Skip to content

Commit 17504f9

Browse files
Update version and changelog for v2.26.11
1 parent b6a9270 commit 17504f9

File tree

2 files changed

+46
-51
lines changed

2 files changed

+46
-51
lines changed

CHANGELOG.md

+45-50
Original file line numberDiff line numberDiff line change
@@ -4,214 +4,209 @@ See the [releases page](https://github.com/github/codeql-action/releases) for th
44

55
Note that the only difference between `v2` and `v3` of the CodeQL Action is the node version they support, with `v3` running on node 20 while we continue to release `v2` to support running on node 16. For example `3.22.11` was the first `v3` release and is functionally identical to `2.22.11`. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.
66

7-
## 3.26.11 - 03 Oct 2024
7+
## 2.26.11 - 03 Oct 2024
88

99
- _Upcoming breaking change_: Add support for using `actions/download-artifact@v4` to programmatically consume CodeQL Action debug artifacts.
10-
1110
Starting November 30, 2024, GitHub.com customers will [no longer be able to use `actions/download-artifact@v3`](https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/). Therefore, to avoid breakage, customers who programmatically download the CodeQL Action debug artifacts should set the `CODEQL_ACTION_ARTIFACT_V4_UPGRADE` environment variable to `true` and bump `actions/download-artifact@v3` to `actions/download-artifact@v4` in their workflows. The CodeQL Action will enable this behavior by default in early November and workflows that have not yet bumped to `actions/download-artifact@v3` to `actions/download-artifact@v4` will begin failing then.
12-
1311
This change is currently unavailable for GitHub Enterprise Server customers, as `actions/upload-artifact@v4` and `actions/download-artifact@v4` are not yet compatible with GHES.
1412

15-
## 3.26.10 - 30 Sep 2024
13+
## 2.26.10 - 30 Sep 2024
1614

1715
- We are rolling out a feature in September/October 2024 that sets up CodeQL using a bundle compressed with [Zstandard](http://facebook.github.io/zstd/). Our aim is to improve the performance of setting up CodeQL. [#2502](https://github.com/github/codeql-action/pull/2502)
1816

19-
## 3.26.9 - 24 Sep 2024
17+
## 2.26.9 - 24 Sep 2024
2018

2119
No user facing changes.
2220

23-
## 3.26.8 - 19 Sep 2024
21+
## 2.26.8 - 19 Sep 2024
2422

2523
- Update default CodeQL bundle version to 2.19.0. [#2483](https://github.com/github/codeql-action/pull/2483)
2624

27-
## 3.26.7 - 13 Sep 2024
25+
## 2.26.7 - 13 Sep 2024
2826

2927
- Update default CodeQL bundle version to 2.18.4. [#2471](https://github.com/github/codeql-action/pull/2471)
3028

31-
## 3.26.6 - 29 Aug 2024
29+
## 2.26.6 - 29 Aug 2024
3230

3331
- Update default CodeQL bundle version to 2.18.3. [#2449](https://github.com/github/codeql-action/pull/2449)
3432

35-
## 3.26.5 - 23 Aug 2024
33+
## 2.26.5 - 23 Aug 2024
3634

3735
- Fix an issue where the `csrutil` system call used for telemetry would fail on MacOS ARM machines with System Integrity Protection disabled. [#2441](https://github.com/github/codeql-action/pull/2441)
3836

39-
## 3.26.4 - 21 Aug 2024
37+
## 2.26.4 - 21 Aug 2024
4038

4139
- _Deprecation:_ The `add-snippets` input on the `analyze` Action is deprecated and will be removed in the first release in August 2025. [#2436](https://github.com/github/codeql-action/pull/2436)
4240
- Fix an issue where the disk usage system call used for telemetry would fail on MacOS ARM machines with System Integrity Protection disabled, and then surface a warning. The system call is now disabled for these machines. [#2434](https://github.com/github/codeql-action/pull/2434)
4341

44-
## 3.26.3 - 19 Aug 2024
42+
## 2.26.3 - 19 Aug 2024
4543

4644
- Fix an issue where the CodeQL Action could not write diagnostic messages on Windows. This issue did not impact analysis quality. [#2430](https://github.com/github/codeql-action/pull/2430)
4745

48-
## 3.26.2 - 14 Aug 2024
46+
## 2.26.2 - 14 Aug 2024
4947

5048
- Update default CodeQL bundle version to 2.18.2. [#2417](https://github.com/github/codeql-action/pull/2417)
5149

52-
## 3.26.1 - 13 Aug 2024
50+
## 2.26.1 - 13 Aug 2024
5351

5452
No user facing changes.
5553

56-
## 3.26.0 - 06 Aug 2024
54+
## 2.26.0 - 06 Aug 2024
5755

5856
- _Deprecation:_ Swift analysis on Ubuntu runner images is no longer supported. Please migrate to a macOS runner if this affects you. [#2403](https://github.com/github/codeql-action/pull/2403)
5957
- Bump the minimum CodeQL bundle version to 2.13.5. [#2408](https://github.com/github/codeql-action/pull/2408)
6058

61-
## 3.25.15 - 26 Jul 2024
59+
## 2.25.15 - 26 Jul 2024
6260

6361
- Update default CodeQL bundle version to 2.18.1. [#2385](https://github.com/github/codeql-action/pull/2385)
6462

65-
## 3.25.14 - 25 Jul 2024
63+
## 2.25.14 - 25 Jul 2024
6664

6765
- Experimental: add a new `start-proxy` action which starts the same HTTP proxy as used by [`github/dependabot-action`](https://github.com/github/dependabot-action). Do not use this in production as it is part of an internal experiment and subject to change at any time. [#2376](https://github.com/github/codeql-action/pull/2376)
6866

69-
## 3.25.13 - 19 Jul 2024
67+
## 2.25.13 - 19 Jul 2024
7068

7169
- Add `codeql-version` to outputs. [#2368](https://github.com/github/codeql-action/pull/2368)
7270
- Add a deprecation warning for customers using CodeQL version 2.13.4 and earlier. These versions of CodeQL were discontinued on 9 July 2024 alongside GitHub Enterprise Server 3.9, and will be unsupported by CodeQL Action versions 3.26.0 and later and versions 2.26.0 and later. [#2375](https://github.com/github/codeql-action/pull/2375)
7371
- If you are using one of these versions, please update to CodeQL CLI version 2.13.5 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
7472
- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.12.6 and 2.13.4, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.25.13` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.25.13` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
7573

76-
## 3.25.12 - 12 Jul 2024
74+
## 2.25.12 - 12 Jul 2024
7775

7876
- Improve the reliability and performance of analyzing code when analyzing a compiled language with the `autobuild` [build mode](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes) on GitHub Enterprise Server. This feature is already available to GitHub.com users. [#2353](https://github.com/github/codeql-action/pull/2353)
7977
- Update default CodeQL bundle version to 2.18.0. [#2364](https://github.com/github/codeql-action/pull/2364)
8078

81-
## 3.25.11 - 28 Jun 2024
79+
## 2.25.11 - 28 Jun 2024
8280

8381
- Avoid failing the workflow run if there is an error while uploading debug artifacts. [#2349](https://github.com/github/codeql-action/pull/2349)
8482
- Update default CodeQL bundle version to 2.17.6. [#2352](https://github.com/github/codeql-action/pull/2352)
8583

86-
## 3.25.10 - 13 Jun 2024
84+
## 2.25.10 - 13 Jun 2024
8785

8886
- Update default CodeQL bundle version to 2.17.5. [#2327](https://github.com/github/codeql-action/pull/2327)
8987

90-
## 3.25.9 - 12 Jun 2024
88+
## 2.25.9 - 12 Jun 2024
9189

9290
- Avoid failing database creation if the database folder already exists and contains some unexpected files. Requires CodeQL 2.18.0 or higher. [#2330](https://github.com/github/codeql-action/pull/2330)
9391
- The init Action will attempt to clean up the database cluster directory before creating a new database and at the end of the job. This will help to avoid issues where the database cluster directory is left in an inconsistent state. [#2332](https://github.com/github/codeql-action/pull/2332)
9492

95-
## 3.25.8 - 04 Jun 2024
93+
## 2.25.8 - 04 Jun 2024
9694

9795
- Update default CodeQL bundle version to 2.17.4. [#2321](https://github.com/github/codeql-action/pull/2321)
9896

99-
## 3.25.7 - 31 May 2024
97+
## 2.25.7 - 31 May 2024
10098

10199
- We are rolling out a feature in May/June 2024 that will reduce the Actions cache usage of the Action by keeping only the newest TRAP cache for each language. [#2306](https://github.com/github/codeql-action/pull/2306)
102100

103-
## 3.25.6 - 20 May 2024
101+
## 2.25.6 - 20 May 2024
104102

105103
- Update default CodeQL bundle version to 2.17.3. [#2295](https://github.com/github/codeql-action/pull/2295)
106104

107-
## 3.25.5 - 13 May 2024
105+
## 2.25.5 - 13 May 2024
108106

109107
- Add a compatibility matrix of supported CodeQL Action, CodeQL CLI, and GitHub Enterprise Server versions to the [README.md](README.md). [#2273](https://github.com/github/codeql-action/pull/2273)
110108
- Avoid printing out a warning for a missing `on.push` trigger when the CodeQL Action is triggered via a `workflow_call` event. [#2274](https://github.com/github/codeql-action/pull/2274)
111109
- The `tools: latest` input to the `init` Action has been renamed to `tools: linked`. This option specifies that the Action should use the tools shipped at the same time as the Action. The old name will continue to work for backwards compatibility, but we recommend that new workflows use the new name. [#2281](https://github.com/github/codeql-action/pull/2281)
112110

113-
## 3.25.4 - 08 May 2024
111+
## 2.25.4 - 08 May 2024
114112

115113
- Update default CodeQL bundle version to 2.17.2. [#2270](https://github.com/github/codeql-action/pull/2270)
116114

117-
## 3.25.3 - 25 Apr 2024
115+
## 2.25.3 - 25 Apr 2024
118116

119117
- Update default CodeQL bundle version to 2.17.1. [#2247](https://github.com/github/codeql-action/pull/2247)
120118
- Workflows running on `macos-latest` using CodeQL CLI versions before v2.15.1 will need to either upgrade their CLI version to v2.15.1 or newer, or change the platform to an Intel MacOS runner, such as `macos-12`. ARM machines with SIP disabled, including the newest `macos-latest` image, are unsupported for CLI versions before 2.15.1. [#2261](https://github.com/github/codeql-action/pull/2261)
121119

122-
## 3.25.2 - 22 Apr 2024
120+
## 2.25.2 - 22 Apr 2024
123121

124122
No user facing changes.
125123

126-
## 3.25.1 - 17 Apr 2024
124+
## 2.25.1 - 17 Apr 2024
127125

128126
- We are rolling out a feature in April/May 2024 that improves the reliability and performance of analyzing code when analyzing a compiled language with the `autobuild` [build mode](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes). [#2235](https://github.com/github/codeql-action/pull/2235)
129127
- Fix a bug where the `init` Action would fail if `--overwrite` was specified in `CODEQL_ACTION_EXTRA_OPTIONS`. [#2245](https://github.com/github/codeql-action/pull/2245)
130128

131-
## 3.25.0 - 15 Apr 2024
129+
## 2.25.0 - 15 Apr 2024
132130

133131
- The deprecated feature for extracting dependencies for a Python analysis has been removed. [#2224](https://github.com/github/codeql-action/pull/2224)
134-
135132
As a result, the following inputs and environment variables are now ignored:
136-
137133
- The `setup-python-dependencies` input to the `init` Action
138134
- The `CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION` environment variable
139-
140135
We recommend removing any references to these from your workflows. For more information, see the release notes for CodeQL Action v3.23.0 and v2.23.0.
141136
- Automatically overwrite an existing database if found on the filesystem. [#2229](https://github.com/github/codeql-action/pull/2229)
142137
- Bump the minimum CodeQL bundle version to 2.12.6. [#2232](https://github.com/github/codeql-action/pull/2232)
143138
- A more relevant log message and a diagnostic are now emitted when the `file` program is not installed on a Linux runner, but is required for Go tracing to succeed. [#2234](https://github.com/github/codeql-action/pull/2234)
144139

145-
## 3.24.10 - 05 Apr 2024
140+
## 2.24.10 - 05 Apr 2024
146141

147142
- Update default CodeQL bundle version to 2.17.0. [#2219](https://github.com/github/codeql-action/pull/2219)
148143
- Add a deprecation warning for customers using CodeQL version 2.12.5 and earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 3.25.0 and later and versions 2.25.0 and later. [#2220](https://github.com/github/codeql-action/pull/2220)
149144
- If you are using one of these versions, please update to CodeQL CLI version 2.12.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
150145
- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.11.6 and 2.12.5, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.24.10` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.24.10` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.
151146

152-
## 3.24.9 - 22 Mar 2024
147+
## 2.24.9 - 22 Mar 2024
153148

154149
- Update default CodeQL bundle version to 2.16.5. [#2203](https://github.com/github/codeql-action/pull/2203)
155150

156-
## 3.24.8 - 18 Mar 2024
151+
## 2.24.8 - 18 Mar 2024
157152

158153
- Improve the ease of debugging extraction issues by increasing the verbosity of the extractor logs when running in debug mode. [#2195](https://github.com/github/codeql-action/pull/2195)
159154

160-
## 3.24.7 - 12 Mar 2024
155+
## 2.24.7 - 12 Mar 2024
161156

162157
- Update default CodeQL bundle version to 2.16.4. [#2185](https://github.com/github/codeql-action/pull/2185)
163158

164-
## 3.24.6 - 29 Feb 2024
159+
## 2.24.6 - 29 Feb 2024
165160

166161
No user facing changes.
167162

168-
## 3.24.5 - 23 Feb 2024
163+
## 2.24.5 - 23 Feb 2024
169164

170165
- Update default CodeQL bundle version to 2.16.3. [#2156](https://github.com/github/codeql-action/pull/2156)
171166

172-
## 3.24.4 - 21 Feb 2024
167+
## 2.24.4 - 21 Feb 2024
173168

174169
- Fix an issue where an existing, but empty, `/sys/fs/cgroup/cpuset.cpus` file always resulted in a single-threaded run. [#2151](https://github.com/github/codeql-action/pull/2151)
175170

176-
## 3.24.3 - 15 Feb 2024
171+
## 2.24.3 - 15 Feb 2024
177172

178173
- Fix an issue where the CodeQL Action would fail to load a configuration specified by the `config` input to the `init` Action. [#2147](https://github.com/github/codeql-action/pull/2147)
179174

180-
## 3.24.2 - 15 Feb 2024
175+
## 2.24.2 - 15 Feb 2024
181176

182177
- Enable improved multi-threaded performance on larger runners for GitHub Enterprise Server users. This feature is already available to GitHub.com users. [#2141](https://github.com/github/codeql-action/pull/2141)
183178

184-
## 3.24.1 - 13 Feb 2024
179+
## 2.24.1 - 13 Feb 2024
185180

186181
- Update default CodeQL bundle version to 2.16.2. [#2124](https://github.com/github/codeql-action/pull/2124)
187182
- The CodeQL action no longer fails if it can't write to the telemetry api endpoint. [#2121](https://github.com/github/codeql-action/pull/2121)
188183

189-
## 3.24.0 - 02 Feb 2024
184+
## 2.24.0 - 02 Feb 2024
190185

191186
- CodeQL Python analysis will no longer install dependencies on GitHub Enterprise Server, as is already the case for GitHub.com. See [release notes for 3.23.0](#3230---08-jan-2024) for more details. [#2106](https://github.com/github/codeql-action/pull/2106)
192187

193-
## 3.23.2 - 26 Jan 2024
188+
## 2.23.2 - 26 Jan 2024
194189

195190
- On Linux, the maximum possible value for the `--threads` option now respects the CPU count as specified in `cgroup` files to more accurately reflect the number of available cores when running in containers. [#2083](https://github.com/github/codeql-action/pull/2083)
196191
- Update default CodeQL bundle version to 2.16.1. [#2096](https://github.com/github/codeql-action/pull/2096)
197192

198-
## 3.23.1 - 17 Jan 2024
193+
## 2.23.1 - 17 Jan 2024
199194

200195
- Update default CodeQL bundle version to 2.16.0. [#2073](https://github.com/github/codeql-action/pull/2073)
201196
- Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. [#2079](https://github.com/github/codeql-action/pull/2079)
202197

203-
## 3.23.0 - 08 Jan 2024
198+
## 2.23.0 - 08 Jan 2024
204199

205200
- We are rolling out a feature in January 2024 that will disable Python dependency installation by default for all users. This improves the speed of analysis while having only a very minor impact on results. You can override this behavior by setting `CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION=false` in your workflow, however we plan to remove this ability in future versions of the CodeQL Action. [#2031](https://github.com/github/codeql-action/pull/2031)
206201
- The CodeQL Action now requires CodeQL version 2.11.6 or later. For more information, see [the corresponding changelog entry for CodeQL Action version 2.22.7](#2227---16-nov-2023). [#2009](https://github.com/github/codeql-action/pull/2009)
207202

208-
## 3.22.12 - 22 Dec 2023
203+
## 2.22.12 - 22 Dec 2023
209204

210205
- Update default CodeQL bundle version to 2.15.5. [#2047](https://github.com/github/codeql-action/pull/2047)
211206

212-
## 3.22.11 - 13 Dec 2023
207+
## 2.22.11 - 13 Dec 2023
213208

214-
- [v3+ only] The CodeQL Action now runs on Node.js v20. [#2006](https://github.com/github/codeql-action/pull/2006)
209+
No user facing changes.
215210

216211
## 2.22.10 - 12 Dec 2023
217212

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "codeql",
3-
"version": "3.26.11",
3+
"version": "2.26.11",
44
"private": true,
55
"description": "CodeQL action",
66
"scripts": {

0 commit comments

Comments
 (0)