action/commit/67a35a08586135a9573f4327e904ecbf517a882d"><code>67a35a0</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/1601">#1601</a> from github/update-v2.2.8-066b6343e</li> 79 <li><a href="https://github.com/github/codeql-action/commit/57571ab0cd1646c26245e45072046dd8523c04c5"><code>57571ab</code></a> Update changelog for v2.2.8</li> 80 <li><a href="https://github.com/github/codeql-action/commit/066b6343ef05c8b9004054f8fb7c6af1a95375aa"><code>066b634</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/1599">#1599</a> from github/update-supported-enterprise-server-versions</li> 81 <li><a href="https://github.com/github/codeql-action/commit/aefd9896b1ac0a2e24b95525643cfa6d0f5538db"><code>aefd989</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/1597">#1597</a> from github/rneatherway/ghe-dotcom</li> 82 <li><a href="https://github.com/github/codeql-action/commit/3ca226064378a93b85e71a9b77c6cf4cbb0d6f3d"><code>3ca2260</code></a> Account for versioning of ghe.com</li> 83 <li><a href="https://github.com/github/codeql-action/commit/5f20b2c372e2df4127c0afad236b5e27f7422434"><code>5f20b2c</code></a> Update supported GitHub Enterprise Server versions.</li> 84 <li><a href="https://github.com/github/codeql-action/commit/760583e70d47693ffb9619d29cd1b1858c197d2b"><code>760583e</code></a> Bump setup-go from v3 to v4 (<a href="https://redirect.github.com/github/codeql-action/issues/1595">#1595</a>)</li> 85 <li><a href="https://github.com/github/codeql-action/commit/0ef7eda548a9f29902ca2a55e9b9d243bd1223dd"><code>0ef7eda</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/1585">#1585</a> from github/henrymercer/bundle-2.12.5</li> 86 <li><a href="https://github.com/github/codeql-action/commit/86128131faa8ac9b0c4d90915acefa9bc8b30a07"><code>8612813</code></a> Merge branch 'main' into henrymercer/bundle-2.12.5</li> 87 <li><a href="https://github.com/github/codeql-action/commit/ebbe965b436d3cf08f411a8e9cdefb6cda0170db"><code>ebbe965</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/1588">#1588</a> from github/update-supported-enterprise-server-versions</li> 88 <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/a34ca99b4610d924e04c68db79e503e1f79f9f02...67a35a08586135a9573f4327e904ecbf517a882d">compare view</a></li> 89 </ul> 90 </details> 91 <br /> 92 93 94 [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) 95 96 Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. 97 98 [//]: # (dependabot-automerge-start) 99 [//]: # (dependabot-automerge-end) 100 101 --- 102 103 <details> 104 <summary>Dependabot commands and options</summary> 105 <br /> 106 107 You can trigger Dependabot actions by commenting on this PR: 108 - `@dependabot rebase` will rebase this PR 109 - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it 110 - `@dependabot merge` will merge this PR after your CI passes on it 111 - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it 112 - `@dependabot cancel merge` will cancel a previously requested merge and block automerging 113 - `@dependabot reopen` will reopen this PR if it is closed 114 - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually 115 - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) 116 - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) 117 - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) 118 119 120 </details> 121 122 <!-- Replace --> 123 ---- 124 ⌛ Deploy Preview - Build in Progress 125 <!-- Replace --> 126 127 128 129 ## Comments 130 131 ### @dependabot[bot] — 2023-04-03T09:03:02Z 132 133 Superseded by #411. 134