-
Notifications
You must be signed in to change notification settings - Fork 5
chore(deps): update github/codeql-action action to v3.31.9 #678
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
🤠 Cargo bloat for toolchain stable-x86_64-unknown-linux-gnu 🤠 @@ Size breakdown @@
- Size 8.38 MB
+ Size 8.37 MB -18.99 KB
- Text Size 2.15 MB
+ Text Size 2.14 MB -11.94 KB
Size difference per crateNote: The numbers below are not 100% accurate, use them as a rough estimate. @@ Breakdown per crate @@
- (stratum_server) hyper::proto::h1::conn::Conn<I,B,T>::write_trailers 681 B
+ (stratum_server) hyper::proto::h1::conn::Conn<I,B,T>::write_trailers 4.78 KB
+ (stratum_server) tower_layer::tuple::<impl tower_layer::Layer<S> for (... 1.48 KB
+ (tokio) tokio::runtime::signal::Driver::shutdown 759 B
+ (http) <http::header::value::HeaderValue as core::convert::From<u64>>:... 631 B
- (num_cpus) num_cpus::linux::init_cgroups 6.08 KB
- (stratum_server) hyper::proto::h1::encode::Encoder::encode_trailers 5.11 KB
- (tokio) alloc::collections::btree::map::BTreeMap<K,V,A>::insert 3.05 KB
- (stratum_server) <http::header::map::HeaderMap<T> as core::iter::trait... 2.26 KB
- (tokio) core::slice::sort::merge_sort 2.04 KB
- (stratum_server) <&T as tower_layer::Layer<S>>::layer 1.55 KB
- (tokio) tokio::runtime::scheduler::current_thread::CurrentThread::shut... 1.29 KB
- (tokio) tokio::runtime::time::wheel::Wheel::poll 935 B
- (num_cpus) std::io::append_to_string 849 B
- (num_cpus) core::str::<impl str>::trim_matches 685 B
- (http) <http::header::value::HeaderValue as core::convert::From<usize>... 631 B
- (hyper) core::fmt::num::<impl core::fmt::Debug for usize>::fmt 29 B
- (num_cpus) num_cpus::linux::get_num_cpus 480 B
- (tokio) tokio::runtime::io::registration_set::RegistrationSet::shutdow... 418 B
- (num_cpus) std::sys::sync::once::futex::Once::call 415 B
- (tower_http) tower_http::cors::CorsLayer::new 394 B
- (std) std::path::Path::_join 382 B
- (stratum_server) hyper::proto::h1::encode::Encoder::encode_and_end 381 B
- (tokio) tokio::runtime::io::driver::Driver::shutdown 379 B
- (num_cpus) num_cpus::linux::Cgroup::raw_param 369 B
- (serde_json) serde_json::de::from_trait 369 B
- (tokio) tokio::runtime::io::registration_set::RegistrationSet::release 367 B
- (stratum_server) <std::collections::hash::map::HashMap<K,V,S> as core:... 352 B
- (tokio) hashbrown::map::HashMap<K,V,S,A>::remove 342 B
- (tokio) tokio::runtime::time::wheel::Wheel::remove 331 B
- (tokio) tokio::runtime::time::Driver::shutdown 315 B
- (mio) mio::sys::unix::selector::epoll::Selector::select 290 B
- (tokio) tokio::runtime::time::wheel::Wheel::insert 288 B
- (stratum_server) futures_channel::mpsc::queue::Queue<T>::pop_spin 268 B
- (std) core::ptr::drop_in_place<alloc::vec::into_iter::IntoIter<http::h... 271 B
- (num_cpus) <std::io::Lines<B> as core::iter::traits::iterator::Iterato... 254 B
- (tokio) core::ptr::drop_in_place<tokio::runtime::io::driver::Handle> 248 B
- (tokio) tokio::runtime::time::wheel::Wheel::new 246 B
- (mio) mio::sys::unix::selector::epoll::Selector::new 245 B
- (tokio) core::ptr::drop_in_place<alloc::vec::Vec<alloc::sync::Arc<toki... 243 B
- (tokio) core::ptr::drop_in_place<tokio::loom::std::parking_lot::Mutex<... 87 B
- (std) std::fs::OpenOptions::_open 214 B
- (mio) mio::sys::unix::waker::eventfd::WakerInternal::wake 202 B
- (std) core::ptr::drop_in_place<alloc::vec::Vec<(usize,std::thread::Joi... 191 B
- (mio) mio::sys::unix::waker::fdbased::Waker::new 186 B
- (std) std::path::PathBuf::_push 185 B
- (stratum_server) core::ptr::drop_in_place<futures_channel::oneshot::Re... 185 B
- (tokio) alloc::raw_vec::RawVec<T,A>::reserve::do_reserve_and_handle 177 B
- (num_cpus) num_cpus::linux::Cgroup::param 169 B
- (num_cpus) alloc::raw_vec::RawVec<T,A>::reserve::do_reserve_and_handle 156 B
- (tokio) core::ptr::drop_in_place<tokio::runtime::context::set_schedule... 155 B
- (stratum_server) axum::routing::route::Route<E>::oneshot_inner 155 B
- (tokio) core::ptr::drop_in_place<tokio::runtime::scheduler::inject::po... 150 B
- (tokio) core::ptr::drop_in_place<alloc::sync::ArcInner<tokio::runtime:... 148 B
- (num_cpus) alloc::raw_vec::finish_grow 141 B
- (tokio) core::ptr::drop_in_place<(usize,std::thread::JoinHandle<()>)> 133 B
- (std) <std::fs::File as std::io::Read>::read_buf 129 B
- (tokio) tokio::runtime::task::Schedule::yield_now 116 B
- (stratum_server) axum::boxed::BoxedIntoRoute<S,E>::into_route 110 B
- (mio) <mio::net::tcp::stream::TcpStream as mio::event::source::Source>... 51 B
- (mio) <mio::net::tcp::listener::TcpListener as mio::event::source::Sou... 109 B
- (num_cpus) alloc::vec::Vec<T,A>::extend_from_slice 90 B
- (stratum_server) core::ptr::drop_in_place<futures_channel::mpsc::Recei... 88 B
- (std) core::ptr::drop_in_place<num_cpus::linux::MountInfo> 54 B
- (std) core::ptr::drop_in_place<tokio::signal::unix::OsExtraData> 52 B
- (mio) <mio::net::uds::stream::UnixStream as mio::event::source::Source... 51 B
- (std) core::ptr::drop_in_place<core::iter::adapters::filter_map::Filte... 37 B
- (std) core::ptr::drop_in_place<std::io::Lines<std::io::buffered::bufre... 37 B
- (std) core::ptr::drop_in_place<axum::json::Json<core::option::Option<s... 37 B
- (std) core::ptr::drop_in_place<axum::json::Json<stratum_server::ban_ma... 37 B
- (mio) <mio::sys::unix::selector::epoll::Selector as core::ops::drop::D... 36 B
- (std) <std::fs::File as std::io::Read>::read_to_string 28 B
- (tokio) tokio::util::rand::FastRand::new 28 B
- (serde_json) <serde_json::raw::ReferenceFromString as serde::de::Visit... 21 B
- (bytes) <*const T as core::fmt::Debug>::fmt 9 B
- (axum_core) core::error::Error::source 3 B
- (std) core::ptr::drop_in_place<signal_hook_registry::register<tokio::s... 1 B
- (tokio) core::ptr::drop_in_place<&std::process::Child> 1 B
- (tokio) core::ptr::drop_in_place<tokio::loom::std::parking_lot::RwLock... 1 B
- (std) core::ptr::drop_in_place<&lock_api::mutex::Mutex<parking_lot::ra... 1 B
- (std) core::ptr::drop_in_place<tokio::runtime::builder::Builder::new::... 1 B
- (axum_core) core::ptr::drop_in_place<http::header::map::MaxSizeReached... 1 B
- (hyper) core::ptr::drop_in_place<&http::header::value::HeaderValue> 1 B
- (stratum_server) core::ptr::drop_in_place<http::header::value::Invalid... 1 B
- (stratum_server) core::ptr::drop_in_place<hyper::proto::h1::encode::No... 1 B
- (std) core::ptr::drop_in_place<&tracing_core::span::Id> 1 B
- (std) core::ptr::drop_in_place<serde_json::raw::BoxedFromString> 1 BDependency tree@@ Dependency tree @@
- Count: 223
+ Count: 221
├─ async-trait v0.1.81 (proc-macro)
│ ├─ proc-macro2 v1.0.86
│ │ └─ unicode-ident v1.0.12
│ ├─ quote v1.0.36
│ │ └─ proc-macro2 v1.0.86
- │ └─ syn v2.0.70
+ │ └─ syn v2.0.72
│ ├─ proc-macro2 v1.0.86
│ ├─ quote v1.0.36
│ └─ unicode-ident v1.0.12
├─ axum v0.7.5
│ ├─ async-trait v0.1.81 (proc-macro)
│ ├─ axum-core v0.4.3
│ │ ├─ async-trait v0.1.81 (proc-macro)
- │ │ ├─ bytes v1.6.0
+ │ │ ├─ bytes v1.6.1
│ │ ├─ futures-util v0.3.30
│ │ │ ├─ futures-channel v0.3.30
│ │ │ │ ├─ futures-core v0.3.30
│ │ │ │ └─ futures-sink v0.3.30
│ │ │ ├─ futures-core v0.3.30
│ │ │ ├─ futures-io v0.3.30
│ │ │ ├─ futures-macro v0.3.30 (proc-macro)
│ │ │ │ ├─ proc-macro2 v1.0.86
│ │ │ │ ├─ quote v1.0.36
- │ │ │ │ └─ syn v2.0.70
+ │ │ │ │ └─ syn v2.0.72
│ │ │ ├─ futures-sink v0.3.30
│ │ │ ├─ futures-task v0.3.30
│ │ │ ├─ memchr v2.7.4
│ │ │ ├─ pin-project-lite v0.2.14
│ │ │ ├─ pin-utils v0.1.0
│ │ │ └─ slab v0.4.9
│ │ │ └─ autocfg v1.3.0
│ │ ├─ http v1.1.0
- │ │ │ ├─ bytes v1.6.0
+ │ │ │ ├─ bytes v1.6.1
│ │ │ ├─ fnv v1.0.7
│ │ │ └─ itoa v1.0.11
- │ │ ├─ http-body v1.0.0
- │ │ │ ├─ bytes v1.6.0
+ │ │ ├─ http-body v1.0.1
+ │ │ │ ├─ bytes v1.6.1
│ │ │ └─ http v1.1.0
│ │ ├─ http-body-util v0.1.2
- │ │ │ ├─ bytes v1.6.0
+ │ │ │ ├─ bytes v1.6.1
│ │ │ ├─ futures-util v0.3.30
│ │ │ ├─ http v1.1.0
- │ │ │ ├─ http-body v1.0.0
+ │ │ │ ├─ http-body v1.0.1
│ │ │ └─ pin-project-lite v0.2.14
│ │ ├─ mime v0.3.17
│ │ ├─ pin-project-lite v0.2.14
│ │ ├─ sync_wrapper v0.1.2
│ │ ├─ tower-layer v0.3.2
│ │ ├─ tower-service v0.3.2
│ │ ├─ tracing v0.1.40
│ │ │ ├─ log v0.4.22
│ │ │ ├─ pin-project-lite v0.2.14
│ │ │ ├─ tracing-attributes v0.1.27 (proc-macro)
│ │ │ │ ├─ proc-macro2 v1.0.86
│ │ │ │ ├─ quote v1.0.36
- │ │ │ │ └─ syn v2.0.70
+ │ │ │ │ └─ syn v2.0.72
│ │ │ └─ tracing-core v0.1.32
│ │ │ └─ once_cell v1.19.0
│ │ └─ rustversion v1.0.17 (proc-macro)
- │ ├─ bytes v1.6.0
+ │ ├─ bytes v1.6.1
│ ├─ futures-util v0.3.30
│ ├─ http v1.1.0
- │ ├─ http-body v1.0.0
+ │ ├─ http-body v1.0.1
│ ├─ http-body-util v0.1.2
│ ├─ hyper v1.4.1
- │ │ ├─ bytes v1.6.0
+ │ │ ├─ bytes v1.6.1
│ │ ├─ futures-channel v0.3.30
│ │ ├─ futures-util v0.3.30
│ │ ├─ http v1.1.0
- │ │ ├─ http-body v1.0.0
+ │ │ ├─ http-body v1.0.1
│ │ ├─ httparse v1.9.4
│ │ ├─ httpdate v1.0.3
│ │ ├─ itoa v1.0.11
│ │ ├─ pin-project-lite v0.2.14
│ │ ├─ smallvec v1.13.2
- │ │ └─ tokio v1.38.0
- │ │ ├─ bytes v1.6.0
+ │ │ └─ tokio v1.39.1
+ │ │ ├─ bytes v1.6.1
│ │ ├─ libc v0.2.155
- │ │ ├─ mio v0.8.11
+ │ │ ├─ mio v1.0.1
│ │ │ └─ libc v0.2.155
- │ │ ├─ num_cpus v1.16.0
- │ │ │ └─ libc v0.2.155
│ │ ├─ parking_lot v0.12.3
│ │ │ ├─ lock_api v0.4.12
│ │ │ │ ├─ scopeguard v1.2.0
│ │ │ │ └─ autocfg v1.3.0
│ │ │ └─ parking_lot_core v0.9.10
│ │ │ ├─ cfg-if v1.0.0
│ │ │ ├─ libc v0.2.155
│ │ │ └─ smallvec v1.13.2
│ │ ├─ pin-project-lite v0.2.14
│ │ ├─ signal-hook-registry v1.4.2
│ │ │ └─ libc v0.2.155
│ │ ├─ socket2 v0.5.7
│ │ │ └─ libc v0.2.155
- │ │ └─ tokio-macros v2.3.0 (proc-macro)
+ │ │ └─ tokio-macros v2.4.0 (proc-macro)
│ │ ├─ proc-macro2 v1.0.86
│ │ ├─ quote v1.0.36
- │ │ └─ syn v2.0.70
+ │ │ └─ syn v2.0.72
│ ├─ hyper-util v0.1.6
- │ │ ├─ bytes v1.6.0
+ │ │ ├─ bytes v1.6.1
│ │ ├─ futures-util v0.3.30
│ │ ├─ http v1.1.0
- │ │ ├─ http-body v1.0.0
+ │ │ ├─ http-body v1.0.1
│ │ ├─ hyper v1.4.1
│ │ ├─ pin-project-lite v0.2.14
- │ │ └─ tokio v1.38.0
+ │ │ └─ tokio v1.39.1
│ ├─ itoa v1.0.11
│ ├─ matchit v0.7.3
│ ├─ memchr v2.7.4
│ ├─ mime v0.3.17
│ ├─ percent-encoding v2.3.1
│ ├─ pin-project-lite v0.2.14
│ ├─ serde v1.0.204
│ │ └─ serde_derive v1.0.204 (proc-macro)
│ │ ├─ proc-macro2 v1.0.86
│ │ ├─ quote v1.0.36
- │ │ └─ syn v2.0.70
+ │ │ └─ syn v2.0.72
│ ├─ serde_json v1.0.120
│ │ ├─ itoa v1.0.11
│ │ ├─ ryu v1.0.18
│ │ └─ serde v1.0.204
│ ├─ serde_path_to_error v0.1.16
│ │ ├─ itoa v1.0.11
│ │ └─ serde v1.0.204
│ ├─ serde_urlencoded v0.7.1
│ │ ├─ form_urlencoded v1.2.1
│ │ │ └─ percent-encoding v2.3.1
│ │ ├─ itoa v1.0.11
│ │ ├─ ryu v1.0.18
│ │ └─ serde v1.0.204
│ ├─ sync_wrapper v1.0.1
- │ ├─ tokio v1.38.0
+ │ ├─ tokio v1.39.1
│ ├─ tower v0.4.13
│ │ ├─ futures-core v0.3.30
│ │ ├─ futures-util v0.3.30
│ │ ├─ pin-project v1.1.5
│ │ │ └─ pin-project-internal v1.1.5 (proc-macro)
│ │ │ ├─ proc-macro2 v1.0.86
│ │ │ ├─ quote v1.0.36
- │ │ │ └─ syn v2.0.70
+ │ │ │ └─ syn v2.0.72
│ │ ├─ pin-project-lite v0.2.14
- │ │ ├─ tokio v1.38.0
+ │ │ ├─ tokio v1.39.1
│ │ ├─ tower-layer v0.3.2
│ │ ├─ tower-service v0.3.2
│ │ └─ tracing v0.1.40
│ ├─ tower-layer v0.3.2
│ ├─ tower-service v0.3.2
│ ├─ tracing v0.1.40
│ └─ rustversion v1.0.17 (proc-macro)
├─ bit-set v0.5.3
│ └─ bit-vec v0.6.3
- ├─ bytes v1.6.0
+ ├─ bytes v1.6.1
├─ dashmap v5.5.3
│ ├─ cfg-if v1.0.0
│ ├─ hashbrown v0.14.5
│ ├─ lock_api v0.4.12
│ ├─ once_cell v1.19.0
│ └─ parking_lot_core v0.9.10
├─ extended-primitives v0.3.8
│ ├─ encodings v0.1.0
- │ └─ thiserror v1.0.62
- │ └─ thiserror-impl v1.0.62 (proc-macro)
+ │ └─ thiserror v1.0.63
+ │ └─ thiserror-impl v1.0.63 (proc-macro)
│ ├─ proc-macro2 v1.0.86
│ ├─ quote v1.0.36
- │ └─ syn v2.0.70
+ │ └─ syn v2.0.72
├─ futures v0.3.30
│ ├─ futures-channel v0.3.30
│ ├─ futures-core v0.3.30
│ ├─ futures-executor v0.3.30
│ │ ├─ futures-core v0.3.30
│ │ ├─ futures-task v0.3.30
│ │ └─ futures-util v0.3.30
│ ├─ futures-io v0.3.30
│ ├─ futures-sink v0.3.30
│ ├─ futures-task v0.3.30
│ └─ futures-util v0.3.30
├─ hyper v1.4.1
├─ parking_lot v0.12.3
├─ rlimit v0.10.1
│ └─ libc v0.2.155
├─ serde v1.0.204
├─ serde_json v1.0.120
- ├─ thiserror v1.0.62
- ├─ tokio v1.38.0
+ ├─ thiserror v1.0.63
+ ├─ tokio v1.39.1
├─ tokio-stream v0.1.15
│ ├─ futures-core v0.3.30
│ ├─ pin-project-lite v0.2.14
- │ └─ tokio v1.38.0
+ │ └─ tokio v1.39.1
├─ tokio-util v0.7.11
- │ ├─ bytes v1.6.0
+ │ ├─ bytes v1.6.1
│ ├─ futures-core v0.3.30
│ ├─ futures-sink v0.3.30
│ ├─ pin-project-lite v0.2.14
│ ├─ slab v0.4.9
- │ └─ tokio v1.38.0
+ │ └─ tokio v1.39.1
├─ tower-http v0.5.2
│ ├─ bitflags v2.6.0
- │ ├─ bytes v1.6.0
+ │ ├─ bytes v1.6.1
│ ├─ http v1.1.0
- │ ├─ http-body v1.0.0
+ │ ├─ http-body v1.0.1
│ ├─ http-body-util v0.1.2
│ ├─ pin-project-lite v0.2.14
│ ├─ tower-layer v0.3.2
│ └─ tower-service v0.3.2
├─ tracing v0.1.40
└─ uuid v1.10.0
├─ getrandom v0.2.15
│ ├─ cfg-if v1.0.0
│ └─ libc v0.2.155
├─ rand v0.8.5
│ ├─ libc v0.2.155
│ ├─ rand_chacha v0.3.1
│ │ ├─ ppv-lite86 v0.2.17
│ │ └─ rand_core v0.6.4
│ │ └─ getrandom v0.2.15
│ └─ rand_core v0.6.4
├─ serde v1.0.204
└─ uuid-macro-internal v1.10.0 (proc-macro)
├─ proc-macro2 v1.0.86
├─ quote v1.0.36
- └─ syn v2.0.70
+ └─ syn v2.0.72
Commit: de408de (Compare with baseline commit) |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #678 +/- ##
==========================================
+ Coverage 68.35% 69.31% +0.96%
==========================================
Files 29 29
Lines 1839 1799 -40
==========================================
- Hits 1257 1247 -10
+ Misses 582 552 -30 ☔ View full report in Codecov by Sentry. |
|
bors: r+ |
e1aa763 to
fb12c1f
Compare
fb12c1f to
dc04046
Compare
dc04046 to
95f9a67
Compare
95f9a67 to
ef14877
Compare
ef14877 to
ade987a
Compare
ade987a to
e9a18fd
Compare
e9a18fd to
5704219
Compare
5704219 to
8b77066
Compare
5bbc138 to
e9048de
Compare
e9048de to
331382c
Compare
331382c to
0ba5ba1
Compare
0ba5ba1 to
5f278e0
Compare
5f278e0 to
741b6fd
Compare
741b6fd to
f99ac0c
Compare
f99ac0c to
8238ab5
Compare
8238ab5 to
d0c587c
Compare
d0c587c to
4a0a9df
Compare
4a0a9df to
0693cb4
Compare
This PR contains the following updates:
v3.23.2->v3.31.9Release Notes
github/codeql-action (github/codeql-action)
v3.31.9Compare Source
v3.31.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.8 - 11 Dec 2025
See the full CHANGELOG.md for more information.
v3.31.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.7 - 05 Dec 2025
See the full CHANGELOG.md for more information.
v3.31.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.6 - 01 Dec 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.31.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.5 - 24 Nov 2025
See the full CHANGELOG.md for more information.
v3.31.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.4 - 18 Nov 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.31.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.3 - 13 Nov 2025
See the full CHANGELOG.md for more information.
v3.31.2Compare Source
v3.31.1Compare Source
v3.31.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.0 - 24 Oct 2025
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #3222See the full CHANGELOG.md for more information.
v3.30.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.9 - 17 Oct 2025
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204See the full CHANGELOG.md for more information.
v3.30.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.8 - 10 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.7 - 06 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.6 - 02 Oct 2025
See the full CHANGELOG.md for more information.
v3.30.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.5 - 26 Sep 2025
3.30.4withupload-sarifwhich resulted in files without a.sarifextension not getting uploaded. #3160See the full CHANGELOG.md for more information.
v3.30.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.4 - 25 Sep 2025
codeql-action/initstep if different versions of the CodeQL Action are detected in the workflow file. Additionally, an error will now be thrown by the other CodeQL Action steps if they load a configuration file that was generated by a different version of thecodeql-action/initstep. #3099 and #3100tools: nightlyto theinitaction. In general, the nightly bundle is unstable and we only recommend running it when directed by GitHub staff. #3130See the full CHANGELOG.md for more information.
v3.30.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.3 - 10 Sep 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.2 - 09 Sep 2025
quality-queriesinput that was added in3.29.2as part of an internal experiment is now deprecated and will be removed in an upcoming version of the CodeQL Action. It has been superseded by a newanalysis-kindsinput, which is part of the same internal experiment. Do not use this in production as it is subject to change at any time. #3064See the full CHANGELOG.md for more information.
v3.30.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.1 - 05 Sep 2025
See the full CHANGELOG.md for more information.
v3.30.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.0 - 01 Sep 2025
See the full CHANGELOG.md for more information.
v3.29.11Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.11 - 21 Aug 2025
See the full CHANGELOG.md for more information.
v3.29.10Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.10 - 18 Aug 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.9 - 12 Aug 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.8 - 08 Aug 2025
See the full CHANGELOG.md for more information.
v3.29.7Compare Source
This is a re-release of v3.29.5 to mitigate an issue that was discovered with v3.29.6.
v3.29.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.6 - 07 Aug 2025
cleanup-levelinput to theanalyzeAction is now deprecated. The CodeQL Action has written a limited amount of intermediate results to the database since version 2.2.5, and now automatically manages cleanup. #2999See the full CHANGELOG.md for more information.
v3.29.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.5 - 29 Jul 2025
See the full CHANGELOG.md for more information.
v3.29.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.4 - 23 Jul 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.3 - 21 Jul 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.29.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.2 - 30 Jun 2025
quality-queriesinput for theinitaction is provided with an argument, separate.quality.sariffiles are produced and uploaded for each language with the results of the specified queries. Do not use this in production as it is part of an internal experiment and subject to change at any time. #2935See the full CHANGELOG.md for more information.
v3.29.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.1 - 27 Jun 2025
includequery filter fails to exclude non-included queries. #2938See the full CHANGELOG.md for more information.
v3.29.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.29.0 - 11 Jun 2025
See the full CHANGELOG.md for more information.
v3.28.21Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.21 - 28 July 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.20Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.20 - 21 July 2025
See the full CHANGELOG.md for more information.
v3.28.19Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.19 - 03 Jun 2025
actionslanguage, which is currently in public preview.The
actionsextractor has been included in the CodeQL CLI since v2.20.6. If your workflow has enabled theactionslanguage and you have pinnedyour
tools:property to a specific version of the CodeQL CLI earlier than v2.20.6, you will need to update to at least CodeQL v2.20.6 or disableactionsanalysis.See the full CHANGELOG.md for more information.
v3.28.18Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.18 - 16 May 2025
CODEQL_THREADSandCODEQL_RAMrunner environment variables. If set, these environment variables override thethreadsandraminputs respectively. #2891See the full CHANGELOG.md for more information.
v3.28.17Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.17 - 02 May 2025
See the full CHANGELOG.md for more information.
v3.28.16Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.16 - 23 Apr 2025
See the full CHANGELOG.md for more information.
v3.28.15Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.15 - 07 Apr 2025
See the full CHANGELOG.md for more information.
v3.28.14Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.14 - 07 Apr 2025
See the full CHANGELOG.md for more information.
v3.28.13Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.13 - 24 Mar 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.12Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.12 - 19 Mar 2025
build-mode: noneextractions. This should speed up workflows and avoid inconsistent alerts in some cases.See the full CHANGELOG.md for more information.
v3.28.11Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.11 - 07 Mar 2025
See the full CHANGELOG.md for more information.
v3.28.10Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.10 - 21 Feb 2025
See the full CHANGELOG.md for more information.
v3.28.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.9 - 07 Feb 2025
See the full CHANGELOG.md for more information.
v3.28.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.8 - 29 Jan 2025
See the full CHANGELOG.md for more information.
v3.28.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.7 - 29 Jan 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.6 - 27 Jan 2025
See the full CHANGELOG.md for more information.
v3.28.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.5 - 24 Jan 2025
See the full CHANGELOG.md for more information.
v3.28.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.4 - 23 Jan 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.3 - 22 Jan 2025
See the full CHANGELOG.md for more information.
v3.28.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.2 - 21 Jan 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.28.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.28.1 - 10 Jan 2025
See the full CHANGELOG.md for more information.
v3.28.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.28.0 - 20 Dec 2024
See the full CHANGELOG.md for more information.
v3.27.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.9 - 12 Dec 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.27.8Compare Source
v3.27.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.7 - 10 Dec 2024
See the full CHANGELOG.md for more information.
v3.27.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.6 - 03 Dec 2024
See the full CHANGELOG.md for more information.
v3.27.5Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.5 - 19 Nov 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.27.4Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.4 - 14 Nov 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.27.3Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.3 - 12 Nov 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.27.2Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.2 - 12 Nov 2024
See the full CHANGELOG.md for more information.
v3.27.1Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.1 - 08 Nov 2024
See the full CHANGELOG.md for more information.
v3.27.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.27.0 - 22 Oct 2024
upload-sarifAction would fail with "upload-sarif post-action step failed: Input required and not supplied: token" when called in a composite Action that had a different set of inputs to the ones expected by theupload-sarifAction. #2557See the full CHANGELOG.md for more information.
v3.26.13Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.26.13 - 14 Oct 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.26.12Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.26.12 - 07 Oct 2024
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.14.5 and earlier. These versions of CodeQL were discontinued on 24 September 2024 alongside GitHub Enterprise Server 3.10, and will be unsupported by CodeQL Action versions 3.27.0 and later and versions 2.27.0 and later. #2520
If you are using one of these versions, please update to CodeQL CLI version 2.14.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.
Alternatively, if you want to continue using a version of the CodeQL CLI between 2.13.5 and 2.14.5, you can replace
github/codeql-action/*@​v3bygithub/codeql-action/*@​v3.26.11andgithub/codeql-action/*@​v2bygithub/codeql-action/*@​v2.26.11in your code scanning workflow to ensure you continue using this version of the CodeQL Action.See the full CHANGELOG.md for more information.
v3.26.11Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.26.11 - 03 Oct 2024
Upcoming breaking change: Add support for using
actions/download-artifact@v4to programmatically consume CodeQL Action debug artifacts.Starting November 30, 2024, GitHub.com customers will no longer be able to use
actions/download-artifact@v3. Therefore, to avoid breakage, customers who programmatically download the CodeQL Action debug artifacts should set theCODEQL_ACTION_ARTIFACT_V4_UPGRADEenvironment variable totrueand bumpactions/download-artifact@v3toactions/download-artifact@v4in their workflows. The CodeQL Action will enable this behavior by default in early November and workflows that have not yet bumped toactions/download-artifact@v3toactions/download-artifact@v4will begin failing then.This change is currently unavailable for GitHub Enterprise Server customers, as
actions/upload-artifact@v4andactions/download-artifact@v4are not yet compatible with GHES.See the full CHANGELOG.md for more information.
v3.26.10Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.26.10 - 30 Sep 2024
See the full CHANGELOG.md for more information.
v3.26.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to support running on node 16. For example3.22.11was the firstv3release and is functionally identical to2.22.11. This approach ensures an easy way to track exactly which features are included in different versions, indicated by the minor and patch version numbers.3.26.9 - 24 Sep 2024
No user facing changes.
See the full CHANGELOG.md for more information.
v3.26.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
Note that the only difference between
v2andv3of the CodeQL Action is the node version they support, withv3running on node 20 while we continue to releasev2to suppConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.