You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+65-57Lines changed: 65 additions & 57 deletions
Original file line number
Diff line number
Diff line change
@@ -7,268 +7,276 @@ Note that the only difference between `v2` and `v3` of the CodeQL Action is the
7
7
**This is the last planned release of the `v2`. To continue getting updates for the CodeQL Action, please switch to `v3`.**
8
8
9
9
## 2.28.0 - 20 Dec 2024
10
+
## 3.28.0 - 20 Dec 2024
10
11
11
12
- Bump the minimum CodeQL bundle version to 2.15.5. [#2655](https://github.com/github/codeql-action/pull/2655)
12
13
- Don't fail in the unusual case that a file is on the search path. [#2660](https://github.com/github/codeql-action/pull/2660).
13
14
14
-
## 2.27.9 - 12 Dec 2024
15
+
## 3.27.9 - 12 Dec 2024
15
16
16
17
No user facing changes.
17
18
18
-
## 2.27.8 - 12 Dec 2024
19
+
## 3.27.8 - 12 Dec 2024
19
20
20
21
- Fixed an issue where streaming the download and extraction of the CodeQL bundle did not respect proxy settings. [#2624](https://github.com/github/codeql-action/pull/2624)
21
22
22
-
## 2.27.7 - 10 Dec 2024
23
+
## 3.27.7 - 10 Dec 2024
23
24
24
25
- We are rolling out a change in December 2024 that will extract the CodeQL bundle directly to the toolcache to improve performance. [#2631](https://github.com/github/codeql-action/pull/2631)
25
26
- Update default CodeQL bundle version to 2.20.0. [#2636](https://github.com/github/codeql-action/pull/2636)
26
27
27
-
## 2.27.6 - 03 Dec 2024
28
+
## 3.27.6 - 03 Dec 2024
28
29
29
30
- Update default CodeQL bundle version to 2.19.4. [#2626](https://github.com/github/codeql-action/pull/2626)
30
31
31
-
## 2.27.5 - 19 Nov 2024
32
+
## 3.27.5 - 19 Nov 2024
32
33
33
34
No user facing changes.
34
35
35
-
## 2.27.4 - 14 Nov 2024
36
+
## 3.27.4 - 14 Nov 2024
36
37
37
38
No user facing changes.
38
39
39
-
## 2.27.3 - 12 Nov 2024
40
+
## 3.27.3 - 12 Nov 2024
40
41
41
42
No user facing changes.
42
43
43
-
## 2.27.2 - 12 Nov 2024
44
+
## 3.27.2 - 12 Nov 2024
44
45
45
46
- Fixed an issue where setting up the CodeQL tools would sometimes fail with the message "Invalid value 'undefined' for header 'authorization'". [#2590](https://github.com/github/codeql-action/pull/2590)
46
47
47
-
## 2.27.1 - 08 Nov 2024
48
+
## 3.27.1 - 08 Nov 2024
48
49
49
50
- The CodeQL Action now downloads bundles compressed using Zstandard on GitHub Enterprise Server when using Linux or macOS runners. This speeds up the installation of the CodeQL tools. This feature is already available to GitHub.com users. [#2573](https://github.com/github/codeql-action/pull/2573)
50
51
- Update default CodeQL bundle version to 2.19.3. [#2576](https://github.com/github/codeql-action/pull/2576)
51
52
52
-
## 2.27.0 - 22 Oct 2024
53
+
## 3.27.0 - 22 Oct 2024
53
54
54
55
- Bump the minimum CodeQL bundle version to 2.14.6. [#2549](https://github.com/github/codeql-action/pull/2549)
55
56
- Fix an issue where the `upload-sarif` Action would fail with "upload-sarif post-action step failed: Input required and not supplied: token" when called in a composite Action that had a different set of inputs to the ones expected by the `upload-sarif` Action. [#2557](https://github.com/github/codeql-action/pull/2557)
56
57
- Update default CodeQL bundle version to 2.19.2. [#2552](https://github.com/github/codeql-action/pull/2552)
57
58
58
-
## 2.26.13 - 14 Oct 2024
59
+
## 3.26.13 - 14 Oct 2024
59
60
60
61
No user facing changes.
61
62
62
-
## 2.26.12 - 07 Oct 2024
63
+
## 3.26.12 - 07 Oct 2024
63
64
64
65
-_Upcoming breaking change_: Add a deprecation warning for customers using CodeQL version 2.14.5 and earlier. These versions of CodeQL were discontinued on 24 September 2024 alongside GitHub Enterprise Server 3.10, and will be unsupported by CodeQL Action versions 3.27.0 and later and versions 2.27.0 and later. [#2520](https://github.com/github/codeql-action/pull/2520)
66
+
65
67
- If you are using one of these versions, please update to CodeQL CLI version 2.14.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
68
+
66
69
- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.13.5 and 2.14.5, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.26.11` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.26.11` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
67
70
68
-
## 2.26.11 - 03 Oct 2024
71
+
## 3.26.11 - 03 Oct 2024
69
72
70
73
-_Upcoming breaking change_: Add support for using `actions/download-artifact@v4` to programmatically consume CodeQL Action debug artifacts.
74
+
71
75
Starting November 30, 2024, GitHub.com customers will [no longer be able to use `actions/download-artifact@v3`](https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/). Therefore, to avoid breakage, customers who programmatically download the CodeQL Action debug artifacts should set the `CODEQL_ACTION_ARTIFACT_V4_UPGRADE` environment variable to `true` and bump `actions/download-artifact@v3` to `actions/download-artifact@v4` in their workflows. The CodeQL Action will enable this behavior by default in early November and workflows that have not yet bumped to `actions/download-artifact@v3` to `actions/download-artifact@v4` will begin failing then.
76
+
72
77
This change is currently unavailable for GitHub Enterprise Server customers, as `actions/upload-artifact@v4` and `actions/download-artifact@v4` are not yet compatible with GHES.
73
78
- Update default CodeQL bundle version to 2.19.1. [#2519](https://github.com/github/codeql-action/pull/2519)
74
79
75
-
## 2.26.10 - 30 Sep 2024
80
+
## 3.26.10 - 30 Sep 2024
76
81
77
82
- We are rolling out a feature in September/October 2024 that sets up CodeQL using a bundle compressed with [Zstandard](http://facebook.github.io/zstd/). Our aim is to improve the performance of setting up CodeQL. [#2502](https://github.com/github/codeql-action/pull/2502)
78
83
79
-
## 2.26.9 - 24 Sep 2024
84
+
## 3.26.9 - 24 Sep 2024
80
85
81
86
No user facing changes.
82
87
83
-
## 2.26.8 - 19 Sep 2024
88
+
## 3.26.8 - 19 Sep 2024
84
89
85
90
- Update default CodeQL bundle version to 2.19.0. [#2483](https://github.com/github/codeql-action/pull/2483)
86
91
87
-
## 2.26.7 - 13 Sep 2024
92
+
## 3.26.7 - 13 Sep 2024
88
93
89
94
- Update default CodeQL bundle version to 2.18.4. [#2471](https://github.com/github/codeql-action/pull/2471)
90
95
91
-
## 2.26.6 - 29 Aug 2024
96
+
## 3.26.6 - 29 Aug 2024
92
97
93
98
- Update default CodeQL bundle version to 2.18.3. [#2449](https://github.com/github/codeql-action/pull/2449)
94
99
95
-
## 2.26.5 - 23 Aug 2024
100
+
## 3.26.5 - 23 Aug 2024
96
101
97
102
- Fix an issue where the `csrutil` system call used for telemetry would fail on macOS ARM machines with System Integrity Protection disabled. [#2441](https://github.com/github/codeql-action/pull/2441)
98
103
99
-
## 2.26.4 - 21 Aug 2024
104
+
## 3.26.4 - 21 Aug 2024
100
105
101
106
-_Deprecation:_ The `add-snippets` input on the `analyze` Action is deprecated and will be removed in the first release in August 2025. [#2436](https://github.com/github/codeql-action/pull/2436)
102
107
- Fix an issue where the disk usage system call used for telemetry would fail on macOS ARM machines with System Integrity Protection disabled, and then surface a warning. The system call is now disabled for these machines. [#2434](https://github.com/github/codeql-action/pull/2434)
103
108
104
-
## 2.26.3 - 19 Aug 2024
109
+
## 3.26.3 - 19 Aug 2024
105
110
106
111
- Fix an issue where the CodeQL Action could not write diagnostic messages on Windows. This issue did not impact analysis quality. [#2430](https://github.com/github/codeql-action/pull/2430)
107
112
108
-
## 2.26.2 - 14 Aug 2024
113
+
## 3.26.2 - 14 Aug 2024
109
114
110
115
- Update default CodeQL bundle version to 2.18.2. [#2417](https://github.com/github/codeql-action/pull/2417)
111
116
112
-
## 2.26.1 - 13 Aug 2024
117
+
## 3.26.1 - 13 Aug 2024
113
118
114
119
No user facing changes.
115
120
116
-
## 2.26.0 - 06 Aug 2024
121
+
## 3.26.0 - 06 Aug 2024
117
122
118
123
-_Deprecation:_ Swift analysis on Ubuntu runner images is no longer supported. Please migrate to a macOS runner if this affects you. [#2403](https://github.com/github/codeql-action/pull/2403)
119
124
- Bump the minimum CodeQL bundle version to 2.13.5. [#2408](https://github.com/github/codeql-action/pull/2408)
120
125
121
-
## 2.25.15 - 26 Jul 2024
126
+
## 3.25.15 - 26 Jul 2024
122
127
123
128
- Update default CodeQL bundle version to 2.18.1. [#2385](https://github.com/github/codeql-action/pull/2385)
124
129
125
-
## 2.25.14 - 25 Jul 2024
130
+
## 3.25.14 - 25 Jul 2024
126
131
127
132
- Experimental: add a new `start-proxy` action which starts the same HTTP proxy as used by [`github/dependabot-action`](https://github.com/github/dependabot-action). Do not use this in production as it is part of an internal experiment and subject to change at any time. [#2376](https://github.com/github/codeql-action/pull/2376)
128
133
129
-
## 2.25.13 - 19 Jul 2024
134
+
## 3.25.13 - 19 Jul 2024
130
135
131
136
- Add `codeql-version` to outputs. [#2368](https://github.com/github/codeql-action/pull/2368)
132
137
- Add a deprecation warning for customers using CodeQL version 2.13.4 and earlier. These versions of CodeQL were discontinued on 9 July 2024 alongside GitHub Enterprise Server 3.9, and will be unsupported by CodeQL Action versions 3.26.0 and later and versions 2.26.0 and later. [#2375](https://github.com/github/codeql-action/pull/2375)
133
138
- If you are using one of these versions, please update to CodeQL CLI version 2.13.5 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
134
139
- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.12.6 and 2.13.4, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.25.13` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.25.13` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
135
140
136
-
## 2.25.12 - 12 Jul 2024
141
+
## 3.25.12 - 12 Jul 2024
137
142
138
143
- Improve the reliability and performance of analyzing code when analyzing a compiled language with the `autobuild`[build mode](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes) on GitHub Enterprise Server. This feature is already available to GitHub.com users. [#2353](https://github.com/github/codeql-action/pull/2353)
139
144
- Update default CodeQL bundle version to 2.18.0. [#2364](https://github.com/github/codeql-action/pull/2364)
140
145
141
-
## 2.25.11 - 28 Jun 2024
146
+
## 3.25.11 - 28 Jun 2024
142
147
143
148
- Avoid failing the workflow run if there is an error while uploading debug artifacts. [#2349](https://github.com/github/codeql-action/pull/2349)
144
149
- Update default CodeQL bundle version to 2.17.6. [#2352](https://github.com/github/codeql-action/pull/2352)
145
150
146
-
## 2.25.10 - 13 Jun 2024
151
+
## 3.25.10 - 13 Jun 2024
147
152
148
153
- Update default CodeQL bundle version to 2.17.5. [#2327](https://github.com/github/codeql-action/pull/2327)
149
154
150
-
## 2.25.9 - 12 Jun 2024
155
+
## 3.25.9 - 12 Jun 2024
151
156
152
157
- Avoid failing database creation if the database folder already exists and contains some unexpected files. Requires CodeQL 2.18.0 or higher. [#2330](https://github.com/github/codeql-action/pull/2330)
153
158
- The init Action will attempt to clean up the database cluster directory before creating a new database and at the end of the job. This will help to avoid issues where the database cluster directory is left in an inconsistent state. [#2332](https://github.com/github/codeql-action/pull/2332)
154
159
155
-
## 2.25.8 - 04 Jun 2024
160
+
## 3.25.8 - 04 Jun 2024
156
161
157
162
- Update default CodeQL bundle version to 2.17.4. [#2321](https://github.com/github/codeql-action/pull/2321)
158
163
159
-
## 2.25.7 - 31 May 2024
164
+
## 3.25.7 - 31 May 2024
160
165
161
166
- We are rolling out a feature in May/June 2024 that will reduce the Actions cache usage of the Action by keeping only the newest TRAP cache for each language. [#2306](https://github.com/github/codeql-action/pull/2306)
162
167
163
-
## 2.25.6 - 20 May 2024
168
+
## 3.25.6 - 20 May 2024
164
169
165
170
- Update default CodeQL bundle version to 2.17.3. [#2295](https://github.com/github/codeql-action/pull/2295)
166
171
167
-
## 2.25.5 - 13 May 2024
172
+
## 3.25.5 - 13 May 2024
168
173
169
174
- Add a compatibility matrix of supported CodeQL Action, CodeQL CLI, and GitHub Enterprise Server versions to the [README.md](README.md). [#2273](https://github.com/github/codeql-action/pull/2273)
170
175
- Avoid printing out a warning for a missing `on.push` trigger when the CodeQL Action is triggered via a `workflow_call` event. [#2274](https://github.com/github/codeql-action/pull/2274)
171
176
- The `tools: latest` input to the `init` Action has been renamed to `tools: linked`. This option specifies that the Action should use the tools shipped at the same time as the Action. The old name will continue to work for backwards compatibility, but we recommend that new workflows use the new name. [#2281](https://github.com/github/codeql-action/pull/2281)
172
177
173
-
## 2.25.4 - 08 May 2024
178
+
## 3.25.4 - 08 May 2024
174
179
175
180
- Update default CodeQL bundle version to 2.17.2. [#2270](https://github.com/github/codeql-action/pull/2270)
176
181
177
-
## 2.25.3 - 25 Apr 2024
182
+
## 3.25.3 - 25 Apr 2024
178
183
179
184
- Update default CodeQL bundle version to 2.17.1. [#2247](https://github.com/github/codeql-action/pull/2247)
180
185
- Workflows running on `macos-latest` using CodeQL CLI versions before v2.15.1 will need to either upgrade their CLI version to v2.15.1 or newer, or change the platform to an Intel macOS runner, such as `macos-12`. ARM machines with SIP disabled, including the newest `macos-latest` image, are unsupported for CLI versions before 2.15.1. [#2261](https://github.com/github/codeql-action/pull/2261)
181
186
182
-
## 2.25.2 - 22 Apr 2024
187
+
## 3.25.2 - 22 Apr 2024
183
188
184
189
No user facing changes.
185
190
186
-
## 2.25.1 - 17 Apr 2024
191
+
## 3.25.1 - 17 Apr 2024
187
192
188
193
- We are rolling out a feature in April/May 2024 that improves the reliability and performance of analyzing code when analyzing a compiled language with the `autobuild`[build mode](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes). [#2235](https://github.com/github/codeql-action/pull/2235)
189
194
- Fix a bug where the `init` Action would fail if `--overwrite` was specified in `CODEQL_ACTION_EXTRA_OPTIONS`. [#2245](https://github.com/github/codeql-action/pull/2245)
190
195
191
-
## 2.25.0 - 15 Apr 2024
196
+
## 3.25.0 - 15 Apr 2024
192
197
193
198
- The deprecated feature for extracting dependencies for a Python analysis has been removed. [#2224](https://github.com/github/codeql-action/pull/2224)
199
+
194
200
As a result, the following inputs and environment variables are now ignored:
201
+
195
202
- The `setup-python-dependencies` input to the `init` Action
196
203
- The `CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION` environment variable
204
+
197
205
We recommend removing any references to these from your workflows. For more information, see the release notes for CodeQL Action v3.23.0 and v2.23.0.
198
206
- Automatically overwrite an existing database if found on the filesystem. [#2229](https://github.com/github/codeql-action/pull/2229)
199
207
- Bump the minimum CodeQL bundle version to 2.12.6. [#2232](https://github.com/github/codeql-action/pull/2232)
200
208
- A more relevant log message and a diagnostic are now emitted when the `file` program is not installed on a Linux runner, but is required for Go tracing to succeed. [#2234](https://github.com/github/codeql-action/pull/2234)
201
209
202
-
## 2.24.10 - 05 Apr 2024
210
+
## 3.24.10 - 05 Apr 2024
203
211
204
212
- Update default CodeQL bundle version to 2.17.0. [#2219](https://github.com/github/codeql-action/pull/2219)
205
213
- Add a deprecation warning for customers using CodeQL version 2.12.5 and earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 3.25.0 and later and versions 2.25.0 and later. [#2220](https://github.com/github/codeql-action/pull/2220)
206
214
- If you are using one of these versions, please update to CodeQL CLI version 2.12.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
207
215
- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.11.6 and 2.12.5, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.24.10` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.24.10` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
208
216
209
-
## 2.24.9 - 22 Mar 2024
217
+
## 3.24.9 - 22 Mar 2024
210
218
211
219
- Update default CodeQL bundle version to 2.16.5. [#2203](https://github.com/github/codeql-action/pull/2203)
212
220
213
-
## 2.24.8 - 18 Mar 2024
221
+
## 3.24.8 - 18 Mar 2024
214
222
215
223
- Improve the ease of debugging extraction issues by increasing the verbosity of the extractor logs when running in debug mode. [#2195](https://github.com/github/codeql-action/pull/2195)
216
224
217
-
## 2.24.7 - 12 Mar 2024
225
+
## 3.24.7 - 12 Mar 2024
218
226
219
227
- Update default CodeQL bundle version to 2.16.4. [#2185](https://github.com/github/codeql-action/pull/2185)
220
228
221
-
## 2.24.6 - 29 Feb 2024
229
+
## 3.24.6 - 29 Feb 2024
222
230
223
231
No user facing changes.
224
232
225
-
## 2.24.5 - 23 Feb 2024
233
+
## 3.24.5 - 23 Feb 2024
226
234
227
235
- Update default CodeQL bundle version to 2.16.3. [#2156](https://github.com/github/codeql-action/pull/2156)
228
236
229
-
## 2.24.4 - 21 Feb 2024
237
+
## 3.24.4 - 21 Feb 2024
230
238
231
239
- Fix an issue where an existing, but empty, `/sys/fs/cgroup/cpuset.cpus` file always resulted in a single-threaded run. [#2151](https://github.com/github/codeql-action/pull/2151)
232
240
233
-
## 2.24.3 - 15 Feb 2024
241
+
## 3.24.3 - 15 Feb 2024
234
242
235
243
- Fix an issue where the CodeQL Action would fail to load a configuration specified by the `config` input to the `init` Action. [#2147](https://github.com/github/codeql-action/pull/2147)
236
244
237
-
## 2.24.2 - 15 Feb 2024
245
+
## 3.24.2 - 15 Feb 2024
238
246
239
247
- Enable improved multi-threaded performance on larger runners for GitHub Enterprise Server users. This feature is already available to GitHub.com users. [#2141](https://github.com/github/codeql-action/pull/2141)
240
248
241
-
## 2.24.1 - 13 Feb 2024
249
+
## 3.24.1 - 13 Feb 2024
242
250
243
251
- Update default CodeQL bundle version to 2.16.2. [#2124](https://github.com/github/codeql-action/pull/2124)
244
252
- The CodeQL action no longer fails if it can't write to the telemetry api endpoint. [#2121](https://github.com/github/codeql-action/pull/2121)
245
253
246
-
## 2.24.0 - 02 Feb 2024
254
+
## 3.24.0 - 02 Feb 2024
247
255
248
256
- CodeQL Python analysis will no longer install dependencies on GitHub Enterprise Server, as is already the case for GitHub.com. See [release notes for 3.23.0](#3230---08-jan-2024) for more details. [#2106](https://github.com/github/codeql-action/pull/2106)
249
257
250
-
## 2.23.2 - 26 Jan 2024
258
+
## 3.23.2 - 26 Jan 2024
251
259
252
260
- On Linux, the maximum possible value for the `--threads` option now respects the CPU count as specified in `cgroup` files to more accurately reflect the number of available cores when running in containers. [#2083](https://github.com/github/codeql-action/pull/2083)
253
261
- Update default CodeQL bundle version to 2.16.1. [#2096](https://github.com/github/codeql-action/pull/2096)
254
262
255
-
## 2.23.1 - 17 Jan 2024
263
+
## 3.23.1 - 17 Jan 2024
256
264
257
265
- Update default CodeQL bundle version to 2.16.0. [#2073](https://github.com/github/codeql-action/pull/2073)
258
266
- Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. [#2079](https://github.com/github/codeql-action/pull/2079)
259
267
260
-
## 2.23.0 - 08 Jan 2024
268
+
## 3.23.0 - 08 Jan 2024
261
269
262
270
- We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting `CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false` in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. [#2031](https://github.com/github/codeql-action/pull/2031)
263
271
- The CodeQL Action now requires CodeQL version 2.11.6 or later. For more information, see [the corresponding changelog entry for CodeQL Action version 2.22.7](#2227---16-nov-2023). [#2009](https://github.com/github/codeql-action/pull/2009)
264
272
265
-
## 2.22.12 - 22 Dec 2023
273
+
## 3.22.12 - 22 Dec 2023
266
274
267
275
- Update default CodeQL bundle version to 2.15.5. [#2047](https://github.com/github/codeql-action/pull/2047)
268
276
269
-
## 2.22.11 - 13 Dec 2023
277
+
## 3.22.11 - 13 Dec 2023
270
278
271
-
No user facing changes.
279
+
-[v3+ only] The CodeQL Action now runs on Node.js v20. [#2006](https://github.com/github/codeql-action/pull/2006)
0 commit comments