420.json (8136B)
1 { 2 "number": 420, 3 "title": "Bump github/codeql-action from 2.1.39 to 2.2.11", 4 "state": "closed", 5 "diff_file": "420.diff", 6 "author": "dependabot[bot]", 7 "created_at": "2023-04-10T09:02:58Z", 8 "closed_at": "2023-04-17T09:03:51Z", 9 "merged_at": null, 10 "base_ref": "main", 11 "head_ref": "dependabot/github_actions/github/codeql-action-2.2.11", 12 "labels": [ 13 "dependencies", 14 "github_actions" 15 ], 16 "assignees": [ 17 "MTRNord" 18 ], 19 "requested_reviewers": [ 20 "MTRNord" 21 ], 22 "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.39 to 2.2.11.\n<details>\n<summary>Changelog</summary>\n<p><em>Sourced from <a href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\">github/codeql-action's changelog</a>.</em></p>\n<blockquote>\n<h1>CodeQL Action Changelog</h1>\n<h2>[UNRELEASED]</h2>\n<p>No user facing changes.</p>\n<h2>2.2.11 - 06 Apr 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.10 - 05 Apr 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.6. <a href=\"https://redirect.github.com/github/codeql-action/pull/1629\">#1629</a></li>\n</ul>\n<h2>2.2.9 - 27 Mar 2023</h2>\n<ul>\n<li>Customers post-processing the SARIF output of the <code>analyze</code> Action before uploading it to Code Scanning will benefit from an improved debugging experience. <a href=\"https://redirect.github.com/github/codeql-action/pull/1598\">#1598</a>\n<ul>\n<li>The CodeQL Action will now upload a SARIF file with debugging information to Code Scanning on failed runs for customers using <code>upload: false</code>. Previously, this was only available for customers using the default value of the <code>upload</code> input.</li>\n<li>The <code>upload</code> input to the <code>analyze</code> Action now accepts the following values:\n<ul>\n<li><code>always</code> is the default value, which uploads the SARIF file to Code Scanning for successful and failed runs.</li>\n<li><code>failure-only</code> is recommended for customers post-processing the SARIF file before uploading it to Code Scanning. This option uploads debugging information to Code Scanning for failed runs to improve the debugging experience.</li>\n<li><code>never</code> avoids uploading the SARIF file to Code Scanning even if the code scanning run fails. This is not recommended for external users since it complicates debugging.</li>\n<li>The legacy <code>true</code> and <code>false</code> options will be interpreted as <code>always</code> and <code>failure-only</code> respectively.</li>\n</ul>\n</li>\n</ul>\n</li>\n</ul>\n<h2>2.2.8 - 22 Mar 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.5. <a href=\"https://redirect.github.com/github/codeql-action/pull/1585\">#1585</a></li>\n</ul>\n<h2>2.2.7 - 15 Mar 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.6 - 10 Mar 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.4. <a href=\"https://redirect.github.com/github/codeql-action/pull/1561\">#1561</a></li>\n</ul>\n<h2>2.2.5 - 24 Feb 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.3. <a href=\"https://redirect.github.com/github/codeql-action/pull/1543\">#1543</a></li>\n</ul>\n<h2>2.2.4 - 10 Feb 2023</h2>\n<p>No user facing changes.</p>\n<h2>2.2.3 - 08 Feb 2023</h2>\n<ul>\n<li>Update default CodeQL bundle version to 2.12.2. <a href=\"https://redirect.github.com/github/codeql-action/pull/1518\">#1518</a></li>\n</ul>\n<h2>2.2.2 - 06 Feb 2023</h2>\n<!-- raw HTML omitted -->\n</blockquote>\n<p>... (truncated)</p>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/github/codeql-action/commit/d186a2a36cc67bfa1b860e6170d37fb9634742c7\"><code>d186a2a</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1638\">#1638</a> from github/update-v2.2.11-518b24fea</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/748f83eaabb67135a415fbeb7b80093a6e103783\"><code>748f83e</code></a> Update changelog for v2.2.11</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/518b24fea4ba18fbafa1f2be06c594583a0966a8\"><code>518b24f</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1637\">#1637</a> from github/henrymercer/fix-init-exception-reporting</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/69371ffa95d3dcf49f2d7bc36280b9d65d72fdb9\"><code>69371ff</code></a> Merge branch 'main' into henrymercer/fix-init-exception-reporting</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/e5c2f32a9f6386408594e3d45f14f4f8e2df4d42\"><code>e5c2f32</code></a> Consistently wrap errors</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/c28edf06a1d03b8250e56cb8ce4f947a55193f06\"><code>c28edf0</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1636\">#1636</a> from github/henrymercer/re-enable-duplicate-sarif-wo...</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/555b602b2f924c3419b1eec61ad4dd717756318e\"><code>555b602</code></a> Report exceptions to telemetry in init Action</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/7193623f40b19441a4b970ec34d09a1130440dbb\"><code>7193623</code></a> Re-enable duplicate SARIF notification location workaround</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/f32426ba96560beecf71186b24134fb3f613f377\"><code>f32426b</code></a> Merge pull request <a href=\"https://redirect.github.com/github/codeql-action/issues/1635\">#1635</a> from github/mergeback/v2.2.10-to-main-8c8d71dd</li>\n<li><a href=\"https://github.com/github/codeql-action/commit/173a94ca3f87f2a4aa454c2f4165dd5b375edeb5\"><code>173a94c</code></a> Update checked-in dependencies</li>\n<li>Additional commits viewable in <a href=\"https://github.com/github/codeql-action/compare/a34ca99b4610d924e04c68db79e503e1f79f9f02...d186a2a36cc67bfa1b860e6170d37fb9634742c7\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n\n[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n</details>\n\n<!-- Replace -->\n----\n\u231b Deploy Preview - Build in Progress\n<!-- Replace -->\n", 23 "comments": [ 24 { 25 "author": "dependabot[bot]", 26 "created_at": "2023-04-17T09:03:50Z", 27 "body": "Superseded by #433." 28 } 29 ], 30 "review_comments": [] 31 }