Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
[UNRELEASED]
No user facing changes.
2.3.4 - 24 May 2023
- Updated the SARIF 2.1.0 JSON schema file to the latest from oasis-tcs/sarif-spec. #1668
- We are rolling out a feature in May 2023 that will disable Python dependency installation for new users of the CodeQL Action. This improves the speed of analysis while having only a very minor impact on results. #1676
- We are improving the way that CodeQL bundles are tagged to make it possible to easily identify bundles by their CodeQL semantic version. #1682
- As of CodeQL CLI 2.13.4, CodeQL bundles will be tagged using semantic versions, for example
codeql-bundle-v2.13.4, instead of timestamps, likecodeql-bundle-20230615.- This change does not affect the majority of workflows, and we will not be changing tags for existing bundle releases.
- Some workflows with custom logic that depends on the specific format of the CodeQL bundle tag may need to be updated. For example, if your workflow matches CodeQL bundle tag names against a
codeql-bundle-yyyymmddpattern, you should update it to also recognizecodeql-bundle-vx.y.ztags.- Remove the requirement for
on.pushandon.pull_requestto trigger on the same branches. #16752.3.3 - 04 May 2023
- Update default CodeQL bundle version to 2.13.1. #1664
- You can now configure CodeQL within your code scanning workflow by passing a
configinput to theinitAction. See Using a custom configuration file for more information about configuring code scanning. #15902.3.2 - 27 Apr 2023
No user facing changes.
2.3.1 - 26 Apr 2023
No user facing changes.
2.3.0 - 21 Apr 2023
- Update default CodeQL bundle version to 2.13.0. #1649
- Bump the minimum CodeQL bundle version to 2.8.5. #1618
2.2.12 - 13 Apr 2023
- Include the value of the
GITHUB_RUN_ATTEMPTenvironment variable in the telemetry sent to GitHub. #1640- Improve the ease of debugging failed runs configured using default setup. The CodeQL Action will now upload diagnostic information to Code Scanning from failed runs configured using default setup. You can view this diagnostic information on the tool status page. #1619
2.2.11 - 06 Apr 2023
No user facing changes.
2.2.10 - 05 Apr 2023
- Update default CodeQL bundle version to 2.12.6. #1629
2.2.9 - 27 Mar 2023
- Customers post-processing the SARIF output of the
analyzeAction before uploading it to Code Scanning will benefit from an improved debugging experience. #1598
... (truncated)
f0e3dfb
Merge pull request #1700
from github/update-v2.3.4-570734c550d65621
Update CHANGELOG.mdc3ae9dc
Update changelog for v2.3.4570734c
Remove unnecessary conditional for Ruby autodetect (#1699)8c923c0
Fix Swift PR Checks on nightly-latest CLI (#1696)1245696
Merge pull request #1687
from github/henrymercer/update-changelog-note317cd34
Push back semver CodeQL bundles6cfb483
Merge pull request #1682
from github/henrymercer/semver-bundlesa5f4123
Improve changelog note50931b4
Add changelog note