Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
[UNRELEASED]
No user facing changes.
2.20.2 - 03 Jul 2023
No user facing changes.
2.20.1 - 21 Jun 2023
- Update default CodeQL bundle version to 2.13.4. #1721
- Experimental: add a new
resolve-environment
action which attempts to infer a configuration for the build environment that is required to build a given project. Do not use this in production as it is part of an internal experiment and subject to change at any time.2.20.0 - 13 Jun 2023
- Bump the version of the Action to 2.20.0. This ensures that users who received a Dependabot upgrade to
cdcdbb5
, which was mistakenly marked as Action version 2.13.4, continue to receive updates to the CodeQL Action. Full details in #17292.3.6 - 01 Jun 2023
- Update default CodeQL bundle version to 2.13.3. #1698
2.3.5 - 25 May 2023
- Allow invalid URIs to be used as values to
artifactLocation.uri
properties. This reverses a change from #1668 that inadvertently led to stricter validation of some URI values. #1705- Gracefully handle invalid URIs when fingerprinting. #1694
2.3.4 - 24 May 2023
- Updated the SARIF 2.1.0 JSON schema file to the latest from oasis-tcs/sarif-spec. #1668
- We are rolling out a feature in May 2023 that will disable Python dependency installation for new users of the CodeQL Action. This improves the speed of analysis while having only a very minor impact on results. #1676
- We are improving the way that CodeQL bundles are tagged to make it possible to easily identify bundles by their CodeQL semantic version. #1682
- As of CodeQL CLI 2.13.4, CodeQL bundles will be tagged using semantic versions, for example
codeql-bundle-v2.13.4
, instead of timestamps, likecodeql-bundle-20230615
.- This change does not affect the majority of workflows, and we will not be changing tags for existing bundle releases.
- Some workflows with custom logic that depends on the specific format of the CodeQL bundle tag may need to be updated. For example, if your workflow matches CodeQL bundle tag names against a
codeql-bundle-yyyymmdd
pattern, you should update it to also recognizecodeql-bundle-vx.y.z
tags.- Remove the requirement for
on.push
andon.pull_request
to trigger on the same branches. #16752.3.3 - 04 May 2023
- Update default CodeQL bundle version to 2.13.1. #1664
- You can now configure CodeQL within your code scanning workflow by passing a
config
input to theinit
Action. See Using a custom configuration file for more information about configuring code scanning. #15902.3.2 - 27 Apr 2023
No user facing changes.
2.3.1 - 26 Apr 2023
No user facing changes.
... (truncated)
004c5de
Merge pull request #1746
from github/update-v2.20.2-7dfbc0e0dcb0b0a3
Update changelog for v2.20.27dfbc0e
Bump semver from 7.3.8 to 7.5.2 (#1745)46a6823
Send new per-query alert count event reports for QA telemetry (#1741)cff3d9e
Merge pull request #1737
from github/mergeback/v2.20.1-to-main-f6e388eb75c683d
Update checked-in dependenciesf4eef0b
Update changelog and version after v2.20.1