matrix-art.meta

Issues/PRs archive for MTRNord/matrix-art
git clone git://archive.git.mtrnord.blog/MTRNord/matrix-art.meta.git
Log | Files | Refs

411.json (8315B)


      1 {
      2   "number": 411,
      3   "title": "Bump github/codeql-action from 2.1.39 to 2.2.9",
      4   "state": "closed",
      5   "diff_file": "411.diff",
      6   "author": "dependabot[bot]",
      7   "created_at": "2023-04-03T09:02:57Z",
      8   "closed_at": "2023-04-10T09:03:03Z",
      9   "merged_at": null,
     10   "base_ref": "main",
     11   "head_ref": "dependabot/github_actions/github/codeql-action-2.2.9",
     12   "labels": [
     13     "dependencies",
     14     "github_actions"
     15   ],
     16   "assignees": [
     17     "MTRNord"
     18   ],
     19   "requested_reviewers": [
     20     "MTRNord"
     21   ],
     22   "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.39 to 2.2.9.\n<details>\n<summary>Changelog</summary>\n<p><em>Sourced from <a href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\">github/codeql-action's changelog</a>.</em></p>\n<blockquote>\n<h1>CodeQL Action Changelog</h1>\n<h2>[UNRELEASED]</h2>\n<p>No user facing changes.</p>\n<h2>2.2.9 - 27 Mar 2023</h2>\n<ul>\n<li>Customers post-processing the SARIF output of the <code>analyze</code> Action before uploading it to Code Scanning will benefit from an improved debugging experience. <a href=\"https://redirect.github.com/github/codeql-action/pull/1598\">#1598</a>\n<ul>\n<li>The CodeQL Action will now upload a SARIF file with debugging information to Code Scanning on failed runs for customers using <code>upload: false</code>. Previously, this was only available for customers using the default value of the <code>upload</code> input.</li>\n<li>The <code>upload</code> input to the <code>analyze</code> Action now accepts the following values:\n<ul>\n<li><code>always</code> is the default value, which uploads the SARIF file to Code Scanning for successful and failed runs.</li>\n<li><code>failure-only</code> is recommended for customers post-processing the SARIF file before uploading it to Code Scanning. This option uploads debugging information to Code Scanning for failed runs to improve the debugging experience.</li>\n<li><code>never</code> avoids uploading the SARIF file to Code Scanning even if the code scanning run fails. This is not recommended for external users since it complicates debugging.</li>\n<li>The legacy <code>true</code> and <code>false</code> options will be interpreted as <code>always</code> and <code>failure-only</code> respectively.</li>\n</ul>\n</li>\n</ul>\n</li>\n</ul>\n<h2>2.2.8 - 22 Mar 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.5. <a href=\"https://redirect.github.com/github/codeql-action/pull/1585\">#1585</a></li>\n</ul>\n<h2>2.2.7 - 15 Mar 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.6 - 10 Mar 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.4. <a href=\"https://redirect.github.com/github/codeql-action/pull/1561\">#1561</a></li>\n</ul>\n<h2>2.2.5 - 24 Feb 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.3. <a href=\"https://redirect.github.com/github/codeql-action/pull/1543\">#1543</a></li>\n</ul>\n<h2>2.2.4 - 10 Feb 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.3 - 08 Feb 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.2. <a href=\"https://redirect.github.com/github/codeql-action/pull/1518\">#1518</a></li>\n</ul>\n<h2>2.2.2 - 06 Feb 2023</h2>\n<ul>\n<li>Fix an issue where customers using the CodeQL Action with the <a href=\"https://docs.github.com/en/enterprise-server@3.7/admin/code-security/managing-github-advanced-security-for-your-enterprise/configuring-code-scanning-for-your-appliance#configuring-codeql-analysis-on-a-server-without-internet-access\">CodeQL Action sync tool</a> would not be able to obtain the CodeQL tools. <a href=\"https://redirect.github.com/github/codeql-action/pull/1517\">#1517</a></li>\n</ul>\n<h2>2.2.1 - 27 Jan 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.0 - 26 Jan 2023</h2>\n<!-- raw HTML omitted -->\n</blockquote>\n<p>... (truncated)</p>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/github/codeql-action/commit/04df1262e6247151b5ac09cd2c303ac36ad3f62b\"><code>04df126</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1608\">#1608</a> from github/update-v2.2.9-fb32c3fef</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/f0988cbd79ff403435044fdb9947c1ec20d01f6a\"><code>f0988cb</code></a> Move changelog note to correct section</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/fef20d6c357cfcd261d53a2d55b0b2132d0f6892\"><code>fef20d6</code></a> Update changelog for v2.2.9</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/fb32c3fefdc4ffebe80488e4ed5d862348621d72\"><code>fb32c3f</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1605\">#1605</a> from github/henrymercer/diagnostics-grouping-workaround</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/329c022f486ae3deced8c256a11365c7a7799041\"><code>329c022</code></a> Just check the number of locations</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/c8935d5a9dbe3383438a0f489ca0c6f7fa2743c3\"><code>c8935d5</code></a> Remove duplicate locations from failed run SARIF</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/ade432fd683e818e4efbc4a803160f5b4f13926e\"><code>ade432f</code></a> Remove duplicate locations from output of <code>database interpret-results</code></li>\n<li><a href=\"https://github.com/github/codeql-action/commit/6f852eeb3899f7918bf6f5d7a201a98a18ce5b51\"><code>6f852ee</code></a> Implement removing duplicate locations from a SARIF file</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/097ab4665fecf3c04acc545d74e40d782046c9e3\"><code>097ab46</code></a> Speed up checks a bit by just running the standard suite</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/befd804b8b0075fbae00d57bc215f6e0ea6033a5\"><code>befd804</code></a> Extend diagnostics export integration test to capture location bug</li>\n<li>Additional commits viewable in <a href=\"https://github.com/github/codeql-action/compare/a34ca99b4610d924e04c68db79e503e1f79f9f02...04df1262e6247151b5ac09cd2c303ac36ad3f62b\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=2.1.39&new-version=2.2.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n</details>\n\n<!-- Replace -->\n----\n\u231b Deploy Preview - Build in Progress\n<!-- Replace -->\n",
     23   "comments": [
     24     {
     25       "author": "dependabot[bot]",
     26       "created_at": "2023-04-10T09:03:03Z",
     27       "body": "Superseded by #420."
     28     }
     29   ],
     30   "review_comments": []
     31 }