Skip to content

Commit

Permalink
chore(deps): bump github/codeql-action from 2.1.20 to 2.1.21 (#3345)
Browse files Browse the repository at this point in the history
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.20 to 2.1.21.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>2.1.21 - 25 Aug 2022</h2>
<ul>
<li>Improve error messages when the code scanning configuration file includes an invalid <code>queries</code> block or an invalid <code>query-filters</code> block. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1208">#1208</a></li>
<li>Fix a bug where Go build tracing could fail on Windows. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1209">#1209</a></li>
</ul>
<h2>2.1.20 - 22 Aug 2022</h2>
<p>No user facing changes.</p>
<h2>2.1.19 - 17 Aug 2022</h2>
<ul>
<li>Add the ability to filter queries from a code scanning run by using the <code>query-filters</code> option in the code scanning configuration file. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1098">#1098</a></li>
<li>In debug mode, debug artifacts are now uploaded even if a step in the Actions workflow fails. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1159">#1159</a></li>
<li>Update default CodeQL bundle version to 2.10.3. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1178">#1178</a></li>
<li>The combination of python2 and Pipenv is no longer supported. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1181">#1181</a></li>
</ul>
<h2>2.1.18 - 03 Aug 2022</h2>
<ul>
<li>Update default CodeQL bundle version to 2.10.2.  <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1156">#1156</a></li>
</ul>
<h2>2.1.17 - 28 Jul 2022</h2>
<ul>
<li>Update default CodeQL bundle version to 2.10.1.  <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1143">#1143</a></li>
</ul>
<h2>2.1.16 - 13 Jul 2022</h2>
<ul>
<li>You can now quickly debug a job that uses the CodeQL Action by re-running the job from the GitHub UI and selecting the &quot;Enable debug logging&quot; option. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1132">#1132</a></li>
<li>You can now see diagnostic messages produced by the analysis in the logs of the <code>analyze</code> Action by enabling debug mode. To enable debug mode, pass <code>debug: true</code> to the <code>init</code> Action, or <a href="https://docs.github.com/en/actions/monitoring-and-troubleshooting-workflows/enabling-debug-logging#enabling-step-debug-logging">enable step debug logging</a>. This feature is available for CodeQL CLI version 2.10.0 and later. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1133">#1133</a></li>
</ul>
<h2>2.1.15 - 28 Jun 2022</h2>
<ul>
<li>CodeQL query packs listed in the <code>packs</code> configuration field will be skipped if their target language is not being analyzed in the current Actions job. Previously, this would throw an error. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1116">#1116</a></li>
<li>The combination of python2 and poetry is no longer supported. See <a href="https://github-redirect.dependabot.com/actions/setup-python/issues/374">actions/setup-python#374</a> for more details. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1124">#1124</a></li>
<li>Update default CodeQL bundle version to 2.10.0. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1123">#1123</a></li>
</ul>
<h2>2.1.14 - 22 Jun 2022</h2>
<p>No user facing changes.</p>
<h2>2.1.13 - 21 Jun 2022</h2>
<ul>
<li>Update default CodeQL bundle version to 2.9.4. <a href="https://github-redirect.dependabot.com/github/codeql-action/pull/1100">#1100</a></li>
</ul>
<h2>2.1.12 - 01 Jun 2022</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/github/codeql-action/commit/c7f292ea4f542c473194b33813ccd4c207a6c725"><code>c7f292e</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/github/codeql-action/issues/1212">#1212</a> from github/update-v2.1.21-21bf3087</li>
<li><a href="https://github.com/github/codeql-action/commit/00ef1ee757c9f992a3a921a02844936ebc020aaa"><code>00ef1ee</code></a> Update changelog for v2.1.21</li>
<li><a href="https://github.com/github/codeql-action/commit/21bf3087a52ab2e39b8af8e483ffcc8c551784f0"><code>21bf308</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/github/codeql-action/issues/1211">#1211</a> from github/get-default-branch-correctly-schedule</li>
<li><a href="https://github.com/github/codeql-action/commit/5960bffd3f2c598375db6e39a272ed2fd53f56d1"><code>5960bff</code></a> When running on a schedule, make a better guess about whether we're analyzing...</li>
<li><a href="https://github.com/github/codeql-action/commit/92c650bfbd067a45bb475e062fe638ea25a14436"><code>92c650b</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/github/codeql-action/issues/1210">#1210</a> from github/edoardo/record-db-creation-time</li>
<li><a href="https://github.com/github/codeql-action/commit/8b45ef384583a3147a413ab8bba906544fb96d4c"><code>8b45ef3</code></a> Telemetry: Record DB creation time</li>
<li><a href="https://github.com/github/codeql-action/commit/e7d4da3fa28ce622cb1c3fc3f53e9c3c23f5f9e7"><code>e7d4da3</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/github/codeql-action/issues/1209">#1209</a> from github/henrymercer/fix-go-tracing-tests</li>
<li><a href="https://github.com/github/codeql-action/commit/182342cdd7fc5578803ce8c6c1650b273ac37850"><code>182342c</code></a> Remove unguarded Actions library query</li>
<li><a href="https://github.com/github/codeql-action/commit/e1954316773fab4ef6656d3fa0427cdc7441409f"><code>e195431</code></a> Override <code>CODEQL_EXTRACTOR_GO_BUILD_TRACING</code> with <code>on</code> when it's <code>true</code></li>
<li><a href="https://github.com/github/codeql-action/commit/3069613ebd27d7036381c2570c3403e1fbbd29b5"><code>3069613</code></a> Prevent hangs in Go autobuild tests due to .NET keychain prompts</li>
<li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/7fee4ca032ac341c12486c4c06822c5221c76533...c7f292ea4f542c473194b33813ccd4c207a6c725">compare view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=2.1.20&new-version=2.1.21)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
  • Loading branch information
dependabot[bot] committed Aug 26, 2022
1 parent c9a9916 commit d3d338d
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Expand Up @@ -16,6 +16,6 @@ jobs:

steps:
- uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # v3
- uses: github/codeql-action/init@7fee4ca032ac341c12486c4c06822c5221c76533 # v2
- uses: github/codeql-action/autobuild@7fee4ca032ac341c12486c4c06822c5221c76533 # v2
- uses: github/codeql-action/analyze@7fee4ca032ac341c12486c4c06822c5221c76533 # v2
- uses: github/codeql-action/init@c7f292ea4f542c473194b33813ccd4c207a6c725 # v2
- uses: github/codeql-action/autobuild@c7f292ea4f542c473194b33813ccd4c207a6c725 # v2
- uses: github/codeql-action/analyze@c7f292ea4f542c473194b33813ccd4c207a6c725 # v2

0 comments on commit d3d338d

Please sign in to comment.