Skip to content

Commit 4238421

Browse files
authored
Merge pull request #1360 from github/update-v2.1.32-33b10be6
Merge main into releases/v2
2 parents c3b6fce + 97be623 commit 4238421

34 files changed

+385
-37
lines changed

Diff for: .github/workflows/__export-file-baseline-information.yml

+85
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

Diff for: .github/workflows/script/check-node-modules.sh

+6-3
Original file line numberDiff line numberDiff line change
@@ -7,16 +7,19 @@ if [ ! -z "$(git status --porcelain)" ]; then
77
>&2 echo "Failed: Repo should be clean before testing!"
88
exit 1
99
fi
10-
sudo npm install --force -g npm@latest
10+
# Pin npm to v8 since v9 doesn't support Node 12.
11+
# When updating this, make sure to update the npm version in
12+
# `.github/workflows/update-dependencies.yml` too.
13+
sudo npm install --force -g npm@^8.19.3
1114
# Reinstall modules and then clean to remove absolute paths
1215
# Use 'npm ci' instead of 'npm install' as this is intended to be reproducible
1316
npm ci
1417
npm run removeNPMAbsolutePaths
1518
# Check that repo is still clean
1619
if [ ! -z "$(git status --porcelain)" ]; then
1720
# If we get a fail here then the PR needs attention
18-
>&2 echo "Failed: node_modules are not up to date. Run 'npm ci && npm run removeNPMAbsolutePaths' on a macOS machine to update. Note it is important this command is run on macOS and not any other operating system as there is one dependency (fsevents) that is needed for macOS and may not be installed if the command is run on a Windows or Linux machine."
21+
>&2 echo "Failed: node_modules are not up to date. Add the 'Update dependencies' label to your PR to update them. Note it is important that node modules are updated on macOS and not any other operating system as there is one dependency (fsevents) that is needed for macOS and may not be installed if dependencies are updated on a Windows or Linux machine."
1922
git status
2023
exit 1
2124
fi
22-
echo "Success: node_modules are up to date"
25+
echo "Success: node_modules are up to date"

Diff for: .github/workflows/update-dependencies.yml

+4-1
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,10 @@ jobs:
2727
run: |
2828
git fetch origin "$BRANCH" --depth=1
2929
git checkout "origin/$BRANCH"
30-
sudo npm install --force -g npm@latest
30+
# Pin npm to v8 since v9 doesn't support Node 12.
31+
# When updating this, make sure to update the npm version in
32+
# `.github/workflows/script/check-node-modules.sh` too.
33+
sudo npm install --force -g npm@^8.19.3
3134
npm install
3235
npm ci
3336
npm run removeNPMAbsolutePaths

Diff for: CHANGELOG.md

+5
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,10 @@
11
# CodeQL Action Changelog
22

3+
## 2.1.32 - 14 Nov 2022
4+
5+
- Update default CodeQL bundle version to 2.11.3. [#1348](https://github.com/github/codeql-action/pull/1348)
6+
- Update the ML-powered additional query pack for JavaScript to version 0.4.0. [#1351](https://github.com/github/codeql-action/pull/1351)
7+
38
## 2.1.31 - 04 Nov 2022
49

510
- The `rb/weak-cryptographic-algorithm` Ruby query has been updated to no longer report uses of hash functions such as `MD5` and `SHA1` even if they are known to be weak. These hash algorithms are used very often in non-sensitive contexts, making the query too imprecise in practice. For more information, see the corresponding change in the [github/codeql repository](https://github.com/github/codeql/pull/11129). [#1344](https://github.com/github/codeql-action/pull/1344)

Diff for: lib/analyze-action.js

+2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)