From 0a9b98b511420bea4ec565faa20f261ccc00247a Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Mon, 23 Feb 2026 11:59:08 +0000 Subject: [PATCH] Highlight that this for advanced setups --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 8d830a05f..7c535f8be 100644 --- a/README.md +++ b/README.md @@ -80,9 +80,9 @@ We typically release new minor versions of the CodeQL Action and Bundle when a n See the full list of GHES release and deprecation dates at [GitHub Enterprise Server releases](https://docs.github.com/en/enterprise-server/admin/all-releases#releases-of-github-enterprise-server). -## Keeping the CodeQL Action up to date +## Keeping the CodeQL Action up to date in advanced setups -We recommend referencing the CodeQL Action using a major version tag (e.g. `v4`) in your workflow file. This ensures your workflow automatically picks up the latest release within that major version, including bug fixes, new features, and updated CodeQL CLI versions. +If you are using an [advanced setup](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/configuring-advanced-setup-for-code-scanning), we recommend referencing the CodeQL Action using a major version tag (e.g. `v4`) in your workflow file. This ensures your workflow automatically picks up the latest release within that major version, including bug fixes, new features, and updated CodeQL CLI versions. If you pin to a specific commit SHA or patch version tag, ensure you keep it updated (e.g. via [Dependabot](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot)). Some CodeQL Action features are controlled by server-side flags that may be removed over time, which can cause pinned versions to lose functionality.