Michael B. Gale
e46ed2cbd0
Merge pull request #3867 from github/update-v4.35.3-8c6e48dbe
...
Merge main into releases/v4
2026-05-01 15:05:28 +01:00
Michael B. Gale
b73d1d1634
Add changelog entry for #3853
2026-05-01 14:09:58 +01:00
Michael B. Gale
24e0bb00a9
Reorder changelog entries
2026-05-01 14:07:12 +01:00
github-actions[bot]
ec298daba7
Update changelog for v4.35.3
2026-05-01 12:57:50 +00:00
Henry Mercer
8c6e48dbe0
Merge pull request #3865 from github/update-bundle/codeql-bundle-v2.25.3
...
Update default bundle to 2.25.3
2026-04-30 16:07:18 +00:00
github-actions[bot]
719098349e
Add changelog note
2026-04-30 15:31:49 +00:00
github-actions[bot]
2bb209555a
Update default bundle to codeql-bundle-v2.25.3
2026-04-30 15:31:40 +00:00
Michael B. Gale
7851e55dc3
Merge pull request #3850 from github/mbg/private-registry/cloudsmith-gcp
...
Private registries: Add support for Cloudsmith and GCP OIDC configurations
2026-04-30 13:33:44 +00:00
Michael B. Gale
262a15f6cf
Add generic non-printable chars test for OIDC configs
2026-04-30 14:10:36 +01:00
Michael B. Gale
a6109b1c07
Merge pull request #3853 from github/mbg/start-proxy/improved-checks
...
Improve connection tests
2026-04-30 12:48:34 +00:00
Michael B. Gale
022ff3c73f
Merge remote-tracking branch 'origin/main' into mbg/private-registry/cloudsmith-gcp
2026-04-30 13:43:29 +01:00
Michael B. Gale
0a4d574ac4
Add changelog entry
2026-04-30 13:42:29 +01:00
Michael B. Gale
d1edf2e4de
Improve replaces-base validation and add tests
2026-04-30 13:41:13 +01:00
Henry Mercer
facd53f789
Merge pull request #3859 from github/dependabot/npm_and_yarn/ava/typescript-7.0.0
...
Bump @ava/typescript from 6.0.0 to 7.0.0
2026-04-30 12:30:35 +00:00
Michael B. Gale
b77983290b
Fix permutations comment
2026-04-30 13:28:42 +01:00
Henry Mercer
fcf29e3d86
Merge pull request #3862 from github/dependabot/github_actions/dot-github/workflows/actions-minor-933f87fbf1
...
Bump ruby/setup-ruby from 1.301.0 to 1.305.0 in /.github/workflows in the actions-minor group across 1 directory
2026-04-30 12:17:13 +00:00
Henry Mercer
1fed3e9ba8
Merge branch 'main' into dependabot/npm_and_yarn/ava/typescript-7.0.0
2026-04-30 13:10:19 +01:00
Michael B. Gale
549683cee5
Make it clearer what the expectations for isUsernamePassword are
2026-04-30 12:49:49 +01:00
Michael B. Gale
7a6ed56219
Modify FromSchema so that optional properties are actually optional
2026-04-30 11:54:21 +01:00
Michael B. Gale
91fbc51606
Improve validateSchema comment
2026-04-30 11:46:01 +01:00
Michael B. Gale
35715ef8fe
Improve typing of cloneCredential
2026-04-30 11:43:54 +01:00
Michael B. Gale
bac7fdaf42
Fix linter error
2026-04-30 11:26:12 +01:00
Henry Mercer
1517969c90
Merge pull request #3837 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2026-04-30 10:16:37 +00:00
github-actions[bot]
f073360456
Rebuild
2026-04-29 18:02:23 +00:00
dependabot[bot]
5145c112e7
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.301.0 to 1.305.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/4c56a21280b36d862b5fc31348f463d60bdc55d5...0cb964fd540e0a24c900370abf38a33466142735 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.305.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-29 18:00:14 +00:00
dependabot[bot]
7108503ac6
Bump @ava/typescript from 6.0.0 to 7.0.0
...
Bumps [@ava/typescript](https://github.com/avajs/typescript ) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/avajs/typescript/releases )
- [Commits](https://github.com/avajs/typescript/compare/v6.0.0...v7.0.0 )
---
updated-dependencies:
- dependency-name: "@ava/typescript"
dependency-version: 7.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-29 17:59:33 +00:00
Henry Mercer
4fe9b1e243
Merge pull request #3856 from github/henrymercer/overlay-add-log-group
...
Add log group for downloading overlay-base DB
2026-04-29 10:51:09 +00:00
Henry Mercer
56733fb5ae
Add log group for downloading overlay-base DB
2026-04-28 19:00:28 +01:00
Henry Mercer
0a636086c9
Add GHES 3.21 to supported versions table
2026-04-28 15:32:55 +01:00
Henry Mercer
97be3af35a
Deprecate CodeQL versions 2.19.3 and earlier
2026-04-28 15:32:55 +01:00
github-actions[bot]
de303a9db5
Update supported GitHub Enterprise Server versions
2026-04-28 15:24:46 +01:00
Michael B. Gale
7a818e6977
Log disclaimer about connection tests, with link to docs
2026-04-28 13:45:53 +01:00
Michael B. Gale
30e0f4391d
Use /v3/index.json for NuGet feed check
2026-04-28 13:45:52 +01:00
Henry Mercer
7c5585e5cf
Merge pull request #3852 from github/henrymercer/avoid-diagnostic-collisions
...
Add random suffix when writing diagnostics to avoid filename collisions
2026-04-28 12:04:59 +00:00
Henry Mercer
245f6828c4
Use a counter instead of Math.random for diagnostic filename suffix
2026-04-28 12:42:42 +01:00
Henry Mercer
c109008fac
Add changelog note
2026-04-28 11:40:03 +01:00
Henry Mercer
e73c940c9b
Defensively sanitize timestamp
2026-04-28 11:40:02 +01:00
Henry Mercer
cdb655d6d4
Add random suffix when writing diagnostics to avoid filename collisions
2026-04-28 11:39:40 +01:00
Michael B. Gale
6153577cab
Switch from HEAD to GET requests
...
Not all registry implementations support `HEAD` correctly.
2026-04-28 10:42:27 +01:00
Michael B. Gale
0ed734b61b
Ignore test files
2026-04-25 18:36:22 +01:00
Michael B. Gale
efdcb31f11
Accept replaces-base option
2026-04-25 18:36:22 +01:00
Michael B. Gale
4d2c7c6e10
Validate GCP OIDC configurations
2026-04-25 18:36:22 +01:00
Michael B. Gale
70b2658d23
Validate Cloudsmith OIDC configurations
2026-04-25 18:36:21 +01:00
Michael B. Gale
530fcb3bbf
Group OIDC schemas into an array
2026-04-25 18:36:19 +01:00
Michael B. Gale
2acf81942b
Add tests for getAuthConfig
2026-04-25 18:34:00 +01:00
Michael B. Gale
d2a54a4507
Add schemas for basic credential types
2026-04-25 18:33:01 +01:00
Michael B. Gale
bc4097bbe1
Simplify credential cloning in getAuthConfig
2026-04-25 18:23:11 +01:00
Michael B. Gale
c8e26e209a
Move getAuthConfig out of start-proxy.ts
2026-04-25 16:49:05 +01:00
Michael B. Gale
0752451507
Use schema/validation for existing OIDC config types
2026-04-25 16:49:05 +01:00
Michael B. Gale
243c274daf
Add simple JSON schema / validation helpers
2026-04-25 15:35:50 +01:00
Henry Mercer
19b3a84f58
Merge pull request #3849 from github/henrymercer/simplify-diff-range-interface
...
Simplify `writeDiffRangeDataExtensionPack` interface
2026-04-23 20:29:05 +00:00
Henry Mercer
858a6149c1
Simplify writeDiffRangeDataExtensionPack interface
2026-04-23 16:47:15 +01:00
Henry Mercer
c60c75576d
Merge pull request #3848 from github/dependabot/npm_and_yarn/fast-xml-parser-5.7.1
...
Bump fast-xml-parser from 5.5.7 to 5.7.1
2026-04-22 23:03:27 +00:00
Henry Mercer
59aede2113
Merge pull request #3847 from github/dependabot/npm_and_yarn/uuid-14.0.0
...
Bump uuid from 13.0.0 to 14.0.0
2026-04-22 23:02:16 +00:00
github-actions[bot]
6c35f8607b
Rebuild
2026-04-22 21:54:06 +00:00
github-actions[bot]
c486cacf49
Rebuild
2026-04-22 21:53:49 +00:00
dependabot[bot]
365478cc5b
Bump fast-xml-parser from 5.5.7 to 5.7.1
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.5.7 to 5.7.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.7...v5.7.1 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.7.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 21:52:05 +00:00
dependabot[bot]
f0e6490756
Bump uuid from 13.0.0 to 14.0.0
...
Bumps [uuid](https://github.com/uuidjs/uuid ) from 13.0.0 to 14.0.0.
- [Release notes](https://github.com/uuidjs/uuid/releases )
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md )
- [Commits](https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0 )
---
updated-dependencies:
- dependency-name: uuid
dependency-version: 14.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 21:51:48 +00:00
Henry Mercer
860353f245
Merge pull request #3840 from github/dependabot/npm_and_yarn/npm-minor-580efa6e3b
...
Bump the npm-minor group across 1 directory with 3 updates
2026-04-22 20:59:20 +00:00
Henry Mercer
4fb8483ef0
Merge pull request #3835 from github/dependabot/npm_and_yarn/eslint-import-resolver-typescript-4.4.4
...
Bump eslint-import-resolver-typescript from 3.8.7 to 4.4.4
2026-04-22 20:33:35 +00:00
dependabot[bot]
c2574efbee
Bump the npm-minor group across 1 directory with 3 updates
...
Bumps the npm-minor group with 3 updates in the / directory: [globals](https://github.com/sindresorhus/globals ), [sinon](https://github.com/sinonjs/sinon ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `globals` from 17.4.0 to 17.5.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.4.0...v17.5.0 )
Updates `sinon` from 21.0.3 to 21.1.2
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.3...v21.1.2 )
Updates `typescript-eslint` from 8.58.1 to 8.58.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.2/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.1.2
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.58.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 17:58:53 +00:00
Henry Mercer
4cbe7bef85
Merge pull request #3839 from github/henrymercer/workflow-run-triggers
...
Escape "+"s in `on.workflow_run.workflows`
2026-04-22 10:44:53 +00:00
Henry Mercer
f6a5638305
Escape "+"s in on.workflow_run.workflows
2026-04-22 11:14:07 +01:00
Henry Mercer
1dcdb940d5
Merge pull request #3830 from github/henrymercer/deflake
...
Add workflow to rerun potentially transient failures
2026-04-21 10:57:19 +00:00
Henry Mercer
0b7b740d4c
Merge pull request #3831 from github/dependabot/npm_and_yarn/npm-minor-f46f1f14d7
...
Bump the npm-minor group across 1 directory with 2 updates
2026-04-16 11:08:29 +00:00
Henry Mercer
0ac85966ba
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-f46f1f14d7
2026-04-16 11:49:39 +01:00
dependabot[bot]
5019ed041c
Bump eslint-import-resolver-typescript from 3.8.7 to 4.4.4
...
Bumps [eslint-import-resolver-typescript](https://github.com/import-js/eslint-import-resolver-typescript ) from 3.8.7 to 4.4.4.
- [Release notes](https://github.com/import-js/eslint-import-resolver-typescript/releases )
- [Changelog](https://github.com/import-js/eslint-import-resolver-typescript/blob/master/CHANGELOG.md )
- [Commits](https://github.com/import-js/eslint-import-resolver-typescript/compare/v3.8.7...v4.4.4 )
---
updated-dependencies:
- dependency-name: eslint-import-resolver-typescript
dependency-version: 4.4.4
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 17:58:58 +00:00
dependabot[bot]
d64d81d41f
Bump the npm-minor group across 1 directory with 2 updates
...
Bumps the npm-minor group with 2 updates in the / directory: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `@eslint/compat` from 2.0.4 to 2.0.5
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.5/packages/compat )
Updates `typescript-eslint` from 8.58.0 to 8.58.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.58.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 17:58:27 +00:00
Henry Mercer
6777c894e9
Merge pull request #3811 from github/henrymercer/record-all-builtin-languages
...
Store all built-in languages
2026-04-15 17:57:19 +00:00
Henry Mercer
79f9c0517c
Merge remote-tracking branch 'origin/main' into henrymercer/record-all-builtin-languages
...
# Conflicts:
# lib/start-proxy-action.js
# src/known-language-aliases.json
2026-04-15 18:36:47 +01:00
Henry Mercer
3b3a77544b
Rename job
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-15 18:34:13 +01:00
Henry Mercer
9f95de42d6
Add workflow to rerun potentially transient failures
2026-04-15 18:28:17 +01:00
Henry Mercer
e2d518d895
Merge pull request #3827 from github/dependabot/npm_and_yarn/follow-redirects-1.16.0
...
Bump follow-redirects from 1.15.11 to 1.16.0
2026-04-15 12:47:52 +00:00
github-actions[bot]
9df9e9176e
Rebuild
2026-04-15 12:20:46 +00:00
dependabot[bot]
6847a42aa8
Bump follow-redirects from 1.15.11 to 1.16.0
...
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects ) from 1.15.11 to 1.16.0.
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases )
- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.11...v1.16.0 )
---
updated-dependencies:
- dependency-name: follow-redirects
dependency-version: 1.16.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 12:18:36 +00:00
Henry Mercer
f820c80d4d
Merge pull request #3825 from github/mergeback/v4.35.2-to-main-95e58e9a
...
Mergeback v4.35.2 refs/heads/releases/v4 into main
2026-04-15 11:56:45 +00:00
github-actions[bot]
ca7d6d3b79
Rebuild
2026-04-15 11:27:36 +00:00
github-actions[bot]
8d9c36a0ce
Update changelog and version after v4.35.2
2026-04-15 11:24:19 +00:00
Henry Mercer
95e58e9a2c
Merge pull request #3824 from github/update-v4.35.2-d2e135a73
...
Merge main into releases/v4
2026-04-15 12:22:51 +01:00
github-actions[bot]
6f31bfe060
Update changelog for v4.35.2
2026-04-15 10:56:23 +00:00
Henry Mercer
d2e135a73a
Merge pull request #3823 from github/update-bundle/codeql-bundle-v2.25.2
...
Update default bundle to 2.25.2
2026-04-15 10:06:23 +00:00
github-actions[bot]
60abb65df0
Add changelog note
2026-04-15 09:39:31 +00:00
github-actions[bot]
5a0a562209
Update default bundle to codeql-bundle-v2.25.2
2026-04-15 09:39:24 +00:00
Henry Mercer
f8b62132ab
Include experimental languages
2026-04-14 17:38:26 +01:00
Henry Mercer
65216971a1
Merge pull request #3820 from github/dependabot/github_actions/dot-github/workflows/actions-minor-cc17fecf2b
...
Bump the actions-minor group across 1 directory with 2 updates
2026-04-13 18:04:26 +00:00
Henry Mercer
3c45af2dd2
Merge pull request #3821 from github/dependabot/npm_and_yarn/npm-minor-345b938e93
...
Bump the npm-minor group across 1 directory with 6 updates
2026-04-13 17:59:04 +00:00
github-actions[bot]
f1c339364c
Rebuild
2026-04-13 17:31:19 +00:00
github-actions[bot]
1024fc496c
Rebuild
2026-04-13 17:30:13 +00:00
dependabot[bot]
9dd4cfed96
Bump the npm-minor group across 1 directory with 6 updates
...
Bumps the npm-minor group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@octokit/plugin-retry](https://github.com/octokit/plugin-retry.js ) | `8.0.3` | `8.1.0` |
| [jsonschema](https://github.com/tdegrunt/jsonschema ) | `1.4.1` | `1.5.0` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `2.0.3` | `2.0.4` |
| [@types/sinon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sinon ) | `21.0.0` | `21.0.1` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.4` | `0.28.0` |
| [nock](https://github.com/nock/nock ) | `14.0.11` | `14.0.12` |
Updates `@octokit/plugin-retry` from 8.0.3 to 8.1.0
- [Release notes](https://github.com/octokit/plugin-retry.js/releases )
- [Commits](https://github.com/octokit/plugin-retry.js/compare/v8.0.3...v8.1.0 )
Updates `jsonschema` from 1.4.1 to 1.5.0
- [Commits](https://github.com/tdegrunt/jsonschema/commits )
Updates `@eslint/compat` from 2.0.3 to 2.0.4
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.4/packages/compat )
Updates `@types/sinon` from 21.0.0 to 21.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sinon )
Updates `esbuild` from 0.27.4 to 0.28.0
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.4...v0.28.0 )
Updates `nock` from 14.0.11 to 14.0.12
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.11...v14.0.12 )
---
updated-dependencies:
- dependency-name: "@octokit/plugin-retry"
dependency-version: 8.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: jsonschema
dependency-version: 1.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@eslint/compat"
dependency-version: 2.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@types/sinon"
dependency-version: 21.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.28.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: nock
dependency-version: 14.0.12
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-13 17:29:04 +00:00
dependabot[bot]
c1403f094c
Bump the actions-minor group across 1 directory with 2 updates
...
Bumps the actions-minor group with 2 updates in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.295.0 to 1.300.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/319994f95fa847cf3fb3cd3dbe89f6dcde9f178f...4c56a21280b36d862b5fc31348f463d60bdc55d5 )
Updates `actions/create-github-app-token` from 3.0.0 to 3.1.1
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v3.0.0...v3.1.1 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.300.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
- dependency-name: actions/create-github-app-token
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-13 17:27:57 +00:00
Henry Mercer
90d7616015
Merge branch 'main' into henrymercer/record-all-builtin-languages
2026-04-13 18:00:09 +01:00
Henry Mercer
1aef4ed505
Exclude new TypeScript code from package tests
...
Avoid new source code changing expected output
2026-04-13 17:37:29 +01:00
Henry Mercer
cb52ba6486
Refactoring: Split up script
2026-04-13 17:03:20 +01:00
Henry Mercer
7c9e131894
Add constant for builtin languages file path
2026-04-13 16:57:47 +01:00
Henry Mercer
130ab2d721
Improve JSDoc
2026-04-13 16:54:06 +01:00
Henry Mercer
8cf2dc52f9
Fix casing mismatch
2026-04-13 16:49:31 +01:00
Henry Mercer
8339b9254e
Merge pull request #3819 from github/henrymercer/refactor-overlay-caching
...
Refactoring: Introduce `overlay/caching.ts`
2026-04-13 15:49:12 +00:00
Henry Mercer
97bcdd8c1e
Move script to pr-checks directory
2026-04-13 16:49:10 +01:00
Henry Mercer
e6c21da23c
Refactoring: Rename KnownLanguage to BuiltInLanguage
2026-04-10 19:09:47 +01:00
Henry Mercer
bad0a744dd
Store all built-in languages
...
While we want the CodeQL Action to work with third-party language support, having a list of all built-in languages can help us create better type-level checks to ensure that we don't miss things that we want to customize for each of our built-in languages.
2026-04-10 19:09:46 +01:00
Michael B. Gale
ee09113642
Merge pull request #3810 from github/mbg/ts6/fix-pr-checks
...
Fix `pr-checks/tsconfig.json` for TS6
2026-04-10 18:02:01 +00:00
Michael B. Gale
b669eab7e3
Explicitly add pr-checks to Dependabot config
2026-04-10 16:58:30 +01:00
Henry Mercer
4e8c9ce33c
Refactoring: Introduce overlay/caching.ts
2026-04-10 14:55:12 +01:00
Michael B. Gale
1cf0431149
Set module option for pr-checks/tsconfig.json
2026-04-10 13:22:36 +01:00
Michael B. Gale
a26cb68cc7
Merge pull request #3807 from github/mbg/start-proxy/fix-field-names
...
Fix OIDC credential property names
2026-04-10 09:18:24 +00:00
Henry Mercer
60991e61ac
Merge pull request #3806 from github/henrymercer/store-language-aliases
...
Store language aliases from linked CLI
2026-04-10 09:16:45 +00:00
Michael B. Gale
7197c2b792
Add changelog entry
2026-04-09 19:01:45 +01:00
Henry Mercer
597e12aa85
Merge pull request #3801 from github/henrymercer/swift-incompatible-os
...
Mark Swift incompatible OS as configuration error
2026-04-09 17:30:06 +00:00
Michael B. Gale
d277a56348
Fix OIDC credential property names
2026-04-09 17:48:52 +01:00
Henry Mercer
111a537cd9
Update start-proxy Action to use known language aliases
2026-04-09 17:10:15 +01:00
Henry Mercer
51d833290e
Store language aliases from linked CLI
2026-04-09 17:10:15 +01:00
Henry Mercer
5a17511bf0
Throw error on Windows too
2026-04-09 16:52:50 +01:00
Henry Mercer
43d8420a42
Do not run Swift in debug artifacts after failure check
2026-04-09 15:18:51 +01:00
Henry Mercer
76a687e1d8
Merge pull request #3804 from github/dependabot/npm_and_yarn/npm-minor-e84c604a08
...
Bump eslint-plugin-jsdoc from 62.8.1 to 62.9.0 in the npm-minor group
2026-04-09 13:04:00 +00:00
dependabot[bot]
751f3e2f7c
Bump eslint-plugin-jsdoc from 62.8.1 to 62.9.0 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.8.1 to 62.9.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.8.1...v62.9.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.9.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-08 17:53:21 +00:00
Henry Mercer
808513f048
Update language aliases test
2026-04-08 16:38:23 +01:00
Henry Mercer
e452857e57
Throw error early rather than warning
2026-04-08 16:33:19 +01:00
Mario Campos
b623f5fd57
Merge pull request #3799 from github/mario-campos/test-multiple-registries
...
Add tests for getCredentials with multiple goproxy_servers and maven_…
2026-04-07 14:52:14 +00:00
Mario Campos
35a38985d3
Specify "Java" for a test case
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-04-07 09:01:00 -05:00
Mario Campos
14ed573199
Specify "Go" for a test case
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-04-07 09:01:00 -05:00
Mario Campos
43d8864b35
Run npm run lint-fix to format the code
2026-04-07 09:01:00 -05:00
Mario Campos
f8aff3ad8b
Add tests for getCredentials with multiple goproxy_servers and maven_repositories
2026-04-07 09:01:00 -05:00
Henry Mercer
e6c83948f5
Merge pull request #3802 from github/dependabot/npm_and_yarn/lodash-4.18.1
...
Bump lodash from 4.17.23 to 4.18.1
2026-04-07 10:12:08 +00:00
Henry Mercer
347f0c676d
Merge pull request #3803 from github/dependabot/npm_and_yarn/npm-minor-113ae615b7
...
Bump eslint-plugin-jsdoc from 62.8.0 to 62.8.1 in the npm-minor group across 1 directory
2026-04-07 10:08:35 +00:00
dependabot[bot]
6eed62b035
Bump eslint-plugin-jsdoc in the npm-minor group across 1 directory
...
Bumps the npm-minor group with 1 update in the / directory: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.8.0 to 62.8.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.8.0...v62.8.1 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.8.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-07 09:36:59 +00:00
dependabot[bot]
de1752b85d
Bump lodash from 4.17.23 to 4.18.1
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.18.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-07 09:36:15 +00:00
Henry Mercer
1065967b50
Merge pull request #3800 from github/henrymercer/typescript-6
...
Upgrade to TypeScript 6
2026-04-07 09:14:42 +00:00
Henry Mercer
e25c0a535a
Merge pull request #3795 from github/henrymercer/deprecate-trap-caching-cleanup
...
Deprecate TRAP cache cleanup
2026-04-07 09:14:31 +00:00
Henry Mercer
5f323cad05
Mark Swift incompatible OS as configuration error
2026-04-02 18:46:26 +01:00
Henry Mercer
212e28374b
Upgrade to TypeScript 6
...
tsconfig changes:
- Specify `moduleResolution: bundler` since we use a bundler
- Specify `types: ["node"]` to speed up build
- Remove `alwaysStrict` as this is now deprecated
- Specify `skipLibCheck: true` to speed up build
- Specify Octokit types.d.ts path manually to address compiler not being able to find types with `moduleResolution: bundler`
2026-04-02 18:32:58 +01:00
Henry Mercer
36075a4980
Deprecate TRAP cache cleanup
2026-04-01 15:31:15 +01:00
Michael B. Gale
34950e1b11
Merge pull request #3792 from github/mario-campos/issue-1664
...
Extend start-proxy.yml to test multiple registry support
2026-04-01 13:59:59 +00:00
Henry Mercer
57ec7e1000
Merge pull request #3794 from github/henrymercer/cleanup
...
Python: Disable standard library extraction on GHES
2026-04-01 11:37:34 +00:00
Henry Mercer
311573e58e
Add changelog note
2026-04-01 12:19:11 +01:00
Henry Mercer
1f4c852aeb
Clean up Python extract stdlib feature flag
2026-04-01 12:08:06 +01:00
Michael B. Gale
2e3aaaefca
Merge pull request #3787 from github/mbg/bundle/metadata
...
Generate and analyse esbuild bundle metadata
2026-04-01 10:29:27 +00:00
Mario Campos
e2203c62cf
Delete fromJSON() calls in test validation step
2026-03-31 13:19:33 -05:00
Mario Campos
7b0c5b1669
Keep validation steps named consistently
2026-03-31 12:49:07 -05:00
Mario Campos
faf45e07f9
Use different maven URL for start-proxy.yml test
2026-03-31 12:44:43 -05:00
Mario Campos
8b5e60477c
Use maven_repository, not maven-repository
...
The registry/language mapping table does not map the one with hyphens.
2026-03-31 11:36:17 -05:00
Mario Campos
99b8dd4d57
Run pr-checks/sync.sh to generate __start-proxy.yml.
2026-03-31 09:32:42 -05:00
Henry Mercer
c618c9bddb
Merge pull request #3789 from github/henrymercer/lower-minimum-git-if-no-submodules
...
Overlay: Only require Git 2.36.0 for repos that contain submodules
2026-03-31 10:10:05 +00:00
Mario Campos
9fd9b64766
Replace jq with Actions expression for proxy_urls validation
...
For the sake of consistency with the other pre-existing validation code.
2026-03-30 22:47:06 -05:00
Mario Campos
0c7c298b2a
Extend start-proxy.yml to test multiple registry support
2026-03-30 18:35:04 -05:00
Henry Mercer
a507a542a4
Test fallback when repo has no submodules
2026-03-30 15:58:58 +01:00
Henry Mercer
be0a156326
Save a computation of the git root
2026-03-30 13:37:14 +01:00
Michael B. Gale
f98bf5e347
Output relative to __dirname
2026-03-27 19:21:14 +00:00
Michael B. Gale
3db32b5d27
Fix outputs type
2026-03-27 19:13:22 +00:00
Michael B. Gale
4e0952a3c0
Output largest inputs
2026-03-27 19:13:02 +00:00
Henry Mercer
0592832ed8
Add changelog note
2026-03-27 18:58:05 +00:00
Henry Mercer
88a7e5118e
Don't disable if we don't need the git version
2026-03-27 18:54:26 +00:00
Henry Mercer
6643a7d207
Only require Git 2.36.0 when repo contains submodules
2026-03-27 18:54:24 +00:00
Michael B. Gale
47f1709a3c
Add basic metadata analysis script
2026-03-27 18:19:57 +00:00
Michael B. Gale
b1981a5480
Move getApiClient out of sync-checks.ts
2026-03-27 18:13:48 +00:00
Henry Mercer
a899987af2
Merge pull request #3786 from github/henrymercer/faster-interactive-jobs
...
Move time-sensitive Actions workflows to `ubuntu-latest`
2026-03-27 18:08:16 +00:00
Michael B. Gale
4ed3c0efe6
Generate esbuild metadata file
2026-03-27 17:54:29 +00:00
Henry Mercer
191d7c6f13
Merge pull request #3783 from github/mergeback/v4.35.1-to-main-c10b8064
...
Mergeback v4.35.1 refs/heads/releases/v4 into main
2026-03-27 17:11:42 +00:00
Henry Mercer
aa69c483cd
Merge pull request #3779 from github/henrymercer/remove-unused-dependency
...
Remove unused `@schemastore/package` dependency
2026-03-27 17:11:32 +00:00
Henry Mercer
fe775da508
Merge pull request #3780 from github/dependabot/npm_and_yarn/brace-expansion-1.1.13
...
Bump brace-expansion from 1.1.12 to 1.1.13
2026-03-27 17:11:18 +00:00
Henry Mercer
353802f9f2
Move time-sensitive Actions workflows to ubuntu-latest
...
We originally moved these to `ubuntu-slim`, but there is a significant performance difference. Since we often find ourselves waiting on these jobs, let's use the faster runners.
2026-03-27 16:22:19 +00:00
github-actions[bot]
cc7db4a1f9
Rebuild
2026-03-27 16:20:01 +00:00
github-actions[bot]
6010f9d8e2
Update changelog and version after v4.35.1
2026-03-27 16:10:47 +00:00
Henry Mercer
c10b8064de
Merge pull request #3782 from github/update-v4.35.1-d6d1743b8
...
Merge main into releases/v4
2026-03-27 16:07:37 +00:00
github-actions[bot]
c5ffd06837
Update changelog for v4.35.1
2026-03-27 15:39:16 +00:00
Henry Mercer
d6d1743b8e
Merge pull request #3781 from github/henrymercer/update-git-minimum-version
...
Update minimum Git version for overlay to 2.36.0
2026-03-27 14:59:36 +00:00
github-actions[bot]
999119ba45
Rebuild
2026-03-27 14:00:54 +00:00
Henry Mercer
65d2efa733
Add changelog note
2026-03-27 14:00:27 +00:00
Henry Mercer
2437b20ab3
Update minimum git version for overlay to 2.36.0
2026-03-27 14:00:17 +00:00
dependabot[bot]
f13c600724
Bump brace-expansion from 1.1.12 to 1.1.13
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 1.1.12 to 1.1.13.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.13 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.13
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 13:58:43 +00:00
Henry Mercer
7dcea06663
Remove unused @schemastore/package dependency
2026-03-27 13:57:52 +00:00
Michael B. Gale
ea5f71947c
Merge pull request #3775 from github/dependabot/npm_and_yarn/node-forge-1.4.0
...
Bump node-forge from 1.3.3 to 1.4.0
2026-03-27 13:47:55 +00:00
Henry Mercer
45ceeea896
Merge pull request #3777 from github/mergeback/v4.35.0-to-main-b8bb9f28
...
Mergeback v4.35.0 refs/heads/releases/v4 into main
2026-03-27 13:36:14 +00:00
github-actions[bot]
24448c9843
Rebuild
2026-03-27 12:23:25 +00:00
github-actions[bot]
7c51060631
Update changelog and version after v4.35.0
2026-03-27 12:14:07 +00:00
Óscar San José
b8bb9f28b8
Merge pull request #3776 from github/update-v4.35.0-0078ad667
...
Merge main into releases/v4
2026-03-27 13:11:18 +01:00
github-actions[bot]
e9cf68bb33
Update changelog for v4.35.0
2026-03-27 11:44:34 +00:00
github-actions[bot]
36791d8d66
Rebuild
2026-03-27 10:27:12 +00:00
dependabot[bot]
22eba96a28
Bump node-forge from 1.3.3 to 1.4.0
...
Bumps [node-forge](https://github.com/digitalbazaar/forge ) from 1.3.3 to 1.4.0.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.3...v1.4.0 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.4.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 10:25:06 +00:00
Óscar San José
0078ad667e
Merge pull request #3773 from github/update-bundle/codeql-bundle-v2.25.1
...
Update default bundle to 2.25.1
2026-03-27 10:02:52 +00:00
github-actions[bot]
fa7a15b909
Add changelog note
2026-03-27 09:43:23 +00:00
github-actions[bot]
8c29faa7ab
Update default bundle to codeql-bundle-v2.25.1
2026-03-27 09:43:12 +00:00
Henry Mercer
f94817b9f0
Merge pull request #3772 from github/dependabot/npm_and_yarn/yaml-2.8.3
...
Bump yaml from 2.8.2 to 2.8.3
2026-03-26 19:43:58 +00:00
dependabot[bot]
dd060970a5
Bump yaml from 2.8.2 to 2.8.3
...
Bumps [yaml](https://github.com/eemeli/yaml ) from 2.8.2 to 2.8.3.
- [Release notes](https://github.com/eemeli/yaml/releases )
- [Commits](https://github.com/eemeli/yaml/compare/v2.8.2...v2.8.3 )
---
updated-dependencies:
- dependency-name: yaml
dependency-version: 2.8.3
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-26 18:26:45 +00:00
Michael B. Gale
5cc552f43e
Merge pull request #3768 from github/dependabot/npm_and_yarn/npm-minor-3536e7c6f0
...
Bump the npm-minor group with 5 updates
2026-03-26 17:46:04 +00:00
Michael B. Gale
6b1a9f2131
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-3536e7c6f0
2026-03-26 16:36:54 +00:00
Michael B. Gale
9d3ec5727a
Merge pull request #3770 from github/dependabot/github_actions/dot-github/workflows/actions-minor-266139ee1d
...
Bump ruby/setup-ruby from 1.288.0 to 1.295.0 in /.github/workflows in the actions-minor group across 1 directory
2026-03-26 16:32:19 +00:00
Michael B. Gale
3ff82aacd0
Merge pull request #3575 from github/mbg/ts/sync-checks
...
Convert `release-branches.py` and `update-required-checks.sh` to TypeScript
2026-03-26 15:47:43 +00:00
Sam Robson
4bdd4e7526
Merge pull request #3554 from github/sam-robson/overlay-include-diff
...
feat: always include files from diff in overlay changed files
2026-03-26 10:57:24 +00:00
Sam Robson
23a0098b57
fix: improve error handling and logging for diff range path resolution
2026-03-25 19:53:21 +00:00
github-actions[bot]
ea7b090925
Rebuild
2026-03-25 18:01:40 +00:00
dependabot[bot]
a663d0174a
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.288.0 to 1.295.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/09a7688d3b55cf0e976497ff046b70949eeaccfd...319994f95fa847cf3fb3cd3dbe89f6dcde9f178f )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.295.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-25 17:59:44 +00:00
dependabot[bot]
b659882aae
Bump the npm-minor group with 5 updates
...
Bumps the npm-minor group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.3` | `0.27.4` |
| [eslint-plugin-import-x](https://github.com/un-ts/eslint-plugin-import-x ) | `4.16.1` | `4.16.2` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.7.1` | `62.8.0` |
| [sinon](https://github.com/sinonjs/sinon ) | `21.0.2` | `21.0.3` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ) | `8.57.0` | `8.57.1` |
Updates `esbuild` from 0.27.3 to 0.27.4
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.3...v0.27.4 )
Updates `eslint-plugin-import-x` from 4.16.1 to 4.16.2
- [Release notes](https://github.com/un-ts/eslint-plugin-import-x/releases )
- [Changelog](https://github.com/un-ts/eslint-plugin-import-x/blob/master/CHANGELOG.md )
- [Commits](https://github.com/un-ts/eslint-plugin-import-x/compare/v4.16.1...v4.16.2 )
Updates `eslint-plugin-jsdoc` from 62.7.1 to 62.8.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.7.1...v62.8.0 )
Updates `sinon` from 21.0.2 to 21.0.3
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.2...v21.0.3 )
Updates `typescript-eslint` from 8.57.0 to 8.57.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: esbuild
dependency-version: 0.27.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-import-x
dependency-version: 4.16.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.8.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.57.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-25 17:53:49 +00:00
Sam Robson
d5bb39fa0b
refactor: single source of truth for getDiffRangesJsonFilePath and simplified getDiffRangeFilePaths
2026-03-25 15:51:51 +00:00
Sam Robson
521c3536d3
feat: always include files from diff in overlay changed files
2026-03-25 15:51:51 +00:00
Michael B. Gale
972365e142
Fix comment
2026-03-25 14:15:39 +00:00
Michael B. Gale
8a0b4f2746
fixup! Update CONTRIBUTING.md
2026-03-25 14:14:49 +00:00
Michael B. Gale
a5418e172c
Delete releases.ini
2026-03-25 13:49:47 +00:00
Michael B. Gale
fae4c28b51
Update CONTRIBUTING.md
2026-03-25 13:48:55 +00:00
Michael B. Gale
661a8fbbe3
Default ref to main
2026-03-25 13:40:05 +00:00
Michael B. Gale
e7c7b68c5f
Remove update-required-checks.sh
2026-03-25 13:38:28 +00:00
Michael B. Gale
fa568ebc69
Delete release-branches.py
2026-03-25 13:37:41 +00:00
Michael B. Gale
0da3139813
Rename to branchName
2026-03-25 13:35:02 +00:00
Michael B. Gale
0abe92ed20
Configure ESLint import/no-extraneous-dependencies rule for pr-checks
2026-03-25 13:17:37 +00:00
Michael B. Gale
07f235e5f2
Add --verbose option
2026-03-25 13:17:37 +00:00
Michael B. Gale
9fd40ff508
Tidy up pr-checks/package.json
2026-03-25 13:17:37 +00:00
Michael B. Gale
75ed461aaa
Add excluded.yml path to config.ts
2026-03-25 13:16:35 +00:00
Michael B. Gale
cfc18781e0
Rebuild
2026-03-25 13:16:34 +00:00
Michael B. Gale
9fe42f69b7
Add some unit tests for sync-checks.ts
2026-03-25 13:16:33 +00:00
Michael B. Gale
c5a984e1aa
Update CONTRIBUTING.md
2026-03-25 13:16:33 +00:00
Michael B. Gale
0543156694
Actually perform the update when necessary and requested
2026-03-25 13:16:33 +00:00
Michael B. Gale
4cec5d2830
Call updateBranch for main
2026-03-25 13:16:32 +00:00
Michael B. Gale
74dd691a45
Identify changes before applying them
2026-03-25 13:16:32 +00:00
Michael B. Gale
a5244bf7dd
Fetch release branches and identify major versions
2026-03-25 13:16:32 +00:00
Michael B. Gale
1bc611ed0c
Fetch and filter check runs for ref
2026-03-25 13:16:32 +00:00
Michael B. Gale
d2008eee7c
Add type to represent exclusions.yml and loading helper
2026-03-25 13:16:32 +00:00
Michael B. Gale
9481177f3d
Initialise API client
2026-03-25 13:16:31 +00:00
Michael B. Gale
9813849e61
Add initial TS implementation of update-required-checks.sh
2026-03-25 13:16:31 +00:00
Michael B. Gale
4867f5927a
Add config file for excluded checks from update-required-checks.sh
2026-03-25 13:16:31 +00:00
Michael B. Gale
49af37b7ab
Add tests for release-branches.ts
2026-03-25 13:16:31 +00:00
Michael B. Gale
b72f4fec40
Validate inputs
2026-03-25 13:16:30 +00:00
Michael B. Gale
0d87a75829
Refactor backport computation into computeReleaseBranches
2026-03-25 13:16:30 +00:00
Michael B. Gale
3db9a05c73
Replace release-branches.py with TS version in release-branches action
2026-03-25 13:16:30 +00:00
Michael B. Gale
aa2773169b
Install node in release-initialise action
2026-03-25 13:16:30 +00:00
Michael B. Gale
054745baee
Convert release-branches.py to TypeScript
2026-03-25 13:16:30 +00:00
Michael B. Gale
3d564d9359
Merge pull request #3579 from github/mbg/start-proxy/token-check-fixes
...
Fix warning for PAT-like token with username
2026-03-25 13:02:47 +00:00
Michael B. Gale
137e0dec2b
Merge remote-tracking branch 'origin/main' into mbg/start-proxy/token-check-fixes
2026-03-25 12:39:48 +00:00
Michael B. Gale
d128e5daa8
Fix test names
2026-03-25 12:39:42 +00:00
Henry Mercer
eedab83377
Merge pull request #3767 from github/henrymercer/overlay-reduce-minimum-git-version
...
Reduce the minimum Git version required for overlay
2026-03-24 11:26:07 +00:00
Henry Mercer
8c023a6b07
Add changelog note
2026-03-23 18:40:55 +00:00
Henry Mercer
28f56f2bed
Update minimum Git version required for overlay
2026-03-23 18:36:25 +00:00
Henry Mercer
d48d054533
Use --stage instead of --format in git ls-files
2026-03-23 18:33:59 +00:00
Henry Mercer
72c0b0efb7
Merge pull request #3587 from github/dependabot/npm_and_yarn/fast-xml-parser-5.5.7
...
Bump fast-xml-parser from 5.5.6 to 5.5.7
2026-03-23 14:22:53 +00:00
Henry Mercer
05b1a5d28f
Merge pull request #3764 from github/mergeback/v4.34.1-to-main-38697555
...
Mergeback v4.34.1 refs/heads/releases/v4 into main
2026-03-20 18:38:55 +00:00
github-actions[bot]
8dc2e5d9d2
Rebuild
2026-03-20 18:19:40 +00:00
github-actions[bot]
8fd6c0e573
Update changelog and version after v4.34.1
2026-03-20 18:14:55 +00:00
Henry Mercer
3869755554
Merge pull request #3763 from github/update-v4.34.1-095e0fe50
...
Merge main into releases/v4
2026-03-20 18:10:50 +00:00
github-actions[bot]
20e68ac12b
Update changelog for v4.34.1
2026-03-20 17:33:39 +00:00
Henry Mercer
095e0fe505
Merge pull request #3762 from github/henrymercer/downgrade-default-bundle
...
Downgrade default bundle to 2.24.3
2026-03-20 17:06:34 +00:00
Henry Mercer
47b94fe61c
Add changelog note
2026-03-20 16:46:45 +00:00
Henry Mercer
51a1d6917f
Downgrade default bundle to codeql-bundle-v2.24.3
2026-03-20 16:45:20 +00:00
Óscar San José
510cf736e3
Merge pull request #3589 from github/mergeback/v4.34.0-to-main-c6f93110
...
Mergeback v4.34.0 refs/heads/releases/v4 into main
2026-03-20 15:15:34 +00:00
github-actions[bot]
89f0c86efa
Rebuild
2026-03-20 12:03:59 +00:00
github-actions[bot]
c3f90ba975
Update changelog and version after v4.34.0
2026-03-20 11:56:24 +00:00
Óscar San José
c6f931105c
Merge pull request #3588 from github/update-v4.34.0-30c555a52
...
Merge main into releases/v4
2026-03-20 12:53:53 +01:00
github-actions[bot]
eeb9b3f424
Update changelog for v4.34.0
2026-03-20 10:35:57 +00:00
github-actions[bot]
64507ed148
Rebuild
2026-03-20 01:40:06 +00:00
dependabot[bot]
1a45a9b9d0
Bump fast-xml-parser from 5.5.6 to 5.5.7
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.5.6 to 5.5.7.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.6...v5.5.7 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.5.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 01:38:13 +00:00
Idriss Riouak
30c555a528
Merge pull request #3584 from github/idrissrio/cpp/overlay
...
Feature flag: C/C++ overlay
2026-03-19 15:26:48 +00:00
Idriss Riouak
39191bd27f
Merge branch 'main' into idrissrio/cpp/overlay
2026-03-19 15:42:47 +01:00
Óscar San José
147e93e5dc
Merge pull request #3585 from github/update-bundle/codeql-bundle-v2.25.0
...
Update default bundle to 2.25.0
2026-03-19 14:14:03 +00:00
Idriss Riouak
e6d83bce6d
Update CHANGELOG.md
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2026-03-19 14:58:16 +01:00
idrissrio
0d057ccbce
Add changelog note for C/C++ overlay
2026-03-19 14:11:02 +01:00
idrissrio
074a0dbd16
Feature flag: update test without overlay support
2026-03-19 14:11:02 +01:00
idrissrio
ab3b6fd199
Feature flag: address copilot comment
...
Wire C/C++ overlay feature flags into overlay mapping
2026-03-19 14:11:00 +01:00
idrissrio
ce4a1feb6a
Feature flag: update generated lib after build
2026-03-19 14:10:57 +01:00
idrissrio
899a672743
Feature flag: C/C++ overlay
2026-03-19 14:10:56 +01:00
github-actions[bot]
f4be604881
Add changelog note
2026-03-19 12:01:31 +00:00
github-actions[bot]
0bc1b6f632
Update default bundle to codeql-bundle-v2.25.0
2026-03-19 12:01:20 +00:00
Henry Mercer
3d8036cf7f
Merge pull request #3583 from github/dependabot/github_actions/dot-github/workflows/actions/create-github-app-token-3.0.0
...
Bump actions/create-github-app-token from 2.2.1 to 3.0.0 in /.github/workflows
2026-03-19 10:37:38 +00:00
Henry Mercer
9fecf32c77
Merge pull request #3581 from github/dependabot/npm_and_yarn/npm-minor-a87b0427cc
...
Bump the npm-minor group with 2 updates
2026-03-19 10:34:28 +00:00
Henry Mercer
07d509fbaf
Merge pull request #3569 from github/henrymercer/overlay-no-trap-caching
...
Disable TRAP caching when overlay is enabled
2026-03-19 10:12:30 +00:00
dependabot[bot]
23674c1f2a
Bump actions/create-github-app-token in /.github/workflows
...
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token ) from 2.2.1 to 3.0.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.2.1...v3.0.0 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 18:10:06 +00:00
dependabot[bot]
ecd1c77ffa
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `@eslint/compat` from 2.0.2 to 2.0.3
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.3/packages/compat )
Updates `typescript-eslint` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 17:53:32 +00:00
Henry Mercer
5b630489d6
Fix changelog automerge
2026-03-18 17:10:57 +00:00
Henry Mercer
582d08c553
Explicitly set C/C++ trap caching env var to false
2026-03-18 17:10:13 +00:00
Henry Mercer
60a0dce0ad
Merge branch 'main' into henrymercer/overlay-no-trap-caching
...
# Conflicts:
# lib/start-proxy-action.js
2026-03-18 16:35:51 +00:00
Henry Mercer
7da6361ba5
Merge pull request #3580 from github/dependabot/npm_and_yarn/fast-xml-parser-5.5.6
...
Bump fast-xml-parser from 5.4.1 to 5.5.6
2026-03-18 11:50:18 +00:00
Sam Robson
08d1198b01
Merge pull request #3248 from github/kaspersv/move-diff-range-absolute-path-conversion
...
Move conversion of PR diff-range paths to absolute paths
2026-03-18 11:41:58 +00:00
Sam Robson
5e54629286
Merge branch 'main' into kaspersv/move-diff-range-absolute-path-conversion
...
* main: (112 commits)
Rebuild
Update changelog and version after v4.33.0
Add changelog entry for #3570
Bump minor version
Update changelog for v4.32.7
Only emit one message with accumulated property names
Remove `cache-dependency-path` options as well
Remove `package-lock.json` that's no longer needed
Add step (in root directory) to install dependencies
Add explicit cache dependency paths in `pr-checks.yml`
Fix linter errors in `sync-back.test.ts`
Fix linter errors in `sync-back.ts`
Rename `sync_back` to `sync-back`
Fix linter errors in `sync.ts`
Add eslint configuration for `pr-checks`
Add minimal `Step` type
Add `workspaces` to root `package.json`
Avoid bundling `package.json`
Move `ava` config out of `package.json`
Emit warning for unrecognised repo properties with our common prefix
...
# Conflicts:
# lib/init-action-post.js
2026-03-18 10:47:46 +00:00
github-actions[bot]
f254006ed7
Rebuild
2026-03-18 01:38:11 +00:00
dependabot[bot]
573e7dd341
Bump fast-xml-parser from 5.4.1 to 5.5.6
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.4.1 to 5.5.6.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.1...v5.5.6 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.5.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 01:36:15 +00:00
Michael B. Gale
f88d49ee5d
Fix warning for PAT-like token with username
2026-03-16 19:34:33 +00:00
Michael B. Gale
28f515d9ad
Add tests for the absence of the warning
2026-03-16 19:34:33 +00:00
Michael B. Gale
de06821112
Add hasMessage to RecordingLogger
2026-03-16 19:34:33 +00:00
Michael B. Gale
ddafddb826
Replace getRecordingLogger implementation with RecordingLogger
2026-03-16 19:34:32 +00:00
Michael B. Gale
740f177889
Add assertNotLogged test helper
2026-03-16 19:34:32 +00:00
Michael B. Gale
0393130759
Add "token without a username" test
2026-03-16 19:34:32 +00:00
Michael B. Gale
f86097dfdb
Add params for credentials and checkAccepted to testPATWarning
2026-03-16 19:34:32 +00:00
Michael B. Gale
6e67ef61f2
Refactor PAT test into a test.macro
2026-03-16 19:34:32 +00:00
Michael B. Gale
193dd19c2d
Add snippet to scaffold test.macros
2026-03-16 19:34:32 +00:00
Michael B. Gale
fd1ca02d0d
Merge pull request #3576 from github/mergeback/v4.33.0-to-main-b1bff819
...
Mergeback v4.33.0 refs/heads/releases/v4 into main
2026-03-16 12:22:52 +00:00
github-actions[bot]
a0e3ed6555
Rebuild
2026-03-16 09:08:32 +00:00
github-actions[bot]
fbb2eb9556
Update changelog and version after v4.33.0
2026-03-16 09:03:58 +00:00
Michael B. Gale
b1bff81932
Merge pull request #3574 from github/update-v4.32.7-7dd76e6bf
...
Merge main into releases/v4
2026-03-16 09:01:14 +00:00
Michael B. Gale
e682234222
Add changelog entry for #3570
2026-03-16 08:43:35 +00:00
Michael B. Gale
95be291f41
Bump minor version
2026-03-16 08:38:13 +00:00
github-actions[bot]
59bcb6025e
Update changelog for v4.32.7
2026-03-16 08:20:09 +00:00
Michael B. Gale
7dd76e6bf7
Merge pull request #3572 from github/mbg/pr-checks/eslint
...
Add eslint for `pr-checks`
2026-03-13 18:51:29 +00:00
Michael B. Gale
e3200e331b
Merge pull request #3563 from github/mbg/private-registry/oidc
...
Accept OIDC configurations in `start-proxy`
2026-03-13 11:58:36 +00:00
Michael B. Gale
4c356c71a2
Merge pull request #3570 from github/mbg/repo-props/warn-on-unexpected-props
...
Emit warning for unrecognised repo properties with our common prefix
2026-03-13 11:13:21 +00:00
Michael B. Gale
b4937c19e5
Only emit one message with accumulated property names
2026-03-13 10:56:36 +00:00
Michael B. Gale
136b8ab377
Remove cache-dependency-path options as well
2026-03-13 10:46:40 +00:00
Michael B. Gale
a5aba5952c
Remove package-lock.json that's no longer needed
...
Since `pr-checks` is now a workspace of the main `package.json`
2026-03-13 10:43:43 +00:00
Michael B. Gale
dafe74070a
Merge pull request #3573 from github/mbg/esbuild/no-package-json
...
Avoid bundling `package.json` in JavaScript files
2026-03-13 10:38:58 +00:00
Michael B. Gale
fc8d303906
Add step (in root directory) to install dependencies
2026-03-12 22:39:45 +00:00
Michael B. Gale
3bc3228be2
Add explicit cache dependency paths in pr-checks.yml
2026-03-12 22:39:45 +00:00
Michael B. Gale
b4cb1049fb
Fix linter errors in sync-back.test.ts
2026-03-12 22:39:45 +00:00
Michael B. Gale
b171c1c6d9
Fix linter errors in sync-back.ts
2026-03-12 22:39:44 +00:00
Michael B. Gale
967ca853e1
Rename sync_back to sync-back
2026-03-12 22:39:44 +00:00
Michael B. Gale
7950e47b7f
Fix linter errors in sync.ts
2026-03-12 22:39:44 +00:00
Michael B. Gale
e608db4784
Add eslint configuration for pr-checks
2026-03-12 22:39:44 +00:00
Michael B. Gale
7df3db2b6f
Add minimal Step type
2026-03-12 22:39:44 +00:00
Michael B. Gale
b5e1fb009d
Add workspaces to root package.json
2026-03-12 22:39:44 +00:00
Michael B. Gale
ea703668e0
Avoid bundling package.json
...
- `package.json` is bundled by `esbuild` because we depend on it in `actions-util.ts`
- That is so we can access the `version` property
- We now use `build.mjs` to define a constant for it instead
- We also set this constant in `ava.setup.mjs` for tests
- This reduces the size of the generated `.js` files and avoids changing them entirely in some cases
2026-03-12 18:55:03 +00:00
Michael B. Gale
c183dca871
Move ava config out of package.json
2026-03-12 18:43:14 +00:00
Michael B. Gale
a717db1a90
Emit warning for unrecognised repo properties with our common prefix
2026-03-12 11:49:17 +00:00
Henry Mercer
1dbebad653
Merge pull request #3566 from github/dependabot/npm_and_yarn/npm-minor-aebc49e072
...
Bump the npm-minor group with 2 updates
2026-03-11 20:49:27 +00:00
Henry Mercer
82d7a77abc
Merge pull request #3567 from github/dependabot/npm_and_yarn/ava-7.0.0
...
Bump ava from 6.4.1 to 7.0.0
2026-03-11 20:47:14 +00:00
Henry Mercer
926e6dfee5
Stub RUNNER_NAME in unit tests
2026-03-11 20:16:47 +00:00
Henry Mercer
b1f1e7bd31
Add changelog note
2026-03-11 19:56:42 +00:00
Henry Mercer
a91b7a3e57
Add unit tests for isTrapCachingEnabled
2026-03-11 19:52:12 +00:00
github-actions[bot]
0d0df94d93
Rebuild
2026-03-11 19:51:54 +00:00
github-actions[bot]
373dec9f22
Rebuild
2026-03-11 19:51:53 +00:00
Henry Mercer
9771a765ac
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-aebc49e072
2026-03-11 19:49:56 +00:00
Henry Mercer
363219d88d
Merge branch 'main' into dependabot/npm_and_yarn/ava-7.0.0
2026-03-11 19:49:53 +00:00
Henry Mercer
556dd79c4b
Drive-by comment fixes
2026-03-11 19:33:57 +00:00
Henry Mercer
19544bb9b4
Remove dead Python library extraction code
2026-03-11 19:32:36 +00:00
Henry Mercer
d74701caa1
Drive-by cleanup: Always use --cache-cleanup
2026-03-11 19:31:03 +00:00
Henry Mercer
d05b50b13f
Clean up: Remove unneeded CodeQL version guard
2026-03-11 19:30:13 +00:00
Henry Mercer
70d5cccce1
Disable TRAP caching when conditions met
2026-03-11 19:25:29 +00:00
Henry Mercer
b04e63ffdf
Enablement: Move TRAP caching check after overlay
2026-03-11 19:21:17 +00:00
Henry Mercer
378e4b367d
Merge pull request #3568 from github/henrymercer/fix-rebuild
...
Fix rebuild Action
2026-03-11 19:18:28 +00:00
Henry Mercer
309fd2aac7
Merge pull request #3565 from github/henrymercer/go-macos-checks
...
PR checks: Only run Go macOS tests on latest CodeQL versions
2026-03-11 19:11:16 +00:00
Henry Mercer
b0f877255d
Add FF for disabling TRAP caching when overlay enabled
2026-03-11 18:44:41 +00:00
Henry Mercer
567ca73ff8
Address review comments
2026-03-11 18:40:22 +00:00
Henry Mercer
5f3f250f83
Fix finishing up in progress merge
2026-03-11 18:24:00 +00:00
Henry Mercer
6fb1c2a300
Fix merge in progress detection
2026-03-11 18:23:04 +00:00
Henry Mercer
44720043ea
CI: Set up Node.js 24 in rebuild workflow
2026-03-11 18:18:30 +00:00
dependabot[bot]
f9f5edb76f
Bump ava from 6.4.1 to 7.0.0
...
Bumps [ava](https://github.com/avajs/ava ) from 6.4.1 to 7.0.0.
- [Release notes](https://github.com/avajs/ava/releases )
- [Commits](https://github.com/avajs/ava/compare/v6.4.1...v7.0.0 )
---
updated-dependencies:
- dependency-name: ava
dependency-version: 7.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-11 17:53:48 +00:00
dependabot[bot]
de2997a8c8
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [globals](https://github.com/sindresorhus/globals ) and [sinon](https://github.com/sinonjs/sinon ).
Updates `globals` from 17.3.0 to 17.4.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.3.0...v17.4.0 )
Updates `sinon` from 21.0.1 to 21.0.2
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.1...v21.0.2 )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-11 17:53:18 +00:00
Henry Mercer
117bf916af
Sort OS list and versions consistently
2026-03-11 17:11:07 +00:00
Henry Mercer
30ecc82e64
PR checks: Replace inline arrays
...
Lists are easier to modify
2026-03-11 17:11:07 +00:00
Henry Mercer
4174779474
PR checks: Only run Go macOS tests on latest CodeQL versions
2026-03-11 17:10:56 +00:00
Henry Mercer
2bc06587aa
PR checks: Add support for per-OS CodeQL version
2026-03-11 17:10:45 +00:00
Michael B. Gale
6c99ca514e
Merge remote-tracking branch 'origin/main' into mbg/private-registry/oidc
2026-03-11 16:15:07 +00:00
Michael B. Gale
1a97b0f94e
Merge pull request #3541 from github/mbg/pr-checks/validation-jobs
...
Add support for validation jobs to `sync.ts`, and refactor
2026-03-11 14:43:46 +00:00
Michael B. Gale
d1a7580bd3
Verify PR checks in a different job, with newer Node
2026-03-11 12:29:36 +00:00
Michael B. Gale
89f63211ed
Use version in error message
2026-03-11 12:18:41 +00:00
Michael B. Gale
6570ad3440
Extend base tsconfig.json
2026-03-11 12:16:28 +00:00
Michael B. Gale
be7fe2bca6
Make it more explicit by construction that known inputs always have the same specifications
2026-03-11 12:14:41 +00:00
Michael B. Gale
2e1f08fe70
Remove installPython condition in sync.ts
...
The behaviour of `installPython` now mirrors other `install*` options
2026-03-11 11:55:59 +00:00
Michael B. Gale
b9b42bed94
Remove last use of installPython
...
- Add explicit `setup-python` step with condition to the workflow that was still using it
- This allows simplifying the logic in `sync.ts`
2026-03-11 11:55:16 +00:00
Henry Mercer
997acaf7eb
Merge pull request #3562 from github/henrymercer/skip-file-coverage-rollout
...
Prepare for rolling out skipping computing file coverage information on PRs
2026-03-11 11:33:21 +00:00
Henry Mercer
2e7e91fd63
Merge pull request #3550 from github/sam-robson/overlay-per-lang-min-bundle-version
...
feat: add minimumVersion values for language overlay flags
2026-03-11 10:28:14 +00:00
Henry Mercer
5cb13d6ab8
Merge pull request #3564 from github/henrymercer/fix-database-upload-retries
...
Fix retries when uploading databases
2026-03-10 16:56:27 +00:00
Henry Mercer
a63886bff5
Refactor: Extract separate function for uploadBundledDatabase
2026-03-10 16:36:02 +00:00
Henry Mercer
a11c6cbbc8
Merge branch 'main' into henrymercer/skip-file-coverage-rollout
2026-03-10 16:25:21 +00:00
Michael B. Gale
048d0ea295
Address review comments
2026-03-10 15:54:58 +00:00
Henry Mercer
cf972cde0e
Update database upload tests to use checkExpectedLogMessages
2026-03-10 15:52:14 +00:00
Henry Mercer
ee5ede79f7
Address review comments
2026-03-10 15:51:28 +00:00
Henry Mercer
e07c3055d7
Tweak changelog formatting
2026-03-10 15:43:28 +00:00
Henry Mercer
55a0f2b2aa
Add environment variable override
2026-03-10 15:41:40 +00:00
Michael B. Gale
c92efdb98d
Type result of parsing JSON as unknown until narrowed
2026-03-10 15:31:21 +00:00
Michael B. Gale
c6e75ac1e8
Add JSON helper types and functions
2026-03-10 15:31:21 +00:00
Sam Robson
79ea59d97e
Merge branch 'main' into sam-robson/overlay-per-lang-min-bundle-version
2026-03-10 14:13:22 +00:00
Michael B. Gale
823869da10
Use isDefined for password and token in credentialToStr
2026-03-10 13:30:52 +00:00
Michael B. Gale
131392e95f
Fix changelog entry
2026-03-10 13:23:16 +00:00
Henry Mercer
bef08edf32
Update to log deprecation warning
...
Move rollout to April
2026-03-10 13:14:00 +00:00
Henry Mercer
edfcb0a509
Update tests
2026-03-10 12:49:58 +00:00
Henry Mercer
ca969a91db
Add changelog note
2026-03-10 12:34:47 +00:00
Henry Mercer
13c548978d
Fix retries when uploading databases
2026-03-10 12:34:18 +00:00
Michael B. Gale
87c3b7b6a1
Merge pull request #3519 from github/mbg/csra/upload-failed-sarif-artifact
...
Upload failed SARIF for risk assessments in `init-post` step
2026-03-10 11:53:12 +00:00
Henry Mercer
ce321daddb
Merge branch 'main' into henrymercer/skip-file-coverage-rollout
2026-03-10 11:46:08 +00:00
Henry Mercer
55ae11793a
Reduce duplication of getFileCoverageInformationEnabled
2026-03-10 11:42:53 +00:00
Henry Mercer
3d2bdbbd3b
Simplify default repo properties
2026-03-10 11:33:00 +00:00
Michael B. Gale
e90d128a3c
Add preliminary change note
2026-03-10 02:14:53 +00:00
Michael B. Gale
88bd340eb0
Add OIDC tests for getCredentials
2026-03-10 02:14:52 +00:00
Michael B. Gale
4649e158bc
Fix old test
2026-03-10 02:14:52 +00:00
Michael B. Gale
3d574205fc
Run more start-proxy tests in parallel
2026-03-10 02:14:52 +00:00
Michael B. Gale
e168f8e52a
Move credentialToStr and update it
2026-03-10 02:14:52 +00:00
Michael B. Gale
7263be2084
Extract AuthConfig from Credential
2026-03-10 01:26:15 +00:00
Michael B. Gale
37eb89b173
Add predicates for Auth types
2026-03-10 01:26:15 +00:00
Michael B. Gale
9e26f9e6e0
Add OIDC config types
2026-03-10 01:26:15 +00:00
Michael B. Gale
01b52624a0
Move out auth config from Credential type
2026-03-10 01:26:15 +00:00
Sam Robson
8bddab0644
Merge branch 'main' into sam-robson/overlay-per-lang-min-bundle-version
2026-03-09 20:23:29 +00:00
Michael B. Gale
65f7f36302
Extend isPrintable check to all keys with string values
2026-03-09 19:06:06 +00:00
Michael B. Gale
746f940d10
Merge remote-tracking branch 'origin/main' into mbg/csra/upload-failed-sarif-artifact
2026-03-09 18:32:36 +00:00
Michael B. Gale
babab88e54
Merge pull request #3561 from github/henrymercer/eslint-unused-vars
...
Linting: Require unused function parameters to start with `_`
2026-03-09 18:00:46 +00:00
Michael B. Gale
0ad7d7be2f
Merge pull request #3560 from github/henrymercer/ghes-3.13-cleanup
...
Clean up pre GHES 3.14 code paths
2026-03-09 18:00:31 +00:00
Michael B. Gale
8ba8180559
Merge remote-tracking branch 'origin/main' into mbg/pr-checks/validation-jobs
2026-03-09 17:58:41 +00:00
Henry Mercer
3592fe5d7a
Address review comments
2026-03-09 17:32:57 +00:00
Henry Mercer
3c97288d80
Merge pull request #3559 from github/henrymercer/ghes-repository-properties
...
Load custom repository properties on GHES and remove feature flag
2026-03-09 17:26:59 +00:00
Henry Mercer
6773afd159
Add changelog note
2026-03-09 17:14:12 +00:00
Henry Mercer
a3fdd0e0b5
Add telemetry diagnostic to track whether repo property is used
2026-03-09 17:13:41 +00:00
Henry Mercer
9e8c05933f
Add ability to override via repository property
2026-03-09 17:08:13 +00:00
Henry Mercer
c102a6d8cd
Require tools feature flag
...
And now that we have this, drop the restriction to `github` org.
2026-03-09 17:07:10 +00:00
Sam Robson
867f2b0e0a
test: verify overlay analysis is disabled for languages without per-language feature flags
2026-03-09 16:46:38 +00:00
Sam Robson
e04697664c
feat: add minimumVersion values for existing language-specific overlay feature flags
2026-03-09 16:45:20 +00:00
Henry Mercer
fdecf48e22
Linting: Require unused function parameters to start with _
2026-03-09 16:43:17 +00:00
Henry Mercer
ab180c9eeb
Clean up pre GHES 3.14 code paths
2026-03-09 16:35:29 +00:00
Henry Mercer
1b7fa1a121
Drop unused variable
2026-03-09 16:30:34 +00:00
Henry Mercer
b0642f9e86
Remove unused imports
2026-03-09 16:25:20 +00:00
Henry Mercer
a770e76359
Add changelog note
2026-03-09 16:20:52 +00:00
Henry Mercer
8924dfb7d0
Remove GHES feature gate
...
All supported versions of GHES support the repository properties API.
2026-03-09 16:19:32 +00:00
Henry Mercer
b35c0d37b1
Clean up repository properties feature flag
2026-03-09 16:15:04 +00:00
Michael B. Gale
b39251fe78
Merge pull request #3557 from github/mbg/repo-props/multi-select
...
Fix handling of non-`string` values from repository properties API
2026-03-09 14:48:17 +00:00
Michael B. Gale
f054eea342
Merge pull request #3549 from github/mbg/pr-checks/remove-python-setup
...
Remove `installPython` from checks which should no longer need it
2026-03-09 14:48:05 +00:00
Michael B. Gale
6f90eb695f
Add changelog entry
2026-03-09 14:24:29 +00:00
Michael B. Gale
5ddbbbe614
Install python if there is no matrix.version
2026-03-09 14:16:23 +00:00
Michael B. Gale
da11f44114
Run prepare-test after setup steps
2026-03-09 14:13:22 +00:00
Michael B. Gale
149fd14ac7
Add unknown property with string[] value
2026-03-09 13:12:37 +00:00
Michael B. Gale
5311ed41ea
Include type in error message
2026-03-09 13:09:34 +00:00
Michael B. Gale
58314dce95
Export types that weren't already
2026-03-09 13:03:47 +00:00
Michael B. Gale
58991590bd
Validate value types returned by API against expectations
2026-03-09 12:46:24 +00:00
Michael B. Gale
9c75a5f60c
Only validate property value type if we care about the property
2026-03-09 12:13:48 +00:00
Michael B. Gale
8e70ae21a1
Update GitHubRepositoryProperty to match schema
2026-03-09 12:03:34 +00:00
Sam Robson
9082319f5c
Merge branch 'main' into kaspersv/move-diff-range-absolute-path-conversion
2026-03-06 15:03:13 +00:00
Sam Robson
cdafc35ccb
refactor: pass checkoutPath as param to writeDiffRangeDataExtensionPack
2026-03-06 10:12:08 +00:00
Óscar San José
d1a65275e8
Merge pull request #3552 from github/mergeback/v4.32.6-to-main-0d579ffd
...
Mergeback v4.32.6 refs/heads/releases/v4 into main
2026-03-06 10:03:43 +00:00
Sam Robson
c10020e6a8
Merge remote-tracking branch 'origin/main' into kaspersv/move-diff-range-absolute-path-conversion
...
* origin/main: (32 commits)
Add changelog note
Update default bundle to codeql-bundle-v2.24.3
Bump tar from 7.5.7 to 7.5.10
Rebuild
Rebuild
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
Bump actions/download-artifact from 7 to 8 in /.github/workflows
Bump the npm-minor group with 2 updates
Fix some tests that should be serial
Update method naming and JSDoc
Rename to `EnabledOverlayConfig`
Address review comments
Use `Result`s for enablement return types
Add disabled by env var disablement reason
Rename to `usesDefaultQueriesOnly`
Update `NonDefaultQueries` documentation
Refactor `getOverlayDatabaseMode` and add new disablement reason
Address review comments
Add JSDoc
Sort `OverlayDisabledReason` enum
...
2026-03-06 09:10:13 +00:00
github-actions[bot]
0ccdcb8c0a
Rebuild
2026-03-05 19:44:36 +00:00
github-actions[bot]
05a48207b3
Update changelog and version after v4.32.6
2026-03-05 19:33:19 +00:00
Óscar San José
0d579ffd05
Merge pull request #3551 from github/update-v4.32.6-72d2d850d
...
Merge main into releases/v4
2026-03-05 20:29:07 +01:00
github-actions[bot]
d4c6be7cf1
Update changelog for v4.32.6
2026-03-05 18:58:14 +00:00
Sam Robson
b2de4934cf
refactor: pass checkoutPath as param and fix docs for relative path semantics
2026-03-05 18:09:06 +00:00
Michael B. Gale
0da2e79318
Remove installPython from checks which should no longer need it
2026-03-05 16:17:19 +00:00
Michael B. Gale
2a0060496c
Fix condition
2026-03-05 16:07:10 +00:00
Michael B. Gale
103db93efa
Make it more explicit that getSetupSteps just needs a JobSpecification
2026-03-05 16:06:03 +00:00
Óscar San José
72d2d850d1
Merge pull request #3548 from github/update-bundle/codeql-bundle-v2.24.3
...
Update default bundle to 2.24.3
2026-03-05 16:02:55 +00:00
Michael B. Gale
23f983ce00
Merge pull request #3544 from github/dependabot/github_actions/dot-github/workflows/actions/download-artifact-8
...
Bump actions/download-artifact from 7 to 8 in /.github/workflows
2026-03-05 15:54:50 +00:00
Michael B. Gale
79fdef791d
Fix generateValidationJobs typing
2026-03-05 15:54:33 +00:00
Michael B. Gale
3d478129f2
Add tsconfig.json for pr-checks
2026-03-05 15:54:17 +00:00
Michael B. Gale
832e97ccad
Merge pull request #3545 from github/dependabot/github_actions/dot-github/workflows/actions/upload-artifact-7
...
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
2026-03-05 15:52:06 +00:00
Michael B. Gale
5ef38c0b13
Merge pull request #3546 from github/dependabot/npm_and_yarn/tar-7.5.10
...
Bump tar from 7.5.7 to 7.5.10
2026-03-05 15:48:25 +00:00
Michael B. Gale
56ebdff8ae
Merge branch 'main' into mbg/pr-checks/validation-jobs
2026-03-05 15:39:28 +00:00
github-actions[bot]
80c9cda739
Add changelog note
2026-03-05 15:34:29 +00:00
github-actions[bot]
f2669dd916
Update default bundle to codeql-bundle-v2.24.3
2026-03-05 15:34:19 +00:00
Michael B. Gale
bd03c44cf4
Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/download-artifact-8
2026-03-05 15:32:00 +00:00
dependabot[bot]
102d7627b6
Bump tar from 7.5.7 to 7.5.10
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.5.7 to 7.5.10.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.7...v7.5.10 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.10
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-05 14:47:50 +00:00
Henry Mercer
0c0c5dc2f1
Merge pull request #3543 from github/dependabot/npm_and_yarn/npm-minor-af60a9b329
...
Bump the npm-minor group with 2 updates
2026-03-05 13:40:16 +00:00
github-actions[bot]
e96635d9ff
Rebuild
2026-03-05 13:19:38 +00:00
github-actions[bot]
77f9a86c60
Rebuild
2026-03-05 13:19:28 +00:00
github-actions[bot]
e681b9fb11
Merge remote-tracking branch 'origin/main' into dependabot/github_actions/dot-github/workflows/actions/upload-artifact-7
2026-03-05 13:18:44 +00:00
github-actions[bot]
bc4b00aadc
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_yarn/npm-minor-af60a9b329
2026-03-05 13:18:38 +00:00
Henry Mercer
05b6a6cfaa
Merge pull request #3538 from github/henrymercer/breakdown-overlay-disabled-reason
...
Break down overlay disabled reason
2026-03-05 13:13:13 +00:00
Michael B. Gale
b1b5550715
Merge pull request #3529 from github/mbg/ts/sync-back
...
Convert `sync_back.py` to TypeScript
2026-03-05 12:36:22 +00:00
Sam Robson
1443f5865e
chore: merge main into kaspersv/move-diff-range-absolute-path-conversion
2026-03-05 11:38:11 +00:00
dependabot[bot]
31d26f2397
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 6 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 18:01:17 +00:00
dependabot[bot]
4d433615e7
Bump actions/download-artifact from 7 to 8 in /.github/workflows
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 7 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 18:00:15 +00:00
dependabot[bot]
545356f200
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `eslint-plugin-jsdoc` from 62.6.0 to 62.7.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.6.0...v62.7.1 )
Updates `typescript-eslint` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.7.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 17:53:15 +00:00
Henry Mercer
6d1c37ed8f
Fix some tests that should be serial
2026-03-04 18:02:17 +01:00
Henry Mercer
759b5db350
Merge branch 'main' into henrymercer/breakdown-overlay-disabled-reason
...
# Conflicts:
# src/config-utils.test.ts
2026-03-04 17:54:35 +01:00
Henry Mercer
60a0e2bf96
Update method naming and JSDoc
2026-03-04 17:50:30 +01:00
Henry Mercer
7449e3294d
Rename to EnabledOverlayConfig
2026-03-04 17:38:56 +01:00
Henry Mercer
4cd47adfe1
Address review comments
2026-03-04 17:38:24 +01:00
Henry Mercer
5fa8dad095
Use Results for enablement return types
2026-03-04 17:36:42 +01:00
Henry Mercer
6a77217a46
Add disabled by env var disablement reason
2026-03-04 17:27:44 +01:00
Henry Mercer
b6dfacb528
Merge pull request #3542 from github/henrymercer/parallel-unit-tests
...
Run some unit tests in parallel
2026-03-04 16:07:10 +00:00
Henry Mercer
6123416ead
Merge remote-tracking branch 'origin/main' into henrymercer/parallel-unit-tests
2026-03-04 15:12:33 +01:00
Henry Mercer
a6594f96a3
Merge pull request #3540 from github/henrymercer/stub-actions-vars
...
Testing: Provide default value for more environment variables in `setupActionsVars`
2026-03-04 13:27:40 +00:00
Henry Mercer
be20394012
Rename to usesDefaultQueriesOnly
2026-03-04 13:56:56 +01:00
Henry Mercer
d1c255c293
Update NonDefaultQueries documentation
2026-03-04 13:55:29 +01:00
Henry Mercer
b371ccd8ea
Refactor getOverlayDatabaseMode and add new disablement reason
2026-03-04 13:53:12 +01:00
Henry Mercer
71d7981285
Address review comments
2026-03-04 13:27:59 +01:00
Henry Mercer
e9e9733cb5
Merge branch 'main' into henrymercer/stub-actions-vars
2026-03-04 13:26:43 +01:00
Henry Mercer
8e17ec94b4
Merge branch 'main' into henrymercer/parallel-unit-tests
2026-03-04 13:25:01 +01:00
Henry Mercer
aae94187c1
Fix test name
2026-03-04 13:09:10 +01:00
Henry Mercer
36148cccb9
Run more actions util tests serially
2026-03-04 13:08:37 +01:00
Henry Mercer
a5b959e10d
Merge pull request #3537 from github/henrymercer/overlay-status-record-job
...
Record the job that published an overlay status
2026-03-04 11:49:52 +00:00
Michael B. Gale
d1ac77f26d
Merge pull request #3527 from github/mbg/start-proxy/remove-unused
...
Remove unused registry types from `LANGUAGE_TO_REGISTRY_TYPE`
2026-03-04 11:48:08 +00:00
Henry Mercer
675af55c60
Run some unit tests in parallel
2026-03-04 12:40:22 +01:00
Michael B. Gale
2b6077152e
Add support for additional, validation jobs
2026-03-04 11:37:17 +00:00
Michael B. Gale
95fc2f11fb
Move yq setup code into getSetupSteps
2026-03-04 11:37:17 +00:00
Michael B. Gale
92ab799fe0
Refactor job generation into generateJob
2026-03-04 11:37:17 +00:00
Michael B. Gale
369d73b98f
Refactor matrix generation into its own function
2026-03-04 11:37:16 +00:00
Michael B. Gale
97a3705788
Organise language-specific setup information
2026-03-04 11:37:16 +00:00
Henry Mercer
281b265245
Address review comments
2026-03-04 12:16:54 +01:00
Henry Mercer
335f08ccc6
Merge pull request #3539 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2026-03-04 11:01:18 +00:00
github-actions[bot]
4593dc2f8f
Update supported GitHub Enterprise Server versions
2026-03-04 00:23:29 +00:00
Henry Mercer
d4f1b14259
Use new setupActionsVars pattern
2026-03-03 19:24:18 +01:00
Henry Mercer
8a884bdb36
Extend setupActionsVars
2026-03-03 19:09:57 +01:00
Henry Mercer
129d771399
Add check run ID
2026-03-03 19:04:04 +01:00
Henry Mercer
776fd85f8c
Address review comments
2026-03-03 18:48:23 +01:00
Henry Mercer
f654d61146
Add JSDoc
2026-03-03 17:24:47 +01:00
Henry Mercer
eddf33655d
Sort OverlayDisabledReason enum
2026-03-03 17:22:36 +01:00
Henry Mercer
9f77ff18bb
Make "insufficient resources" reason more specific
2026-03-03 17:21:59 +01:00
Henry Mercer
0158d05946
Make "feature not enabled" reason more specific
2026-03-03 17:17:07 +01:00
Henry Mercer
a05f541a6e
Record the job that published an overlay status
...
This makes it easier to find the job that produced the status.
2026-03-03 16:56:18 +01:00
Michael B. Gale
5db3a9e947
Extract JobSpecification type from Specification
2026-03-03 14:15:45 +00:00
Michael B. Gale
40f0fa95c4
Merge pull request #3535 from github/mbg/ci/no-skip-overlay
...
Disable overlay status check for CS config test workflow
2026-03-03 12:26:50 +00:00
Michael B. Gale
9bf973324f
Merge pull request #3528 from github/mbg/refactor/sarif
...
Refactor SARIF-related types and functions into a separate module
2026-03-03 12:10:30 +00:00
Michael B. Gale
1175fd9b5d
Add some docs to some newer overlay Features
...
To make it easier to see what they do at a glance
2026-03-03 12:06:46 +00:00
Michael B. Gale
1faad73c9a
Disable resource checks as well
2026-03-03 12:06:46 +00:00
Michael B. Gale
6b246e4709
Disable overlay status check for CS config test workflow
2026-03-03 11:53:33 +00:00
Michael B. Gale
0a5b95cdcc
Update pr-checks README
2026-03-03 11:45:18 +00:00
Michael B. Gale
77fc89c78d
Remove python files from pr-checks
2026-03-03 11:42:49 +00:00
Michael B. Gale
bf9bf1c027
Remove python setup from rebuild workflow
2026-03-03 11:41:24 +00:00
Michael B. Gale
24fa947692
Update pr-checks to run new tests
2026-03-03 11:40:54 +00:00
Michael B. Gale
aaed7b75f9
Merge remote-tracking branch 'origin/main' into mbg/ts/sync-back
2026-03-03 11:36:59 +00:00
Michael B. Gale
2a2f4c30a1
Add docs for automationId
2026-03-03 11:35:43 +00:00
Michael B. Gale
6d060bbaa1
Return Partial<Log> from readSarifFile
...
Our previous definition had `tools` as a mandatory field, so this
also makes some changes to deal with the case where that may
be `undefined` by treating it as equivalent to `[]`.
2026-03-03 11:34:01 +00:00
Michael B. Gale
28b449d8c7
Improve version handling in combineSarifFiles
2026-03-03 11:18:47 +00:00
Michael B. Gale
1721ce7afd
Address minor review comments
2026-03-03 11:05:37 +00:00
Michael B. Gale
ff2daa0aba
Merge pull request #3526 from github/mbg/pr-checks/ts
...
Convert `sync.py` to TypeScript
2026-03-03 10:49:56 +00:00
Michael B. Gale
b43d146e37
Do not alias types
2026-03-02 20:47:19 +00:00
Michael B. Gale
66e08d2b3f
Make entries in new mapping mandatory
2026-03-02 18:08:53 +00:00
Michael B. Gale
9a31859f78
Use @types/sarif
2026-03-02 18:04:11 +00:00
Michael B. Gale
ae9cb02459
Add dependency on @types/sarif
2026-03-02 17:41:41 +00:00
Michael B. Gale
c0b22b827b
Replace filename in CONTRIBUTING.md
2026-03-02 15:40:32 +00:00
Michael B. Gale
d09af9d5b8
Type workflow input names
2026-03-02 15:39:46 +00:00
Michael B. Gale
e7ec96cee0
Remove isTruthy: consistently use booleans in templates
2026-03-02 15:34:11 +00:00
Michael B. Gale
41d5a06bfd
Address basic style comments
2026-03-02 15:32:30 +00:00
Michael B. Gale
4ca06280ba
Merge remote-tracking branch 'origin/main' into mbg/pr-checks/ts
2026-03-02 14:03:56 +00:00
Henry Mercer
b895512248
Merge pull request #3532 from github/mergeback/v4.32.5-to-main-c793b717
...
Mergeback v4.32.5 refs/heads/releases/v4 into main
2026-03-02 11:59:49 +00:00
github-actions[bot]
6059d3ceb5
Rebuild
2026-03-02 11:35:32 +00:00
github-actions[bot]
bab3951531
Merge remote-tracking branch 'origin/main' into mergeback/v4.32.5-to-main-c793b717
2026-03-02 11:34:42 +00:00
github-actions[bot]
93ec0f487d
Update changelog and version after v4.32.5
2026-03-02 11:13:35 +00:00
Henry Mercer
c793b717bc
Merge pull request #3523 from github/update-v4.32.5-ca42bf226
...
Merge main into releases/v4
2026-03-02 11:11:20 +00:00
Henry Mercer
06cd615ad8
Soften language re overlay failures
2026-03-02 11:48:45 +01:00
Henry Mercer
f5516c6630
Improve changelog
2026-03-02 11:45:27 +01:00
Henry Mercer
97519e197e
Update release date
2026-03-02 10:03:22 +00:00
Michael B. Gale
a6892dcba5
Use sync_back.ts in rebuild workflow
2026-03-01 16:04:35 +00:00
Michael B. Gale
8eb0202e9d
Port tests
2026-03-01 16:04:35 +00:00
Michael B. Gale
dd779fa7d3
Add updateTemplateFiles
2026-03-01 16:04:35 +00:00
Michael B. Gale
f05cfae018
Add updateSyncTs
2026-03-01 16:04:35 +00:00
Michael B. Gale
e1b83ccb74
Add scanGeneratedWorkflows
2026-03-01 16:04:35 +00:00
Michael B. Gale
6a6bd778b6
Add initial sync_back.ts script
2026-03-01 16:04:35 +00:00
Michael B. Gale
f0f92a1dc8
Remove sync.py
2026-03-01 16:03:47 +00:00
Michael B. Gale
e931a2475a
Replace remaining uses of sync.py
2026-03-01 16:03:35 +00:00
Michael B. Gale
8bfaf96434
Run npm ci in actions
2026-03-01 15:20:30 +00:00
Michael B. Gale
8a1cd7656d
Put change behind a FF
2026-03-01 15:07:47 +00:00
Michael B. Gale
3b16d31abc
Delete unused fixInvalidNotifications function
2026-03-01 14:26:41 +00:00
Michael B. Gale
40aec383a1
Move more SARIF helpers to sarif module
2026-03-01 14:22:49 +00:00
Michael B. Gale
2fce45b8e6
Add wrapper around JSON.parse to sarif module
2026-03-01 14:10:25 +00:00
Michael B. Gale
d7cfd19fb8
Move SARIF types out of util.ts
2026-03-01 13:42:46 +00:00
Michael B. Gale
68d73442fa
Remove unused registry types from LANGUAGE_TO_REGISTRY_TYPE
2026-02-28 23:24:41 +00:00
Michael B. Gale
f91cab1409
Adjust quotes and re-generate workflows
2026-02-28 18:13:05 +00:00
Michael B. Gale
5876a93a5f
Switch sync.sh script to only use sync.ts
2026-02-28 17:58:00 +00:00
Michael B. Gale
0ea8490473
Switch from js-yaml to yaml for better output formatting
2026-02-28 17:55:41 +00:00
Michael B. Gale
a85af80f34
Generate and write collections
2026-02-28 16:47:22 +00:00
Michael B. Gale
47671ab7aa
Track collections
2026-02-28 16:46:47 +00:00
Michael B. Gale
96e6b655c1
Add tool-specific setup steps
2026-02-28 16:32:32 +00:00
Michael B. Gale
57c7bc6885
Add analysisKinds
2026-02-28 16:32:32 +00:00
Michael B. Gale
d52917b510
Add useAllPlatformBundle
2026-02-28 16:32:32 +00:00
Michael B. Gale
b948e562f4
Add basic job steps
2026-02-28 16:32:31 +00:00
Michael B. Gale
c889588a2c
Add env, container, and services
2026-02-28 16:32:31 +00:00
Michael B. Gale
b77ebbe4d8
Add CODEQL_ACTION_TEST_MODE
2026-02-28 16:32:31 +00:00
Michael B. Gale
9a0fe9e006
Add permissions
2026-02-28 16:32:31 +00:00
Michael B. Gale
dd78add36d
Add matrix to job
2026-02-28 16:32:31 +00:00
Michael B. Gale
e62a268a73
Add job construction
2026-02-28 16:32:31 +00:00
Michael B. Gale
63b4776d64
Add matrix construction
2026-02-28 16:32:30 +00:00
Michael B. Gale
6932b1cda2
Add concurrency settings
2026-02-28 16:32:30 +00:00
Michael B. Gale
40aefb0faf
Add basic workflow construction
2026-02-28 16:32:30 +00:00
Michael B. Gale
efe64e03d9
Add isTruthy helper
2026-02-28 16:32:30 +00:00
Michael B. Gale
898d46e783
Strip trailing whitespace in output
2026-02-28 16:32:30 +00:00
Michael B. Gale
04c1e601ab
Add defaultTestVersions constant
2026-02-28 16:18:04 +00:00
Michael B. Gale
2f77cd04d4
Add specification types
2026-02-28 16:06:14 +00:00
Michael B. Gale
c7e378f003
Scaffold project for sync.ts script
2026-02-28 15:58:47 +00:00
Michael B. Gale
f3663cdc32
Fix typos in comments
2026-02-28 15:18:25 +00:00
Henry Mercer
0ec47d036c
Merge pull request #3524 from github/henrymercer/checks-use-setup-codeql
...
CI: Update CodeQL Action test to use `setup-codeql`
2026-02-27 17:02:44 +00:00
Henry Mercer
59245fd159
Add missing permissions to access feature flags
2026-02-27 17:39:20 +01:00
Henry Mercer
05259a1d08
Add more changelog notes
2026-02-27 17:24:17 +01:00
Henry Mercer
389c8322d5
CI: Update CodeQL Action test to use setup-codeql
2026-02-27 17:06:16 +01:00
Henry Mercer
01ee2f785a
Add changelog notes
2026-02-27 16:09:38 +01:00
github-actions[bot]
c72d9a4933
Update changelog for v4.32.5
2026-02-27 14:37:26 +00:00
Henry Mercer
ca42bf226a
Merge pull request #3522 from github/henrymercer/update-supported-versions-table
...
Update supported Action / Bundle / GHES version table
2026-02-27 13:57:17 +00:00
Henry Mercer
6704d80ac6
Merge pull request #3520 from github/dependabot/npm_and_yarn/fast-xml-parser-5.4.1
...
Bump fast-xml-parser from 5.3.6 to 5.4.1
2026-02-27 13:57:12 +00:00
Henry Mercer
76348c0f12
Merge pull request #3521 from github/dependabot/npm_and_yarn/minimatch-3.1.5
...
Bump minimatch from 3.1.3 to 3.1.5
2026-02-27 13:57:06 +00:00
Henry Mercer
3a42a998ef
Update supported Action / Bundle / GHES version table
2026-02-27 13:37:42 +00:00
Henry Mercer
8ab0431fc3
Merge pull request #3514 from github/dependabot/npm_and_yarn/globals-17.3.0
...
Bump globals from 16.5.0 to 17.3.0
2026-02-27 13:28:04 +00:00
Henry Mercer
2c92579346
Merge pull request #3513 from github/dependabot/npm_and_yarn/npm-minor-e1092f1102
...
Bump eslint-plugin-jsdoc from 62.5.0 to 62.6.0 in the npm-minor group
2026-02-27 13:27:19 +00:00
github-actions[bot]
2475286230
Rebuild
2026-02-27 13:23:45 +00:00
github-actions[bot]
236fbf7645
Rebuild
2026-02-27 13:23:30 +00:00
dependabot[bot]
29181f28d5
Bump minimatch from 3.1.3 to 3.1.5
...
Bumps [minimatch](https://github.com/isaacs/minimatch ) from 3.1.3 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.3...v3.1.5 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 3.1.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-27 13:21:47 +00:00
dependabot[bot]
a0735d7c2a
Bump fast-xml-parser from 5.3.6 to 5.4.1
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.6 to 5.4.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.6...v5.4.1 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.4.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-27 13:21:34 +00:00
Henry Mercer
b35e0349aa
Merge pull request #3518 from github/mbg/ci/merge-queue-codeql
...
Disable CodeQL upload for merge queue and exclude PR size workflow from required checks
2026-02-27 12:56:04 +00:00
Michael B. Gale
e995ba3522
Add more tests/assertions
2026-02-27 12:52:54 +00:00
Michael B. Gale
1e7e52a330
Add tests where upload should get skipped
2026-02-27 12:40:04 +00:00
Michael B. Gale
383b86ddcb
Refactor some test setup code into mockRiskAssessmentEnv
2026-02-27 12:27:32 +00:00
Michael B. Gale
4406eba03e
Skip uploads in merge queue
2026-02-27 12:14:56 +00:00
Henry Mercer
1b897f3911
Fix conditions in code scanning config checks
...
DIff-informed analysis isn't enabled in the merge queue.
2026-02-27 12:10:38 +00:00
Henry Mercer
adf58cf166
Merge pull request #3515 from github/henrymercer/drop-ram-limit
...
Skip overlay memory check for CodeQL 2.24.3 and later
2026-02-27 11:17:11 +00:00
Michael B. Gale
ca32b84657
Ensure correct failed SARIF file names for CSRA
2026-02-26 19:56:07 +00:00
Michael B. Gale
ce97dfe405
Sanitise artifact name
2026-02-26 19:47:55 +00:00
Michael B. Gale
003044eb84
Add test
2026-02-26 19:18:32 +00:00
Michael B. Gale
5b9d1f4fdf
Simplify prepareFailedSarif for risk assessments
2026-02-26 19:18:29 +00:00
Michael B. Gale
f265dd9392
Separate generateFailedSarif out of prepareFailedSarif
2026-02-26 18:44:50 +00:00
Michael B. Gale
44b66a8064
Upload failed SARIF as artifact for risk assessments
2026-02-26 18:40:00 +00:00
Michael B. Gale
b7d3fb98df
Exclude "Label PR with size" from required checks
2026-02-26 18:25:26 +00:00
Michael B. Gale
4e8e79431d
Run CodeQL with linked tools for merge queue
2026-02-26 18:25:26 +00:00
Michael B. Gale
60ca40ecd4
Refactor prepareFailedSarif out of maybeUploadFailedSarif
2026-02-26 18:07:00 +00:00
Michael B. Gale
56d1ccc87a
Change skipped reason message
2026-02-26 17:51:06 +00:00
Michael B. Gale
e9ce32d807
Change order of checks in tryUploadSarifIfRunFailed
2026-02-26 17:51:06 +00:00
Michael B. Gale
0f3e632580
Rename secondary run to uploadFailureInfo
2026-02-26 17:47:32 +00:00
github-actions[bot]
52c2a032f3
Rebuild
2026-02-26 17:22:24 +00:00
Henry Mercer
ba1288cb3c
Merge branch 'main' into dependabot/npm_and_yarn/globals-17.3.0
2026-02-26 17:20:10 +00:00
Henry Mercer
29765a3c71
Skip overlay memory check for CodeQL 2.24.3 and later
2026-02-26 16:53:26 +00:00
github-actions[bot]
068e80c14c
Rebuild
2026-02-26 16:42:43 +00:00
Michael B. Gale
154969e08b
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-e1092f1102
2026-02-26 16:40:19 +00:00
Michael B. Gale
b0ed4dedcb
Merge pull request #3511 from github/henrymercer/merge-queue
...
Add `merge_group` trigger to required checks to prepare for merge queue
2026-02-26 16:33:14 +00:00
Michael B. Gale
3c83f578ed
Merge pull request #3516 from github/mbg/start-proxy/reduce-connection-check-severity
2026-02-26 16:32:00 +00:00
Henry Mercer
20f148b36e
Merge pull request #3507 from github/henrymercer/overlay-repo-property
...
Add a repository property for disabling overlay
2026-02-26 16:21:03 +00:00
Henry Mercer
4068616de4
Merge branch 'main' into henrymercer/overlay-repo-property
2026-02-26 15:27:25 +00:00
Michael B. Gale
0d5f70631a
Merge branch 'main' into mbg/start-proxy/reduce-connection-check-severity
2026-02-26 15:16:23 +00:00
Michael B. Gale
ae14a1f513
Merge branch 'main' into henrymercer/merge-queue
2026-02-26 15:11:41 +00:00
Michael B. Gale
a577f702b9
Merge pull request #3512 from github/mbg/start-proxy/use-default-cli
...
Use `getDefaultCliVersion` for `start-proxy`
2026-02-26 15:11:18 +00:00
Michael B. Gale
bce0deb953
Fix log message / returned version
2026-02-26 13:55:47 +00:00
Michael B. Gale
db33d20bf4
Put change behind a FF
2026-02-26 13:10:52 +00:00
Michael B. Gale
3c911485ed
Address Copilot's review comments
2026-02-26 13:07:03 +00:00
Michael B. Gale
1ec5b701fc
Reduce log levels for registry connection checks
2026-02-26 11:53:26 +00:00
dependabot[bot]
9bdf640d99
Bump globals from 16.5.0 to 17.3.0
...
Bumps [globals](https://github.com/sindresorhus/globals ) from 16.5.0 to 17.3.0.
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v16.5.0...v17.3.0 )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.3.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 17:53:31 +00:00
dependabot[bot]
b2beb85441
Bump eslint-plugin-jsdoc from 62.5.0 to 62.6.0 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.5.0 to 62.6.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.5.0...v62.6.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.6.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 17:53:10 +00:00
Michael B. Gale
f657c4e1eb
Use getDefaultCliVersion for start-proxy
2026-02-25 17:43:15 +00:00
Henry Mercer
f379c46d49
Address review comments
2026-02-25 15:26:48 +00:00
Henry Mercer
8105503f1a
Add merge_group trigger to required checks to prepare for merge queue
2026-02-25 15:12:37 +00:00
Henry Mercer
056b0912cf
Merge branch 'main' into henrymercer/overlay-repo-property
2026-02-25 14:43:34 +00:00
Henry Mercer
445a2a9bb2
Record overlay disablement reason
2026-02-25 14:36:03 +00:00
Henry Mercer
182427800c
Add disabled reason
2026-02-25 14:22:13 +00:00
Henry Mercer
c0fc915677
Merge pull request #3509 from github/dependabot/npm_and_yarn/multi-871638c4a1
...
Bump minimatch
2026-02-25 13:43:36 +00:00
Michael B. Gale
18898a6dd3
Merge pull request #3504 from github/mbg/ff/remove-ImprovedProxyCertificates
...
Remove FF gate for improved CA generation
2026-02-25 13:25:57 +00:00
Henry Mercer
70db156dcb
Add diagnostic when overlay disabled by repo property
2026-02-25 11:48:10 +00:00
Henry Mercer
9c61a2ddf4
Reorganize properties file
2026-02-25 11:35:34 +00:00
github-actions[bot]
123b3011fa
Rebuild
2026-02-25 00:19:51 +00:00
dependabot[bot]
0aafb58a10
Bump minimatch
...
Bumps and [minimatch](https://github.com/isaacs/minimatch ). These dependencies needed to be updated together.
Updates `minimatch` from 10.1.1 to 10.2.2
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 5.1.6 to 5.1.7
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 3.1.2 to 3.1.3
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 9.0.5 to 9.0.6
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 10.2.2
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 5.1.7
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 3.1.3
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 9.0.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 00:17:44 +00:00
Henry Mercer
16adc4e672
Merge pull request #3506 from github/henrymercer/result-better-inference
...
Improve type inference of `Result<T, E>`
2026-02-24 20:05:34 +00:00
Henry Mercer
2808ca726e
Improve validation and address review comments
2026-02-24 19:56:43 +00:00
Henry Mercer
2a607fea25
Update JSDoc
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-02-24 19:28:27 +00:00
Henry Mercer
ed39a1ea5c
Add repository property for disabling overlay
2026-02-24 18:58:08 +00:00
Henry Mercer
7ea93ee2e1
Add support for boolean repository properties
2026-02-24 18:48:32 +00:00
Henry Mercer
e51b6a9a52
Update names in tests
2026-02-24 17:55:29 +00:00
Henry Mercer
160d27baf0
Improve type inference of Result<T, E>
2026-02-24 17:41:30 +00:00
Michael B. Gale
28737ec792
Merge pull request #3503 from github/mbg/ff/make-connection-checks-default
...
Remove FF gate for connection checks
2026-02-24 17:26:42 +00:00
Henry Mercer
e5f9d3b55e
Merge pull request #3487 from github/henrymercer/overlay-status
...
Cache first failure building an overlay base DB to avoid repeated failures
2026-02-24 17:19:19 +00:00
Henry Mercer
dc00a6f08f
Improve error message
2026-02-24 16:47:42 +00:00
Henry Mercer
ab56c02e0c
Merge pull request #3497 from github/henrymercer/eslint-v9
...
Update eslint to v9
2026-02-24 14:38:34 +00:00
Michael B. Gale
83c236af2b
Remove FF gate for improved CA generation
2026-02-24 11:25:57 +00:00
Michael B. Gale
25bde03dfb
Remove FF gate for connection checks
2026-02-24 11:18:51 +00:00
Michael B. Gale
c4dca28336
Merge pull request #3502 from github/mbg/remove-ccr
...
Remove all CCR-specific code and tests
2026-02-24 10:58:49 +00:00
Michael B. Gale
1aad2787ec
Update PR template
2026-02-24 10:36:28 +00:00
Michael B. Gale
b6cf67a711
Remove CCR e2e check
2026-02-24 10:34:09 +00:00
Michael B. Gale
f59338d600
Remove isCCR
2026-02-24 10:33:23 +00:00
Henry Mercer
2a07b6e3c7
Merge branch 'main' into henrymercer/eslint-v9
2026-02-23 19:01:30 +00:00
Henry Mercer
fba33f686a
Enable tseslint strict rules
2026-02-23 19:00:06 +00:00
Henry Mercer
48094d2b6e
Explicitly include eslint recommended rules
2026-02-23 18:43:10 +00:00
Michael B. Gale
cb4e075f11
Merge pull request #3501 from github/mbg/ci/dont-label-merged
2026-02-23 15:41:07 +00:00
Henry Mercer
1847416575
Merge pull request #3498 from github/henrymercer/overlay-resource-checks-v2
...
Add feature flag for more lenient overlay resource checks
2026-02-23 15:22:02 +00:00
Michael B. Gale
11dd746d70
Don't run label-pr-size once a PR has been merged
2026-02-23 15:09:13 +00:00
Michael B. Gale
a754a57c21
Merge pull request #3500 from github/mbg/fixup/version-pinning
...
Minor improvements to "Keeping the CodeQL Action up to date" section
2026-02-23 14:19:30 +00:00
Michael B. Gale
466da5ec2d
Slight wording change
2026-02-23 12:00:58 +00:00
Michael B. Gale
0a9b98b511
Highlight that this for advanced setups
2026-02-23 11:59:08 +00:00
Michael B. Gale
bce7dc4616
v3 => v4
2026-02-23 11:58:25 +00:00
Michael B. Gale
b13ab62bc0
Remove extra blank line
2026-02-23 11:57:23 +00:00
Sam Robson
4ea06e96f5
Merge pull request #3499 from github/sam-robson/document-version-pinning-risk
...
docs: guidance on keeping the CodeQL Action up to date
2026-02-23 10:34:02 +00:00
Sam Robson
c9223eb0a0
Merge branch 'main' into sam-robson/document-version-pinning-risk
2026-02-23 10:05:57 +00:00
Sam Robson
f0767c48a1
docs: risks of pinning
2026-02-20 20:15:14 +00:00
Henry Mercer
4e71011f44
Add feature flag for more lenient overlay resource checks
2026-02-20 18:26:14 +00:00
Henry Mercer
710e294578
Merge pull request #3489 from github/dependabot/npm_and_yarn/npm-minor-37a5b5ae66
...
Bump the npm-minor group with 6 updates
2026-02-20 17:12:00 +00:00
Henry Mercer
b948539dd4
Use import-x/no-cycle
2026-02-20 16:34:03 +00:00
Henry Mercer
c54531587d
Update eslint to v9
2026-02-20 15:57:26 +00:00
Michael B. Gale
559d85d1fa
Merge pull request #3477 from github/mbg/features/offline-features
2026-02-20 15:36:07 +00:00
Michael B. Gale
8e010557a9
Merge pull request #3495 from github/mergeback/v4.32.4-to-main-89a39a4e
2026-02-20 15:02:14 +00:00
github-actions[bot]
37d6d1ca27
Rebuild
2026-02-20 14:32:21 +00:00
github-actions[bot]
68b53dc641
Update changelog and version after v4.32.4
2026-02-20 14:17:35 +00:00
Michael B. Gale
89a39a4e59
Merge pull request #3494 from github/update-v4.32.4-39ba80c47
2026-02-20 14:15:31 +00:00
Michael B. Gale
e5d84c885c
Apply remaining review suggestions
2026-02-20 13:54:55 +00:00
Michael B. Gale
0c202097b5
Apply suggestions from code review
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-20 13:51:55 +00:00
Michael B. Gale
314172e5a1
Fix typo
2026-02-20 13:11:54 +00:00
Michael B. Gale
cdda72d36b
Add changelog entries
2026-02-20 13:07:14 +00:00
github-actions[bot]
cfda84cc55
Update changelog for v4.32.4
2026-02-20 12:42:43 +00:00
Michael B. Gale
39ba80c475
Merge pull request #3493 from github/update-bundle/codeql-bundle-v2.24.2
...
Update default bundle to 2.24.2
2026-02-20 11:01:00 +00:00
github-actions[bot]
00150dad95
Add changelog note
2026-02-20 10:44:41 +00:00
github-actions[bot]
d97dce6561
Update default bundle to codeql-bundle-v2.24.2
2026-02-20 10:44:31 +00:00
Michael B. Gale
50fdbb9ec8
Merge pull request #3492 from github/henrymercer/new-repository-properties-ff
...
Use new feature flag for repository properties
2026-02-20 10:43:26 +00:00
Henry Mercer
f7905e8415
Use new feature flag for repository properties
2026-02-19 18:30:50 +00:00
Henry Mercer
4191f52110
Address review comments
2026-02-19 17:57:08 +00:00
github-actions[bot]
79a913656c
Rebuild
2026-02-18 17:55:38 +00:00
dependabot[bot]
167b47e60c
Bump the npm-minor group with 6 updates
...
Bumps the npm-minor group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [semver](https://github.com/npm/node-semver ) | `7.7.3` | `7.7.4` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.54.0` | `8.55.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.54.0` | `8.56.0` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.2` | `0.27.3` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.5.0` | `62.5.4` |
| [nock](https://github.com/nock/nock ) | `14.0.10` | `14.0.11` |
Updates `semver` from 7.7.3 to 7.7.4
- [Release notes](https://github.com/npm/node-semver/releases )
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md )
- [Commits](https://github.com/npm/node-semver/compare/v7.7.3...v7.7.4 )
Updates `@typescript-eslint/eslint-plugin` from 8.54.0 to 8.55.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.55.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/parser )
Updates `esbuild` from 0.27.2 to 0.27.3
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.2...v0.27.3 )
Updates `eslint-plugin-jsdoc` from 62.5.0 to 62.5.4
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.5.0...v62.5.4 )
Updates `nock` from 14.0.10 to 14.0.11
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.10...v14.0.11 )
---
updated-dependencies:
- dependency-name: semver
dependency-version: 7.7.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.55.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.56.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.5.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: nock
dependency-version: 14.0.11
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 17:53:34 +00:00
Óscar San José
5e7a52feb2
Merge pull request #3488 from github/dependabot/npm_and_yarn/fast-xml-parser-5.3.6
...
Bump fast-xml-parser from 5.3.4 to 5.3.6
2026-02-18 15:41:31 +01:00
github-actions[bot]
76cf404c99
Rebuild
2026-02-18 05:01:36 +00:00
dependabot[bot]
7407d38386
Bump fast-xml-parser from 5.3.4 to 5.3.6
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.4 to 5.3.6.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.4...v5.3.6 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 04:59:37 +00:00
Michael B. Gale
015d8c7cbc
Merge pull request #3486 from github/mbg/start-proxy/java-env-checks
...
Log information about the runner which may affect the private registry proxy
2026-02-17 20:48:41 +00:00
Michael B. Gale
09bd46dda5
Fix typos in comments
2026-02-17 17:18:09 +00:00
Michael B. Gale
b927a69f96
Merge remote-tracking branch 'origin/main' into mbg/features/offline-features
2026-02-17 17:14:08 +00:00
Michael B. Gale
61f7dd3d0d
Fix checkExpectedLogMessages not asserting anything on success
2026-02-17 16:49:01 +00:00
Michael B. Gale
64300e453b
Merge branch 'main' into mbg/start-proxy/java-env-checks
2026-02-17 16:49:01 +00:00
Michael B. Gale
906dd890a5
Run java to show computed settings
2026-02-17 16:49:00 +00:00
Henry Mercer
898ae16413
Improve log message
2026-02-17 15:55:15 +00:00
Henry Mercer
fa56ea8dc0
Extract status file path helper
2026-02-17 15:55:13 +00:00
Henry Mercer
657f337cd1
Add tests for shouldSkipOverlayAnalysis
2026-02-17 15:55:05 +00:00
Henry Mercer
05d4e25296
Avoid mutating languages array in overlay status functions
...
Use [...languages].sort() instead of languages.sort() to avoid
mutating the caller's array as a side effect.
2026-02-17 15:55:05 +00:00
Henry Mercer
5c583bbb19
Include diagnostics in bundle
2026-02-17 15:55:02 +00:00
Henry Mercer
554b93127b
More error message improvements
2026-02-17 15:55:01 +00:00
Henry Mercer
3dd1275368
Improve error messages
2026-02-17 15:55:01 +00:00
Henry Mercer
d24014a749
Tweak diagnostic message
2026-02-17 15:55:00 +00:00
Henry Mercer
cc0dce044b
Improve diagnostic message wording
2026-02-17 15:55:00 +00:00
Henry Mercer
ef58c00dfe
Only store overlay status if analysis failed
2026-02-17 15:54:59 +00:00
Henry Mercer
7b7a951e08
Add status page diagnostic when overlay skipped
2026-02-17 15:54:58 +00:00
Henry Mercer
0c47ae1c18
Sort doc URLs
2026-02-17 15:54:58 +00:00
Henry Mercer
6c405c2562
Be more explicit about attempt to build overlay DB
2026-02-17 15:54:57 +00:00
Henry Mercer
827bba691f
Introduce feature flags for saving and checking status
2026-02-17 15:54:57 +00:00
Henry Mercer
96961e0ee3
Save overlay status to Actions cache
2026-02-17 15:54:53 +00:00
Henry Mercer
ebad062f08
Skip overlay analysis based on cached status
2026-02-17 15:54:31 +00:00
Henry Mercer
e275d63e1d
Generalise status to multiple languages
2026-02-17 15:54:06 +00:00
Henry Mercer
69c2819972
Add save and restore methods
2026-02-17 15:54:06 +00:00
Henry Mercer
d28d9967fe
Compute cache key for overlay language status
2026-02-17 15:54:06 +00:00
Henry Mercer
d1bdc0ea05
Create separate directory for overlay source code
2026-02-17 15:54:03 +00:00
Michael B. Gale
b1b1e44da9
Merge pull request #3474 from github/mbg/risk-assessment-analysis
...
Add `csra` analysis kind
2026-02-17 15:39:05 +00:00
Michael B. Gale
46473e05b7
Add more interesting Java properties
2026-02-17 15:23:21 +00:00
Michael B. Gale
32ab108bfd
Move interesting JRE properties out of checkJdkSettings
2026-02-17 15:22:43 +00:00
Michael B. Gale
971592501c
Consistently use "\n" to split lines, then trim extra characters if needed
2026-02-17 14:58:40 +00:00
Michael B. Gale
2abec3f0c3
Replace most occurrences of CSRA
2026-02-17 14:55:31 +00:00
Michael B. Gale
6d55dfff02
Reword error message
2026-02-17 14:49:34 +00:00
Michael B. Gale
5c96b6e3db
Add JSDoc comments to upload-lib types
2026-02-17 14:40:16 +00:00
Michael B. Gale
44a4bea367
Fixup: add missing .env
2026-02-17 13:54:22 +00:00
Michael B. Gale
11c6c18818
Only run when debugging or test mode is enabled
2026-02-17 13:44:18 +00:00
Michael B. Gale
99fcc7b2a1
Check whether value is a URL in checkEnvVar and clear credentials
...
Note also that we run this after `getCredentials` which already instructs Actions to mask credentials that we know about in logs
2026-02-17 13:42:51 +00:00
Michael B. Gale
c1d6ee5477
Fix typos
2026-02-17 13:31:01 +00:00
Michael B. Gale
ef9cfd91a8
Clear GHA JAVA_HOME_* env vars for discoverActionsJdks test
2026-02-17 13:28:56 +00:00
Michael B. Gale
4250b466b2
Wrap checkProxyEnvironment call in try/catch for good measure
2026-02-17 13:17:49 +00:00
Michael B. Gale
a3d7d36aa6
Find likely JDK locations and check configurations
2026-02-17 13:17:48 +00:00
Michael B. Gale
33e2dff082
Log information about proxy-related environment variables
2026-02-17 12:38:30 +00:00
Michael B. Gale
bff89dcba4
Add enum for Java-related env var names
2026-02-17 11:37:25 +00:00
Michael B. Gale
d6ea6709b9
Remove unnecessary check
2026-02-17 10:56:29 +00:00
Michael B. Gale
f315d82bd7
Rename csra to risk-assessment
2026-02-17 10:52:04 +00:00
Michael B. Gale
ebce69a4b7
Merge pull request #3485 from github/mbg/java/network-debugging
...
Add feature to enable Java network debugging
2026-02-17 10:19:54 +00:00
Michael B. Gale
ab2580041c
Merge remote-tracking branch 'origin/main' into mbg/features/offline-features
2026-02-17 09:54:34 +00:00
Michael B. Gale
d1689c9307
Use all
2026-02-17 09:53:49 +00:00
Michael B. Gale
147d1495e4
Merge pull request #3484 from github/mbg/cli/force-nightly
...
Add feature for forcing the `nightly` bundle in `dynamic` workflows
2026-02-16 22:37:31 +00:00
Michael B. Gale
3e37216660
Merge branch 'main' into mbg/java/network-debugging
2026-02-16 22:02:36 +00:00
Michael B. Gale
ad5a6c0147
Merge pull request #3482 from github/mbg/release/author-or-merger
...
Release notes: Use author if they are GitHub staff
2026-02-16 18:21:44 +00:00
Michael B. Gale
aee29a19d7
Merge pull request #3473 from github/mbg/start-proxy/cert-gen
...
Improve proxy certificate generation
2026-02-16 17:19:30 +00:00
Michael B. Gale
ac74c2835a
Use init in new check workflow
2026-02-16 17:15:11 +00:00
Michael B. Gale
f8c75d3f32
Change diagnostic level to note
2026-02-16 17:12:12 +00:00
Michael B. Gale
e315c6fd3b
Add diagnostic when a nightly release is forced
2026-02-16 09:29:32 +00:00
Michael B. Gale
e6a312a771
Allow addNoLanguageDiagnostic to be used without a Config
2026-02-16 09:13:06 +00:00
Michael B. Gale
73f5a29960
Complete JSDoc
2026-02-16 09:07:02 +00:00
Michael B. Gale
8b734d3bc2
Improve variable names and comments
...
Also set default `GITHUB_EVENT_NAME` in `setupActionsVars`
2026-02-16 08:54:19 +00:00
Michael B. Gale
e21e4ca93f
Add debugging options to JAVA_TOOL_OPTIONS when FF is enabled
2026-02-15 18:12:51 +00:00
Michael B. Gale
595ce2dc3e
Add JavaNetworkDebugging feature
2026-02-15 18:04:48 +00:00
Michael B. Gale
a61e3cb9f2
Add integration test
2026-02-15 17:49:10 +00:00
Michael B. Gale
d5f0374a1f
Force nightly bundle when FF is enabled
2026-02-15 17:22:20 +00:00
Michael B. Gale
466a4f00eb
Add unit test for tools: nightly
2026-02-15 17:19:12 +00:00
Michael B. Gale
817d568ca0
Improve docs in setup-codeql
2026-02-15 16:21:03 +00:00
Michael B. Gale
34d43db4c6
Add ForceNightly feature
2026-02-15 16:10:53 +00:00
Michael B. Gale
db834c9e1d
Use OfflineFeatures when !supportsFeatureFlags as well
2026-02-15 16:03:48 +00:00
Michael B. Gale
7af50a43c1
Restore test improvements from previous PR
2026-02-15 15:57:02 +00:00
Michael B. Gale
60dee3dbd3
Log when using OfflineFeatures for CCR
2026-02-15 15:55:03 +00:00
Michael B. Gale
0874cf9f8b
Change FFs not supported log message
2026-02-15 15:51:06 +00:00
Michael B. Gale
bc76ceafaf
Add test to check that OfflineFeatures doesn't use the API client
2026-02-15 15:40:23 +00:00
Michael B. Gale
377300bcda
Add mockCCR helper to testing-utils
2026-02-15 15:40:23 +00:00
Michael B. Gale
ee8360df59
Move FF test utils out of main file
2026-02-15 15:40:23 +00:00
Michael B. Gale
9dcfdf2c9c
Return OfflineFeatures for CCR
2026-02-15 15:40:22 +00:00
Michael B. Gale
2c9bc45d46
Abstract over FeatureEnablement implementations with initFeatures
2026-02-15 15:40:21 +00:00
Michael B. Gale
368f322a09
Add OfflineFeatures class
2026-02-15 15:40:20 +00:00
Michael B. Gale
5283c3ba5a
Move getDefaultCliVersion out of GitHubFeatureFlags
...
It doesn't need to be in there since it doesn't depend on the API itself and call `getDefaultCliVersionFromFlags` directly
2026-02-15 15:40:19 +00:00
Michael B. Gale
ea1a400e13
Revert "Merge pull request #3476 from github/henrymercer/retry-auth-errors"
...
This reverts commit 9658e23e5b , reversing
changes made to 2d6b98c7cf .
2026-02-15 15:39:04 +00:00
Michael B. Gale
248d7971c2
Remove superfluous try/catch
2026-02-15 15:23:38 +00:00
Michael B. Gale
64940fad4a
Use author if they are GitHub staff
2026-02-13 15:10:39 +00:00
Henry Mercer
ef618feace
Merge pull request #3480 from github/mergeback/v4.32.3-to-main-9e907b5e
...
Mergeback v4.32.3 refs/heads/releases/v4 into main
2026-02-13 12:21:19 +00:00
github-actions[bot]
6bddc7956d
Rebuild
2026-02-13 12:01:09 +00:00
github-actions[bot]
01fcdceb89
Update changelog and version after v4.32.3
2026-02-13 11:52:49 +00:00
Henry Mercer
9e907b5e64
Merge pull request #3479 from github/update-v4.32.3-4bf6fa4e2
...
Merge main into releases/v4
2026-02-13 11:50:53 +00:00
github-actions[bot]
1814c9fbfd
Update changelog for v4.32.3
2026-02-13 11:17:52 +00:00
Henry Mercer
4bf6fa4e2d
Merge pull request #3478 from github/mbg/changelog/add-connection-test-entry
...
Add changelog entry for #3466
2026-02-13 11:12:32 +00:00
Henry Mercer
9658e23e5b
Merge pull request #3476 from github/henrymercer/retry-auth-errors
...
Avoid requesting features in CCR
2026-02-13 11:11:50 +00:00
Michael B. Gale
e1933c66bd
Find all missing messages in checkExpectedLogMessages
2026-02-12 23:22:33 +00:00
Michael B. Gale
edf36092cf
Add RecordingLogger that keeps track of groups
2026-02-12 23:21:58 +00:00
Michael B. Gale
15a3d32df0
Extend uploadPayload tests to all analysis kinds
2026-02-12 22:28:27 +00:00
Michael B. Gale
9835994414
CSRA category does not need to be adjusted
2026-02-12 20:16:22 +00:00
Michael B. Gale
0ce6420f8e
Validate CODEQL_ACTION_CSRA_ASSESSMENT_ID value
2026-02-12 20:15:18 +00:00
Michael B. Gale
be75dd92ea
Add changelog entry for #3466
2026-02-12 19:40:23 +00:00
Henry Mercer
05bca54402
Apply suggestion from @Copilot
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-12 17:37:10 +00:00
Michael B. Gale
2d6b98c7cf
Merge pull request #3475 from github/henrymercer/retry-auth-errors
...
Retry API authentication errors since these can be transient
2026-02-12 17:04:05 +00:00
Henry Mercer
876cecb383
Avoid requesting features in CCR
2026-02-12 16:53:19 +00:00
Henry Mercer
43b46a19be
Retry API authentication errors since these can be transient
2026-02-12 16:19:04 +00:00
Michael B. Gale
8ad4b6ec58
Merge pull request #3472 from github/dependabot/github_actions/dot-github/workflows/actions-minor-299c02fd34
...
Bump ruby/setup-ruby from 1.286.0 to 1.288.0 in /.github/workflows in the actions-minor group across 1 directory
2026-02-12 14:00:07 +00:00
Michael B. Gale
4edc7d2e82
Merge pull request #3467 from github/dependabot/npm_and_yarn/npm-minor-5707d09364
...
Bump the npm-minor group with 2 updates
2026-02-12 13:33:11 +00:00
Michael B. Gale
2adcb6464e
Add BasePayload type and derive AssessmentPayload from it
2026-02-12 00:13:22 +00:00
Michael B. Gale
da67096c6f
Change assessment_id to be a number
2026-02-12 00:10:42 +00:00
Michael B. Gale
c48cd247df
Add assessment_id to CSRA payload
2026-02-11 23:56:52 +00:00
Michael B. Gale
0cfcceb4b8
Add transformPayload to AnalysisConfig
2026-02-11 23:56:51 +00:00
Michael B. Gale
cbb92e7ff6
Type the upload payload object
2026-02-11 23:56:51 +00:00
Michael B. Gale
db9346285d
Add csra case to addSarifExtension test
2026-02-11 23:28:38 +00:00
Michael B. Gale
2de76b6faa
Update PR check for csra
2026-02-11 22:46:24 +00:00
Michael B. Gale
6a17f4e258
Update getPrimaryAnalysis* and add test
2026-02-11 22:46:24 +00:00
Michael B. Gale
8cc4d2539b
Remove redundant analysis kind check
2026-02-11 22:14:39 +00:00
Michael B. Gale
406bbfcef1
Update upload-lib tests for CSRA
2026-02-11 22:11:17 +00:00
Michael B. Gale
5132eb53f2
Fix CodeScanning config's sarifPredicate and add test
2026-02-11 22:10:55 +00:00
Michael B. Gale
5b3261bcbf
Enforce that only compatible kinds can be enabled concurrently
2026-02-11 20:14:37 +00:00
Michael B. Gale
9267d8d51e
Add csra analysis kind
2026-02-11 19:48:06 +00:00
Michael B. Gale
bc1164e014
Fix typo in test
2026-02-11 19:35:29 +00:00
Michael B. Gale
7801eda177
Add some basic unit tests
2026-02-11 19:23:35 +00:00
Michael B. Gale
b1d963ed8f
Gate updated cert gen behind FF
2026-02-11 19:23:10 +00:00
Michael B. Gale
d636fb3f63
Move certificate code to its own file
2026-02-11 19:23:09 +00:00
Michael B. Gale
d155ebf27f
Set more extensions
2026-02-11 19:23:09 +00:00
Michael B. Gale
e8f0116911
Explicitly sign certificate with SHA256
2026-02-11 19:23:09 +00:00
Michael B. Gale
713a293090
Set keyUsage
2026-02-11 19:23:08 +00:00
Michael B. Gale
ff33514494
Merge pull request #3466 from github/mbg/start-proxy/test-connections
...
Test connections to private registries in `start-proxy`
2026-02-11 19:19:02 +00:00
Michael B. Gale
efb92e2714
Skip checks for non-URLs for now
2026-02-11 18:02:24 +00:00
github-actions[bot]
d73644591f
Rebuild
2026-02-11 18:01:35 +00:00
dependabot[bot]
41d2cc39b6
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.286.0 to 1.288.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/90be1154f987f4dc0fe0dd0feedac9e473aa4ba8...09a7688d3b55cf0e976497ff046b70949eeaccfd )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.288.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-11 17:59:56 +00:00
github-actions[bot]
be578c7735
Rebuild
2026-02-11 17:54:50 +00:00
dependabot[bot]
fa6e24cf12
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@eslint/compat` from 2.0.1 to 2.0.2
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.2/packages/compat )
Updates `eslint-plugin-jsdoc` from 62.4.1 to 62.5.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.4.1...v62.5.0 )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-11 17:53:12 +00:00
Michael B. Gale
2b5b614c85
Add timeout event handler
2026-02-11 17:50:44 +00:00
Michael B. Gale
555ee17b0b
Remove unused logger in NetworkReachabilityBackend
2026-02-11 17:46:33 +00:00
Michael B. Gale
e114998dda
Add test for missing type
2026-02-11 17:15:45 +00:00
Michael B. Gale
bd36637537
Require validated Credential for credentialToStr
2026-02-11 17:13:01 +00:00
Michael B. Gale
4d0bec12bf
Rename types
2026-02-11 17:10:39 +00:00
Michael B. Gale
0387f55b70
Fix outdated comment
2026-02-11 16:49:07 +00:00
Michael B. Gale
27b3b6586d
Remove unnecessary test assertions
2026-02-11 16:47:57 +00:00
Michael B. Gale
c4b0f60beb
Remove superfluous error handling details
2026-02-10 17:15:03 +00:00
Michael B. Gale
51357000d2
Add a 5s timeout to requests
2026-02-10 17:09:49 +00:00
Michael B. Gale
4d44b570d2
Type that registries must have either an url or a host
2026-02-10 17:05:44 +00:00
Michael B. Gale
700fc11b44
Add missing else
2026-02-10 16:21:07 +00:00
Michael B. Gale
9f2f6d0d2e
Remove superflous log message
2026-02-10 16:13:23 +00:00
Michael B. Gale
01ee641f14
Test connections to registries, if FF is enabled
2026-02-10 15:37:45 +00:00
Michael B. Gale
c7eff3f0b1
Add StartProxyConnectionChecks feature
2026-02-10 14:57:16 +00:00
Michael B. Gale
c4717c9c74
Add ProxyInfo type and return from startProxy
2026-02-10 14:56:24 +00:00
Michael B. Gale
b030333651
Add explicit dependency on https-proxy-agent
2026-02-10 14:53:56 +00:00
Michael B. Gale
70eae154c6
Break up Credential type into two interfaces
2026-02-09 17:36:08 +00:00
Michael B. Gale
93302bc63a
Move Credential type
2026-02-09 17:32:48 +00:00
Michael B. Gale
310177a1fb
Merge branch 'main' into mbg/start-proxy/test-connections
2026-02-09 17:27:05 +00:00
Henry Mercer
b13d724d35
Merge pull request #3462 from github/mergeback/v4.32.2-to-main-45cbd0c6
...
Mergeback v4.32.2 refs/heads/releases/v4 into main
2026-02-06 11:33:23 +00:00
github-actions[bot]
4b8e16f54f
Rebuild
2026-02-06 11:00:39 +00:00
github-actions[bot]
481be99883
Merge remote-tracking branch 'origin/main' into mergeback/v4.32.2-to-main-45cbd0c6
2026-02-06 10:59:51 +00:00
Michael B. Gale
9b3a0d2c26
Merge pull request #3464 from github/mbg/disable-ts-unused-checks
...
Disable TypeScript `noUnusedLocals` and `noUnusedParameters` options, already covered by eslint
2026-02-06 10:59:44 +00:00
Michael B. Gale
d2901f5537
Make FFs available in start-proxy action
2026-02-06 10:43:36 +00:00
Michael B. Gale
46c411a7f4
Disable noUnusedLocals and noUnusedParameters
2026-02-06 00:14:12 +00:00
github-actions[bot]
5a82333186
Update changelog and version after v4.32.2
2026-02-05 17:09:49 +00:00
Henry Mercer
45cbd0c69e
Merge pull request #3461 from github/update-v4.32.2-7aee93297
...
Merge main into releases/v4
2026-02-05 17:07:58 +00:00
github-actions[bot]
cb528be87e
Update changelog for v4.32.2
2026-02-05 16:29:51 +00:00
Henry Mercer
7aee932974
Merge pull request #3460 from github/update-bundle/codeql-bundle-v2.24.1
...
Update default bundle to 2.24.1
2026-02-05 15:52:29 +00:00
Henry Mercer
b5f028a984
Merge pull request #3457 from github/dependabot/npm_and_yarn/npm-minor-4c1fc3d0aa
...
Bump the npm-minor group across 1 directory with 4 updates
2026-02-05 15:47:13 +00:00
Henry Mercer
9702c27ab9
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-4c1fc3d0aa
2026-02-05 15:18:18 +00:00
github-actions[bot]
c36c94846f
Add changelog note
2026-02-05 15:16:32 +00:00
github-actions[bot]
3d0331896c
Update default bundle to codeql-bundle-v2.24.1
2026-02-05 15:16:22 +00:00
Henry Mercer
77591e2c4a
Merge pull request #3459 from github/copilot/fix-github-actions-workflow-again
...
Fix `git merge --continue` missing --no-edit in Rebuild workflow
2026-02-05 15:00:59 +00:00
copilot-swe-agent[bot]
7a44a9db3f
Fix Rebuild Action workflow by adding --no-edit flag to git merge --continue
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2026-02-04 21:50:17 +00:00
copilot-swe-agent[bot]
e2ac371513
Initial plan
2026-02-04 21:48:30 +00:00
Michael B. Gale
7deb0a15d3
Merge pull request #3444 from github/mbg/start-proxy/error-types
...
Report some types of errors in `start-proxy` status reports
2026-02-04 19:12:25 +00:00
github-actions[bot]
4f6ea84c21
Rebuild
2026-02-04 18:53:07 +00:00
dependabot[bot]
73dbc8364d
Bump the npm-minor group across 1 directory with 4 updates
...
Bumps the npm-minor group with 3 updates in the / directory: [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@actions/github` from 8.0.0 to 8.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
Updates `@typescript-eslint/eslint-plugin` from 8.53.1 to 8.54.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.54.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.53.1 to 8.54.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.54.0/packages/parser )
Updates `eslint-plugin-jsdoc` from 62.3.0 to 62.4.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.3.0...v62.4.1 )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 8.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.54.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.54.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.4.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-04 18:51:26 +00:00
Michael B. Gale
f959778b39
Merge pull request #3451 from github/dependabot/npm_and_yarn/isaacs/brace-expansion-5.0.1
...
Bump @isaacs/brace-expansion from 5.0.0 to 5.0.1
2026-02-04 10:07:23 +00:00
github-actions[bot]
d38ad56358
Rebuild
2026-02-03 19:49:21 +00:00
dependabot[bot]
bc9796e2e0
Bump @isaacs/brace-expansion from 5.0.0 to 5.0.1
...
Bumps @isaacs/brace-expansion from 5.0.0 to 5.0.1.
---
updated-dependencies:
- dependency-name: "@isaacs/brace-expansion"
dependency-version: 5.0.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-03 19:47:47 +00:00
Henry Mercer
ab5b0e3aab
Merge pull request #3450 from github/henrymercer/add-requires-auth
...
Add "Requires authentication" to `wrapApiConfigurationError`
2026-02-02 10:22:51 -08:00
Michael B. Gale
57a47f44df
Improve credentialToStr tests
2026-02-02 18:13:23 +00:00
Michael B. Gale
076d055bee
Improve sendFailedStatusReport tests
2026-02-02 18:09:44 +00:00
Henry Mercer
6d4cd5d744
Add "Requires authentication" to wrapApiConfigurationError
2026-02-02 18:02:11 +00:00
Michael B. Gale
42fb267c1c
Don't store error message in StartProxyError errors
2026-02-02 17:26:37 +00:00
Michael B. Gale
832a783bd4
Address minor review comments
2026-02-02 17:13:43 +00:00
Michael B. Gale
160e695297
Merge branch 'main' into mbg/start-proxy/error-types
2026-02-02 16:34:35 +00:00
Henry Mercer
8aac4e47ac
Merge pull request #3448 from github/mergeback/v4.32.1-to-main-6bc82e05
...
Mergeback v4.32.1 refs/heads/releases/v4 into main
2026-02-02 07:46:51 -08:00
github-actions[bot]
e8d7df4f04
Rebuild
2026-02-02 15:21:41 +00:00
github-actions[bot]
c1bba77db0
Update changelog and version after v4.32.1
2026-02-02 15:11:38 +00:00
Henry Mercer
6bc82e05fd
Merge pull request #3447 from github/update-v4.32.1-f52cbc830
...
Merge main into releases/v4
2026-02-02 07:09:16 -08:00
Michael B. Gale
42f00f2d33
Add a couple of change notes
2026-02-02 14:32:28 +00:00
github-actions[bot]
cedee6de9f
Update changelog for v4.32.1
2026-02-02 12:13:48 +00:00
Henry Mercer
f52cbc8309
Merge pull request #3445 from github/dependabot/npm_and_yarn/fast-xml-parser-5.3.4
...
Bump fast-xml-parser from 5.3.3 to 5.3.4
2026-02-02 03:49:48 -08:00
Michael B. Gale
c5aaca4bb9
Merge pull request #3446 from github/mbg/ci/pin-node-packages
2026-02-02 10:51:35 +00:00
Michael B. Gale
3e58739c65
Pin @actions/tool-cache@3 in workflows to avoid failures with github-script
2026-02-02 08:18:36 +00:00
github-actions[bot]
a6ccefb47c
Rebuild
2026-01-30 23:00:12 +00:00
dependabot[bot]
0e64858573
Bump fast-xml-parser from 5.3.3 to 5.3.4
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.3 to 5.3.4.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.3...v5.3.4 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-30 22:58:35 +00:00
Michael B. Gale
beb9f533db
Add and use getProxyFilename
2026-01-29 15:19:36 +00:00
Michael B. Gale
a1c70789a3
Use getSafeErrorMessage for unhandled error message
2026-01-29 15:09:21 +00:00
Michael B. Gale
d94d88d717
Add tests for getProxyBinaryPath
2026-01-29 15:06:20 +00:00
Michael B. Gale
a6d296a341
Move getProxyBinaryPath to start-proxy module
2026-01-29 14:20:16 +00:00
Michael B. Gale
28f6d316c0
Handle toolcache errors with StartProxyError
2026-01-29 14:16:36 +00:00
Michael B. Gale
1d0f911837
Handle extraction errors with StartProxyError
2026-01-29 13:45:46 +00:00
Michael B. Gale
05bd050f34
Add and use withRecordingLoggerAsync
2026-01-29 13:44:10 +00:00
Michael B. Gale
325a3a2ae3
Add wrapFailureTest test macro
2026-01-29 13:34:19 +00:00
Michael B. Gale
6394750070
Add test for sendFailedStatusReport
2026-01-29 13:19:37 +00:00
Michael B. Gale
f1588cde0c
Add StartProxyError for status-report-safe errors, and use for proxy download
2026-01-29 12:38:04 +00:00
Henry Mercer
f985be5b50
Merge pull request #3443 from github/dependabot/npm_and_yarn/tar-7.5.7
...
Bump tar from 7.5.6 to 7.5.7
2026-01-29 03:00:35 -08:00
Michael B. Gale
4dcc8a9cdc
Move failed status report code into sendFailedStatusReport
2026-01-29 10:28:55 +00:00
Michael B. Gale
fbe3ae9de8
Move sendSuccessStatusReport to start-proxy module
2026-01-29 10:20:59 +00:00
Michael B. Gale
2a384c1c14
Move credentialToStr and add tests
2026-01-29 10:07:51 +00:00
dependabot[bot]
0c8e06dfb2
Bump tar from 7.5.6 to 7.5.7
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.5.6 to 7.5.7.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.6...v7.5.7 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-28 19:01:18 +00:00
Henry Mercer
b2ff80ddac
Merge pull request #3440 from github/dependabot/npm_and_yarn/npm-minor-6271c457c1
...
Bump the npm-minor group with 7 updates
2026-01-28 10:59:57 -08:00
github-actions[bot]
48f3548141
Rebuild
2026-01-28 17:55:06 +00:00
dependabot[bot]
800dfbe5e1
Bump the npm-minor group with 7 updates
...
Bumps the npm-minor group with 7 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact ) | `5.0.2` | `5.0.3` |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `5.0.3` | `5.0.5` |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core ) | `2.0.2` | `2.0.3` |
| [@actions/glob](https://github.com/actions/toolkit/tree/HEAD/packages/glob ) | `0.5.0` | `0.5.1` |
| [@actions/http-client](https://github.com/actions/toolkit/tree/HEAD/packages/http-client ) | `3.0.1` | `3.0.2` |
| [@actions/tool-cache](https://github.com/actions/toolkit/tree/HEAD/packages/tool-cache ) | `3.0.0` | `3.0.1` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.2.0` | `62.3.0` |
Updates `@actions/artifact` from 5.0.2 to 5.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/artifact )
Updates `@actions/cache` from 5.0.3 to 5.0.5
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@actions/core` from 2.0.2 to 2.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core )
Updates `@actions/glob` from 0.5.0 to 0.5.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/glob/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/glob )
Updates `@actions/http-client` from 3.0.1 to 3.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/http-client/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/http-client )
Updates `@actions/tool-cache` from 3.0.0 to 3.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/tool-cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/tool-cache )
Updates `eslint-plugin-jsdoc` from 62.2.0 to 62.3.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.2.0...v62.3.0 )
---
updated-dependencies:
- dependency-name: "@actions/artifact"
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/cache"
dependency-version: 5.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/core"
dependency-version: 2.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/glob"
dependency-version: 0.5.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/http-client"
dependency-version: 3.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/tool-cache"
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.3.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-28 17:53:24 +00:00
Michael B. Gale
1314d3d17e
Merge pull request #3439 from github/mbg/fix-proxy-test
...
Remove `gh` setup from global proxy test
2026-01-28 13:58:28 +00:00
Michael B. Gale
f7f9d3f341
Remove gh setup from global proxy test
2026-01-28 13:35:59 +00:00
Henry Mercer
eb5bd2d0b9
Merge pull request #3421 from github/henrymercer/only-request-properties-for-orgs
...
Tolerate errors loading repository properties
2026-01-28 04:00:31 -08:00
Henry Mercer
9aa0515f67
Update comments
2026-01-28 11:33:06 +00:00
Henry Mercer
0720e13f0b
Log repository owner type explicitly
2026-01-28 11:30:35 +00:00
Henry Mercer
38ba96d2aa
Merge branch 'main' into henrymercer/only-request-properties-for-orgs
2026-01-27 18:28:33 +00:00
Henry Mercer
679da45cc3
Add basic unit tests for Result class
2026-01-27 15:19:17 +00:00
Henry Mercer
d5dd165f8b
Ensure default value is assignable if we have a Failure
2026-01-27 15:18:50 +00:00
Henry Mercer
fbf75ebd7b
Merge branch 'main' into henrymercer/only-request-properties-for-orgs
2026-01-27 15:17:20 +00:00
Henry Mercer
6a50972d16
Introduce addNoLanguageDiagnostic
2026-01-27 15:14:32 +00:00
Henry Mercer
5cb12c41c2
Include "Result" in name
2026-01-27 15:11:48 +00:00
Henry Mercer
e8f487178f
Add some doc for loadRepositoryProperties
2026-01-27 15:11:01 +00:00
Henry Mercer
a0671be58e
Add doc for Result
2026-01-27 15:07:46 +00:00
Henry Mercer
9ea34c5169
Result: Make use of type hint
2026-01-27 15:05:03 +00:00
Henry Mercer
9fda641d8d
Prefer accessing context via @actions/github
2026-01-27 15:00:52 +00:00
Henry Mercer
b126facd4e
Merge pull request #3434 from github/mbg/dependabot/cooldown
...
Add `cooldown` settings for Dependabot
2026-01-27 06:57:30 -08:00
Henry Mercer
835dadecbf
Merge pull request #3420 from github/henrymercer/compute-job-status-if-no-config
...
Simplify computation of job status
2026-01-27 06:51:55 -08:00
Henry Mercer
a02edfe319
Merge pull request #3424 from github/henrymercer/feature-skip-file-coverage-info-prs
...
Add feature flag to skip computing baseline file coverage information on PRs
2026-01-27 06:49:29 -08:00
Michael B. Gale
173919c9d5
Merge pull request #3436 from github/mbg/rebuild-js-es2022
...
Update JS for ES2022
2026-01-27 14:46:54 +00:00
Henry Mercer
6095dc4d51
Merge branch 'main' into henrymercer/compute-job-status-if-no-config
2026-01-27 14:31:51 +00:00
Henry Mercer
b333fc6f5b
Split up getFinalJobStatus
2026-01-27 14:30:42 +00:00
Henry Mercer
60b658ed10
Update comment
2026-01-27 14:26:31 +00:00
Michael B. Gale
e4e324705e
Update JS
2026-01-27 14:13:28 +00:00
github-actions[bot]
faf7a50b01
Rebuild
2026-01-27 14:13:05 +00:00
Michael B. Gale
2591c2031f
Add cooldown settings for Dependabot
2026-01-27 14:08:27 +00:00
Michael B. Gale
34cae51104
Merge pull request #3422 from github/mbg/start-proxy/warn-if-pat-without-username
...
Warn if a private registry configuration uses a PAT, but has no username
2026-01-27 14:07:06 +00:00
Henry Mercer
9308bcd6bb
Add unit tests for file coverage enablement
2026-01-27 13:55:22 +00:00
Michael B. Gale
fa9b76ac37
Merge pull request #3432 from github/dependabot/npm_and_yarn/actions/github-8.0.0
...
Bump @actions/github from 7.0.0 to 8.0.0
2026-01-27 13:49:13 +00:00
Michael B. Gale
6059a66dec
Remove @octokit/plugin-retry from Dependabot ignore list
2026-01-27 13:22:57 +00:00
Michael B. Gale
cb4fc9e8db
Update @octokit/plugin-retry
2026-01-27 13:10:33 +00:00
Michael B. Gale
be82188a2a
Bump ES version, required by newer @octokit/request-error
2026-01-27 13:09:39 +00:00
Michael B. Gale
c656a11252
Use .match in isAuthToken and add repeated call to test
2026-01-27 11:45:03 +00:00
Michael B. Gale
bd9f639752
Merge pull request #3433 from github/dependabot/github_actions/dot-github/workflows/actions-minor-69d791f5c9
...
Bump ruby/setup-ruby from 1.284.0 to 1.286.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-27 11:31:46 +00:00
Michael B. Gale
0a0c3a2e09
Merge branch 'main' into mbg/start-proxy/warn-if-pat-without-username
2026-01-27 11:27:31 +00:00
github-actions[bot]
46a8de52fc
Rebuild
2026-01-26 19:47:52 +00:00
dependabot[bot]
f8cea24201
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.284.0 to 1.286.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/80740b3b13bf9857e28854481ca95a84e78a2bdf...90be1154f987f4dc0fe0dd0feedac9e473aa4ba8 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.286.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-26 19:46:17 +00:00
dependabot[bot]
b1993d9139
Bump @actions/github from 7.0.0 to 8.0.0
...
Bumps [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ) from 7.0.0 to 8.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 8.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-26 19:40:04 +00:00
Henry Mercer
ee1e1399e2
Merge pull request #3429 from github/mergeback/v4.32.0-to-main-b20883b0
...
Mergeback v4.32.0 refs/heads/releases/v4 into main
2026-01-26 11:18:48 -08:00
github-actions[bot]
e7d3af2e1e
Rebuild
2026-01-26 18:54:35 +00:00
github-actions[bot]
13a6d8be95
Update changelog and version after v4.32.0
2026-01-26 18:39:39 +00:00
Henry Mercer
b20883b0cd
Merge pull request #3428 from github/update-v4.32.0-e3b8227a2
...
Merge main into releases/v4
2026-01-26 10:38:00 -08:00
Henry Mercer
bf20b3e07b
Exclude PR check from feature flag
2026-01-26 18:04:37 +00:00
Henry Mercer
f1aa4f497a
Explain why we ignore extra baseline files options
2026-01-26 18:02:58 +00:00
Henry Mercer
9a55d5bc5f
Improve log message
2026-01-26 18:00:34 +00:00
Henry Mercer
17cd475099
Move to separate function
2026-01-26 17:55:17 +00:00
github-actions[bot]
c9aa45dd0f
Update changelog for v4.32.0
2026-01-26 17:52:31 +00:00
Henry Mercer
e3b8227a28
Merge pull request #3427 from github/henrymercer/bump-for-new-minor-series
...
Bump the Action minor version number on new CodeQL minor version series
2026-01-26 09:12:23 -08:00
Henry Mercer
8a01181ce2
Compare minor version number
...
This deals with the case that we skip `x.y.0` and go straight to `x.y.1`.
2026-01-26 16:50:11 +00:00
Henry Mercer
80e142568f
Bump minor version for CLI v2.24.0
2026-01-26 15:46:05 +00:00
Henry Mercer
b748848f27
Bump the Action minor version number on new CodeQL minor version series
2026-01-26 15:45:24 +00:00
Nick Rolfe
5e767eff5a
Merge pull request #3425 from github/update-bundle/codeql-bundle-v2.24.0
...
Update default bundle to 2.24.0
2026-01-26 04:40:17 -08:00
github-actions[bot]
9752869470
Add changelog note
2026-01-26 12:16:22 +00:00
github-actions[bot]
c62c214723
Update default bundle to codeql-bundle-v2.24.0
2026-01-26 12:16:14 +00:00
Henry Mercer
18c2cfc765
Indulge caniuse-lite to avoid build warnings
2026-01-26 11:42:13 +00:00
Henry Mercer
1996ca9f5d
Log when file coverage info is disabled
2026-01-26 11:42:13 +00:00
Henry Mercer
12c4c7d0e9
Don't log empty summaries
2026-01-26 11:42:13 +00:00
Michael B. Gale
25a224b808
Merge pull request #3423 from github/mbg/ci/yq-windows
...
Add `installYq` option to `sync.py` and install `yq` directly from GitHub release
2026-01-26 11:23:44 +00:00
Henry Mercer
919e8aaa40
Mention caveat in feature JSDoc
2026-01-26 11:00:04 +00:00
Henry Mercer
4918026b93
Use FF to disable baseline file coverage
2026-01-26 11:00:04 +00:00
Henry Mercer
e8c164b902
Remove unused database print-baseline
2026-01-26 11:00:03 +00:00
Michael B. Gale
3657da1eac
Move yq version into env var and add comment
2026-01-26 10:59:43 +00:00
Michael B. Gale
605d404db0
Install yq directly from GitHub release
2026-01-24 14:09:33 +00:00
Michael B. Gale
efea9cca02
Add installYq option to sync.py and cache downloads
2026-01-24 13:43:15 +00:00
Michael B. Gale
9fccf271ff
Warn if a private registry configuration uses a PAT, but has no username
2026-01-24 13:02:41 +00:00
Michael B. Gale
c12cf8d49a
Move makeTestToken to testing-utils
2026-01-24 12:55:32 +00:00
Michael B. Gale
0fcbec3eec
Add isAuthToken function, with tests
2026-01-24 12:38:14 +00:00
Michael B. Gale
0ae8b05d08
Extend unit tests to cover all token types
2026-01-24 12:25:40 +00:00
Michael B. Gale
49cdf744d9
Use enum for token types
2026-01-24 11:58:10 +00:00
Michael B. Gale
aac4202424
Add fine-grained tokens to GITHUB_TOKEN_PATTERNS
2026-01-24 11:52:53 +00:00
Henry Mercer
e7ece62b96
Add feature flag to skip file coverage information on PRs
2026-01-23 18:41:24 +00:00
Henry Mercer
d9e374ef85
Tolerate failures loading repository properties
2026-01-23 17:51:41 +00:00
Henry Mercer
f4b47e7013
Add result type
2026-01-23 17:51:02 +00:00
Henry Mercer
4e14537b54
Improve logging when no known repository properties found
2026-01-23 17:29:15 +00:00
Henry Mercer
e142eee9b4
Only load repository properties for repos owned by orgs
2026-01-23 17:20:30 +00:00
Henry Mercer
dcd1b12beb
Simplify computation of job status
...
- Move it out of the failed SARIF reporting so we compute the job status
whether or not we have a CodeQL config.
- Add comments to clarify what happens in the case that the CodeQL
config is absent.
2026-01-23 17:07:21 +00:00
Michael B. Gale
55252c7a3a
Merge pull request #3418 from github/mergeback/v4.31.11-to-main-19b2f06d
...
Mergeback v4.31.11 refs/heads/releases/v4 into main
2026-01-23 15:26:56 +00:00
github-actions[bot]
7381f9750d
Rebuild
2026-01-23 14:48:27 +00:00
github-actions[bot]
6e162a0930
Update changelog and version after v4.31.11
2026-01-23 13:53:17 +00:00
Michael B. Gale
19b2f06db2
Merge pull request #3417 from github/update-v4.31.11-1601acf88
...
Merge main into releases/v4
2026-01-23 13:51:38 +00:00
Michael B. Gale
03afde035d
Add noteworthy changes to changelog
2026-01-23 13:24:31 +00:00
github-actions[bot]
9469107033
Update changelog for v4.31.11
2026-01-23 12:58:42 +00:00
Henry Mercer
1601acf88b
Merge pull request #3415 from github/henrymercer/address-telemetry-gap
...
Address missing telemetry at the start of Actions
2026-01-23 04:51:05 -08:00
Henry Mercer
fba78720ca
Address review comments
2026-01-23 12:22:31 +00:00
Henry Mercer
a8dd5ab7a4
Merge pull request #3414 from github/dependabot/npm_and_yarn/lodash-4.17.23
...
Bump lodash from 4.17.21 to 4.17.23
2026-01-23 02:55:45 -08:00
Henry Mercer
28bfb7b7b5
Omit error from start-proxy Action
2026-01-23 10:42:42 +00:00
Henry Mercer
91f3460006
Throw if in test mode
2026-01-23 10:40:51 +00:00
Henry Mercer
edebb7861e
Differentiate unhandled errors in telemetry
2026-01-23 10:39:51 +00:00
Henry Mercer
529c266223
Use getErrorMessage in more places
2026-01-23 10:36:25 +00:00
Henry Mercer
6bd84b6a82
Rename to "unhandled"
2026-01-23 10:34:45 +00:00
Henry Mercer
5e98e18a17
Merge pull request #3410 from github/dependabot/npm_and_yarn/tar-7.5.6
...
Bump tar from 7.4.3 to 7.5.6
2026-01-22 05:15:39 -08:00
Henry Mercer
229e0cd749
Add catch-all error reporting for errors that slip through run
2026-01-22 13:14:53 +00:00
Henry Mercer
14bd76753f
Add reminder to minimise code outside try/catch
2026-01-22 11:31:17 +00:00
Henry Mercer
b715292b74
Move config saving within try-catch
2026-01-22 11:27:46 +00:00
Henry Mercer
7c72e12ecb
Expand try-catch to cover more of Actions
2026-01-22 10:46:05 +00:00
dependabot[bot]
b5bb69ad4b
Bump lodash from 4.17.21 to 4.17.23
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 00:26:32 +00:00
Michael B. Gale
1c4c0b36be
Merge pull request #3318 from github/mbg/ignore-generated
2026-01-21 14:43:55 +00:00
Michael B. Gale
bc75091173
Add empty lines to test cases
2026-01-21 13:29:15 +00:00
Michael B. Gale
dc2428c879
Trim whitespace/remove empty lines
2026-01-21 13:27:47 +00:00
Michael B. Gale
cb2dd2ed29
Add telemetry diagnostic
2026-01-21 13:22:01 +00:00
Michael B. Gale
9e2fa7419d
Use joinAtMost for log message
2026-01-21 13:12:28 +00:00
Michael B. Gale
6a02be43ee
Add joinAtMost utility function
2026-01-21 13:10:50 +00:00
dependabot[bot]
e19f95e73f
Bump tar from 7.4.3 to 7.5.6
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.4.3 to 7.5.6.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.4.3...v7.5.6 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-21 12:56:03 +00:00
Michael B. Gale
4325937dc6
Merge pull request #3405 from github/mbg/ci/fix-concurrency-ignores-inputs
...
Improve `concurrency` settings for PR checks
2026-01-21 12:54:48 +00:00
Michael B. Gale
d5b3d42fd4
Inline EnvVar.ANALYSIS_KEY in getAnalysisKey
2026-01-21 12:52:24 +00:00
Michael B. Gale
417a8c2176
Merge branch 'main' into mbg/ignore-generated
2026-01-21 12:44:35 +00:00
Michael B. Gale
fa03060d60
Update new CCR workflow
2026-01-21 12:33:08 +00:00
Michael B. Gale
f58cb3d53e
Improve comment for concurrency settings
2026-01-21 12:33:02 +00:00
Michael B. Gale
51975ff7b7
Merge branch 'main' into mbg/ci/fix-concurrency-ignores-inputs
2026-01-21 12:28:09 +00:00
Henry Mercer
32d41f36fe
Merge pull request #3403 from github/henrymercer/abridge-release-notes
...
Abridge release notes
2026-01-20 06:26:19 -08:00
Michael B. Gale
d60bbdfd70
Merge pull request #3409 from github/mbg/start-proxy/make-unique-artifact
...
Ensure that proxy log artifacts have unique names
2026-01-20 14:24:28 +00:00
Henry Mercer
93a99bf571
Merge pull request #3404 from github/henrymercer/include-oids-in-bundle
...
Include base database OIDs when bundling database
2026-01-20 06:13:13 -08:00
Michael B. Gale
dce83e1c1e
Merge pull request #3408 from github/mbg/add-ccr-check
...
Add basic PR check with CCR-like environment
2026-01-20 14:04:13 +00:00
Henry Mercer
ec4eda1b42
Just link the release notes
2026-01-20 14:00:21 +00:00
Michael B. Gale
1df1c9f85d
Include expected suffixes in test
2026-01-20 13:55:25 +00:00
Michael B. Gale
9483bd5a7f
Check that matrixObject is an object
2026-01-20 13:51:59 +00:00
Henry Mercer
b880a1a7bd
Improve comment
2026-01-20 13:45:41 +00:00
Henry Mercer
5ac04769eb
Rename argument
2026-01-20 13:39:43 +00:00
Michael B. Gale
1ac62705ed
Change log message to warning
2026-01-20 13:25:25 +00:00
Michael B. Gale
9a57e78a04
Improving sorting of matrix keys
2026-01-20 13:21:16 +00:00
Michael B. Gale
7e96d45489
Use uploadArtifacts for start-proxy post action
2026-01-20 12:52:35 +00:00
Michael B. Gale
13eb1818b9
Refactor generic part of uploadDebugArtifacts into uploadArtifacts
2026-01-20 12:49:19 +00:00
Michael B. Gale
f950f7f442
Add unit tests for getArtifactSuffix
2026-01-20 12:41:35 +00:00
Michael B. Gale
69173ea009
Refactor artifact suffix computation into getArtifactSuffix
2026-01-20 12:41:22 +00:00
Michael B. Gale
a886c30690
Add basic PR check with CCR-like environment
2026-01-20 12:19:29 +00:00
Michael B. Gale
044ff10e29
Merge pull request #3406 from github/dependabot/npm_and_yarn/npm-minor-e76a272df4
...
Bump the npm-minor group with 4 updates
2026-01-20 11:18:45 +00:00
Michael B. Gale
84edfc05fa
Merge pull request #3407 from github/dependabot/github_actions/dot-github/workflows/actions-minor-ec7bddb364
...
Bump ruby/setup-ruby from 1.281.0 to 1.284.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-20 11:16:49 +00:00
github-actions[bot]
df0cc0ca39
Rebuild
2026-01-19 19:40:50 +00:00
dependabot[bot]
24f1cbdafb
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.281.0 to 1.284.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/675dd7ba1b06c8786a1480d89c384f5620a42647...80740b3b13bf9857e28854481ca95a84e78a2bdf )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.284.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 19:39:18 +00:00
github-actions[bot]
8881a4160f
Rebuild
2026-01-19 19:34:41 +00:00
dependabot[bot]
1191c09db6
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@actions/cache` from 5.0.2 to 5.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@typescript-eslint/eslint-plugin` from 8.53.0 to 8.53.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.53.0 to 8.53.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.1/packages/parser )
Updates `eslint-plugin-jsdoc` from 62.0.0 to 62.2.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.0.0...v62.2.0 )
---
updated-dependencies:
- dependency-name: "@actions/cache"
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.53.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.53.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.2.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 19:33:09 +00:00
Michael B. Gale
90f4ffcc7e
Include input values in concurrency groups
2026-01-19 18:53:51 +00:00
Michael B. Gale
03e3f60d99
Explicitly set cancel-in-progress to false
2026-01-19 18:51:44 +00:00
Michael B. Gale
778f83ff16
Use hard-coded concurrency group names instead of github.workflow
...
Since `github.workflow` will be the caller's name for `workflow_call` events
2026-01-19 18:43:17 +00:00
Henry Mercer
75716abfa3
Merge branch 'main' into henrymercer/include-oids-in-bundle
2026-01-19 18:11:11 +00:00
Henry Mercer
ebffc48bf5
Include /tag in bundle release URL
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-19 18:00:34 +00:00
Henry Mercer
d51b375a03
Drop unneeded version tag argument
2026-01-19 17:59:04 +00:00
Henry Mercer
3a7caafd73
Update comment
2026-01-19 17:57:59 +00:00
Henry Mercer
4d4ae1fbe8
Abridge release notes for Action GH release
2026-01-19 17:55:06 +00:00
Henry Mercer
064fafeb49
Link CLI/language pack notes from new bundle changelog
2026-01-19 17:51:27 +00:00
Henry Mercer
a7783c507b
Make bundle changelog script executable
...
For local testing
2026-01-19 17:49:14 +00:00
Henry Mercer
0d94aab48f
Make prepare changelog script executable
...
For local testing
2026-01-19 17:43:45 +00:00
Michael B. Gale
1ec7dd2bc4
Merge pull request #3398 from github/dependabot/npm_and_yarn/actions/github-7.0.0
...
Bump @actions/github from 6.0.1 to 7.0.0
2026-01-19 14:47:09 +00:00
github-actions[bot]
1b4c62b79d
Rebuild
2026-01-19 14:20:47 +00:00
Michael B. Gale
4bd7556a48
Log when there are no generated files
2026-01-19 14:12:57 +00:00
Michael B. Gale
7beb64218a
Move after Git version check
2026-01-19 14:12:04 +00:00
Michael B. Gale
546ea07303
Use linebreaks
2026-01-19 14:11:11 +00:00
Michael B. Gale
9c3f69d7a3
Add some logging
2026-01-19 14:04:41 +00:00
Michael B. Gale
5f5c095469
Add docs comments for listFiles and getGeneratedFiles
2026-01-19 13:49:42 +00:00
Michael B. Gale
c7d0b92094
Drop isDynamic check from isCCR
...
The analysis key already tells us this under normal conditions
2026-01-19 13:47:50 +00:00
Michael B. Gale
055e6b6f36
Add EnvVar constant for analysis key
2026-01-19 13:41:38 +00:00
Michael B. Gale
644e2b9bd7
Restore condition for enablement
2026-01-19 13:19:48 +00:00
Michael B. Gale
02b2c55c51
Use stdin for files to query attributes of
2026-01-19 13:18:48 +00:00
Michael B. Gale
1782089bde
Merge branch 'main' into mbg/ignore-generated
2026-01-19 13:09:15 +00:00
dependabot[bot]
6c5e0ea335
Bump @actions/github from 6.0.1 to 7.0.0
...
Bumps [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ) from 6.0.1 to 7.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 13:05:53 +00:00
Michael B. Gale
c99e493099
Merge pull request #3399 from github/dependabot/npm_and_yarn/eslint-plugin-jsdoc-62.0.0
...
Bump eslint-plugin-jsdoc from 61.5.0 to 62.0.0
2026-01-19 13:04:30 +00:00
Michael B. Gale
f687ebf1c9
Merge pull request #3397 from github/dependabot/npm_and_yarn/npm-minor-70139cb906
...
Bump the npm-minor group with 7 updates
2026-01-19 11:46:30 +00:00
Michael B. Gale
070e2a5f21
Merge pull request #3400 from github/dependabot/npm_and_yarn/actions/tool-cache-3.0.0
...
Bump @actions/tool-cache from 2.0.2 to 3.0.0
2026-01-19 10:49:50 +00:00
Michael B. Gale
fb650c22f9
Merge pull request #3401 from github/dependabot/github_actions/dot-github/workflows/actions-minor-c79fd65a81
...
Bump ruby/setup-ruby from 1.278.0 to 1.281.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-16 18:03:34 +00:00
github-actions[bot]
21c5dc0f33
Rebuild
2026-01-12 22:02:32 +00:00
dependabot[bot]
bdabb8f1bc
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.278.0 to 1.281.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/4c24fa5ec04b2e79eb40571b1cee2a0d2b705771...675dd7ba1b06c8786a1480d89c384f5620a42647 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.281.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:59:39 +00:00
github-actions[bot]
39105f35da
Rebuild
2026-01-12 21:55:29 +00:00
github-actions[bot]
dc7e2ff87d
Rebuild
2026-01-12 21:55:24 +00:00
github-actions[bot]
642eca368e
Rebuild
2026-01-12 21:54:58 +00:00
dependabot[bot]
e20d24fb28
Bump @actions/tool-cache from 2.0.2 to 3.0.0
...
Bumps [@actions/tool-cache](https://github.com/actions/toolkit/tree/HEAD/packages/tool-cache ) from 2.0.2 to 3.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/tool-cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/tool-cache )
---
updated-dependencies:
- dependency-name: "@actions/tool-cache"
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:57 +00:00
dependabot[bot]
f301585a01
Bump eslint-plugin-jsdoc from 61.5.0 to 62.0.0
...
Bumps [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) from 61.5.0 to 62.0.0.
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.5.0...v62.0.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:52 +00:00
dependabot[bot]
c8914af920
Bump the npm-minor group with 7 updates
...
Bumps the npm-minor group with 7 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact ) | `5.0.1` | `5.0.2` |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `5.0.1` | `5.0.2` |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core ) | `2.0.1` | `2.0.2` |
| [@actions/http-client](https://github.com/actions/toolkit/tree/HEAD/packages/http-client ) | `3.0.0` | `3.0.1` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `2.0.0` | `2.0.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.52.0` | `8.53.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.52.0` | `8.53.0` |
Updates `@actions/artifact` from 5.0.1 to 5.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/artifact )
Updates `@actions/cache` from 5.0.1 to 5.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@actions/core` from 2.0.1 to 2.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core )
Updates `@actions/http-client` from 3.0.0 to 3.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/http-client/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/http-client )
Updates `@eslint/compat` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.1/packages/compat )
Updates `@typescript-eslint/eslint-plugin` from 8.52.0 to 8.53.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.52.0 to 8.53.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@actions/artifact"
dependency-version: 5.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/cache"
dependency-version: 5.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/core"
dependency-version: 2.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/http-client"
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@eslint/compat"
dependency-version: 2.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.53.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.53.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:28 +00:00
Ian Lynagh
a2d9de63c2
Merge pull request #3395 from github/mergeback/v4.31.10-to-main-cdefb33c
...
Mergeback v4.31.10 refs/heads/releases/v4 into main
2026-01-12 15:23:02 +00:00
github-actions[bot]
4672d7807f
Rebuild
2026-01-12 14:39:48 +00:00
github-actions[bot]
be6e3c4480
Update changelog and version after v4.31.10
2026-01-12 14:34:39 +00:00
Ian Lynagh
cdefb33c0f
Merge pull request #3394 from github/update-v4.31.10-0fa411efd
...
Merge main into releases/v4
2026-01-12 14:32:55 +00:00
github-actions[bot]
cfa77c6b13
Update changelog for v4.31.10
2026-01-12 12:24:26 +00:00
Henry Mercer
79939d8ca5
Copy OIDs from DB cluster to individual DBs
2026-01-09 19:08:36 +00:00
Henry Mercer
d32cd4ddde
Include base database OIDs when bundling database
2026-01-09 18:58:32 +00:00
Henry Mercer
d6efb85cdf
Add tools feature for codeql database bundle --include
2026-01-09 18:50:12 +00:00
Ian Lynagh
0fa411efd0
Merge pull request #3393 from github/update-bundle/codeql-bundle-v2.23.9
...
Update default bundle to 2.23.9
2026-01-09 17:24:49 +00:00
github-actions[bot]
c284324212
Add changelog note
2026-01-09 16:41:42 +00:00
github-actions[bot]
83e7d0046c
Update default bundle to codeql-bundle-v2.23.9
2026-01-09 16:41:33 +00:00
Henry Mercer
f6a16bef8e
Merge pull request #3391 from github/dependabot/npm_and_yarn/npm-minor-f1cdf520b2
...
Bump the npm-minor group with 2 updates
2026-01-08 15:36:24 +00:00
github-actions[bot]
c1f5f1a8b5
Rebuild
2026-01-07 16:07:35 +00:00
dependabot[bot]
1805d8d0a4
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@typescript-eslint/eslint-plugin` from 8.51.0 to 8.52.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.52.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.51.0 to 8.52.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.52.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.52.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.52.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-07 16:05:56 +00:00
Henry Mercer
b2951d2a1e
Merge pull request #3353 from github/kaspersv/bump-min-cli-v-for-overlay
...
Overlay: Bump minimum CLI version for overlay
2026-01-06 16:44:27 +00:00
Henry Mercer
41448d92b9
Merge pull request #3287 from github/henrymercer/generate-mergeback-last
...
Open mergeback PR last
2026-01-06 12:16:00 +00:00
Michael B. Gale
a7fe4ffe40
Merge pull request #3387 from github/dependabot/npm_and_yarn/npm-minor-59ea988ea1
...
Bump the npm-minor group with 2 updates
2026-01-06 11:29:09 +00:00
Michael B. Gale
fd448f79eb
Merge pull request #3388 from github/dependabot/github_actions/dot-github/workflows/actions-minor-a0e46cd791
...
Bump ruby/setup-ruby from 1.275.0 to 1.278.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-05 21:28:14 +00:00
github-actions[bot]
079ca18961
Rebuild
2026-01-05 17:16:59 +00:00
github-actions[bot]
80dbba139d
Merge remote-tracking branch 'origin/main' into dependabot/github_actions/dot-github/workflows/actions-minor-a0e46cd791
2026-01-05 17:16:09 +00:00
dependabot[bot]
7edf2bd491
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.275.0 to 1.278.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/d354de180d0c9e813cfddfcbdc079945d4be589b...4c24fa5ec04b2e79eb40571b1cee2a0d2b705771 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.278.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-05 17:15:28 +00:00
Henry Mercer
db726913e9
Merge pull request #3386 from github/henrymercer/codeql-ff-improve-safety
...
Introduce a type-level check that CodeQL is passed during feature flag lookup if it is needed
2026-01-05 17:13:26 +00:00
github-actions[bot]
c327260b2b
Rebuild
2026-01-05 17:03:30 +00:00
dependabot[bot]
ce7b1f8663
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@typescript-eslint/eslint-plugin` from 8.50.0 to 8.51.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.51.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.50.0 to 8.51.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.51.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.51.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.51.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-05 17:01:55 +00:00
Henry Mercer
855c0888b6
Improve test for throwing when no CodeQL provided
2026-01-05 16:38:04 +00:00
Henry Mercer
ec1705eb43
Rebuild now type error fixed in main
2026-01-05 16:23:16 +00:00
Henry Mercer
29ee0e040d
Merge branch 'main' into henrymercer/codeql-ff-improve-safety
2026-01-05 16:22:46 +00:00
Henry Mercer
35d39dfdb3
Introduce type error when CodeQL is needed
2026-01-05 16:22:40 +00:00
Henry Mercer
66bcc86d07
Merge pull request #3385 from github/henrymercer/fix-ff-lookup
...
Fix feature flag lookup when uploading DB
2026-01-05 14:28:10 +00:00
Henry Mercer
44e589b637
Fix feature flag lookup when uploading DB
2026-01-05 14:07:03 +00:00
Henry Mercer
0d648eb4d1
Merge pull request #3380 from github/dependabot/github_actions/dot-github/workflows/actions-minor-b4688f1603
...
Bump ruby/setup-ruby from 1.270.0 to 1.275.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-05 13:44:11 +00:00
Henry Mercer
3fd7db80f0
Merge pull request #3379 from github/dependabot/npm_and_yarn/npm-minor-1607f6c1cd
...
Bump the npm-minor group with 4 updates
2026-01-05 13:41:32 +00:00
github-actions[bot]
6b11018e07
Rebuild
2025-12-22 17:18:17 +00:00
dependabot[bot]
d0d445f91c
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.270.0 to 1.275.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/ac793fdd38cc468a4dd57246fa9d0e868aba9085...d354de180d0c9e813cfddfcbdc079945d4be589b )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.275.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 17:16:43 +00:00
github-actions[bot]
60b2ba310b
Rebuild
2025-12-22 17:03:28 +00:00
dependabot[bot]
709d6de5f3
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ), [esbuild](https://github.com/evanw/esbuild ) and [sinon](https://github.com/sinonjs/sinon ).
Updates `@typescript-eslint/eslint-plugin` from 8.49.0 to 8.50.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.50.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.49.0 to 8.50.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.50.0/packages/parser )
Updates `esbuild` from 0.27.1 to 0.27.2
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.1...v0.27.2 )
Updates `sinon` from 21.0.0 to 21.0.1
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.0...v21.0.1 )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.50.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.50.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 17:01:51 +00:00
Kasper Svendsen
efbc56d117
Overlay: Bump minimum CLI version for overlay
2025-12-19 11:25:46 +01:00
Henry Mercer
f67ec12472
Merge pull request #3370 from github/copilot/update-overlay-git-version-check
...
Add git version check for overlay analysis enablement
2025-12-18 15:47:40 +00:00
Henry Mercer
3b6fef64d5
Fix import order
2025-12-18 14:39:01 +00:00
Henry Mercer
8b428c0d4c
Use EnvVar
2025-12-18 14:34:50 +00:00
Henry Mercer
034401b281
Merge branch 'main' into copilot/update-overlay-git-version-check
2025-12-18 14:06:01 +00:00
Henry Mercer
95246ce019
Prefer explicit env var to binary accessibility check
2025-12-18 14:05:12 +00:00
Henry Mercer
525b64847a
Merge pull request #3374 from github/henrymercer/scan-debug-artifacts
...
CI: Perform a best-effort scan of the debug artifacts during release validation
2025-12-18 14:00:25 +00:00
Henry Mercer
a7e88a44f8
Only enable overlay for the code scanning suite
2025-12-18 13:06:44 +00:00
Henry Mercer
ff84c6f23c
Improve comment
2025-12-18 13:03:52 +00:00
Henry Mercer
948c7fbf11
Test mode: Tolerate missing git binary
2025-12-18 13:01:00 +00:00
Henry Mercer
cec3cc5782
Trim git version output
2025-12-18 12:52:30 +00:00
Henry Mercer
358a55e232
Throw in test mode if can't compute git version
2025-12-18 12:52:13 +00:00
Henry Mercer
eb823a7a97
Merge pull request #3375 from github/henrymercer/overlay-upload-tools-feature
...
Require tools feature for uploading overlay DBs
2025-12-18 12:43:26 +00:00
Henry Mercer
003ddaeef5
Avoid non-determinism in PR checks due to overlay FFs
2025-12-18 12:35:06 +00:00
Henry Mercer
a2c3c8e3e2
Bump log level for failing to parse git version
2025-12-17 17:28:13 +00:00
Henry Mercer
a13b404670
Record both truncated and full git versions
2025-12-17 17:27:14 +00:00
Henry Mercer
a2917b0733
Check !== undefined rather than truthiness
2025-12-17 16:27:36 +00:00
Henry Mercer
67e683bd1b
Report bundled DB size in error if known
2025-12-17 16:02:55 +00:00
Henry Mercer
cb26a026e5
Require tools feature for uploading overlay DBs
2025-12-17 16:02:26 +00:00
Henry Mercer
ac6c41b910
Extract zstd files too
2025-12-17 15:34:12 +00:00
Henry Mercer
056581e05b
Update makeTelemetryDiagnostic doc
2025-12-17 12:15:37 +00:00
Henry Mercer
9c5588d006
Remove unnecessary stub restores
2025-12-17 12:12:04 +00:00
Henry Mercer
3765106c90
Move git version logging to config utils
2025-12-17 12:06:41 +00:00
Henry Mercer
e052dbd57d
Remove caching mechanism
2025-12-17 11:56:23 +00:00
Henry Mercer
7673a2de65
Run testing Action using Node 24
2025-12-17 11:51:34 +00:00
Henry Mercer
32795b3c52
Merge branch 'main' into copilot/update-overlay-git-version-check
2025-12-17 11:49:32 +00:00
Henry Mercer
6b5763e5ee
Skip slow test on Windows
2025-12-17 11:47:39 +00:00
Henry Mercer
3322491022
Bump timeout on Windows
2025-12-17 11:41:55 +00:00
Henry Mercer
6bc6217487
Merge branch 'main' into henrymercer/scan-debug-artifacts
2025-12-17 11:36:38 +00:00
Henry Mercer
faf6d35e7b
Verify using post step
2025-12-17 11:35:26 +00:00
Henry Mercer
3b94cfeb15
Avoid logging each extract call
2025-12-17 11:35:26 +00:00
Henry Mercer
b88acb2f6c
Merge pull request #3359 from github/dependabot/npm_and_yarn/npm-minor-b2e0062778
...
Bump the npm-minor group with 3 updates
2025-12-17 11:04:55 +00:00
Henry Mercer
241948c698
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-b2e0062778
2025-12-17 10:38:55 +00:00
Henry Mercer
da77f9f638
Suppress debug logs for artifact scanner test
2025-12-17 10:25:48 +00:00
Henry Mercer
de172624a1
Slim down test debug artifacts
2025-12-17 10:25:48 +00:00
Henry Mercer
488c1f1959
Add regression test for artifact scanner
2025-12-17 10:25:48 +00:00
Henry Mercer
f2ccf3b4f1
Ensure .gz files are extracted too
2025-12-17 10:25:47 +00:00
Henry Mercer
f28848a66a
Use artifact scanner in debug artifacts PR checks
2025-12-17 10:25:47 +00:00
Henry Mercer
5459b98ca0
Add simple artifact scanner for tests only
2025-12-17 10:25:46 +00:00
Henry Mercer
0c8bfeaf84
Add artifact scanner
2025-12-17 10:25:46 +00:00
Henry Mercer
1fe89fe9cb
Merge pull request #3368 from github/copilot/bump-actions-npm-packages
...
Bump @actions/* npm packages to latest versions
2025-12-17 09:59:27 +00:00
Henry Mercer
6dba00881c
Merge pull request #3372 from github/mergeback/v4.31.9-to-main-5d4e8d1a
...
Mergeback v4.31.9 refs/heads/releases/v4 into main
2025-12-16 19:33:12 +00:00
github-actions[bot]
d4d47c0d3d
Rebuild
2025-12-16 18:56:12 +00:00
github-actions[bot]
6c6e810910
Update changelog and version after v4.31.9
2025-12-16 18:32:18 +00:00
Henry Mercer
5d4e8d1aca
Merge pull request #3371 from github/update-v4.31.9-998798e34
...
Merge main into releases/v4
2025-12-16 18:30:42 +00:00
github-actions[bot]
1dc115f17a
Update changelog for v4.31.9
2025-12-16 17:45:14 +00:00
Nick Rolfe
998798e34d
Merge pull request #3352 from github/nickrolfe/jar-min-ff-cleanup
...
Clean up `JavaMinimizeDependencyJars` feature flag
2025-12-16 17:25:23 +00:00
copilot-swe-agent[bot]
393c074965
Refactor existing telemetry diagnostics to use makeTelemetryDiagnostic
...
Refactored bundle-download-telemetry and zstd-availability diagnostics
in init-action.ts to use the new makeTelemetryDiagnostic helper function.
Also added guard for empty languages array in logGitVersionTelemetry.
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 17:24:57 +00:00
copilot-swe-agent[bot]
c3dc529aef
Address feedback: cache git version, improve error handling, add telemetry
...
- Cache the git version to avoid recomputing on repeated calls
- Refactor getGitVersion to getGitVersionOrThrow with detailed errors
- Add getGitVersion that logs errors and handles caching
- Add makeTelemetryDiagnostic helper to diagnostics.ts
- Add logGitVersionTelemetry function to log git version telemetry
- Call logGitVersionTelemetry in init-action.ts
- Add resetCachedGitVersion for testing
- Update tests to work with new function signatures and caching
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 17:19:46 +00:00
copilot-swe-agent[bot]
fc2bbb041e
Address code review feedback
...
- Add test for Windows-style git version format
- Add comment clarifying regex extracts major.minor.patch
- Replace dynamic import with static import for semver
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 16:27:41 +00:00
copilot-swe-agent[bot]
89753aa84b
Add git version check for overlay analysis enablement
...
Overlay analysis depends on `getFileOidsUnderPath`, which uses
`git ls-files --format` option that requires Git 2.38.0+. This
change adds a check for the git version before enabling overlay
analysis.
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 16:22:23 +00:00
Henry Mercer
5eb751966f
Merge pull request #3358 from github/henrymercer/database-upload-telemetry
...
Add status report for uploading databases to API
2025-12-16 16:18:52 +00:00
Nick Rolfe
d29eddb39b
Extract version number to constant
2025-12-16 16:17:52 +00:00
copilot-swe-agent[bot]
aff7998c4a
Initial plan
2025-12-16 16:09:09 +00:00
Henry Mercer
e9626872ef
Merge branch 'main' into henrymercer/database-upload-telemetry
2025-12-16 15:53:31 +00:00
Henry Mercer
19c7f96922
Rename isOverlayBase
2025-12-16 15:41:50 +00:00
Henry Mercer
ae5de9a20d
Use getErrorMessage in log too
2025-12-16 15:41:04 +00:00
Henry Mercer
0cb86337c5
Prefer performance.now()
2025-12-16 15:38:29 +00:00
Henry Mercer
c07cc0d3a9
Merge pull request #3351 from github/henrymercer/ghec-dr-determine-tools-version-from-ffs
...
Determine CodeQL version from feature flags on GHEC-DR
2025-12-16 13:42:01 +00:00
Henry Mercer
7a5748cf0d
Remove changelog note
2025-12-16 13:41:13 +00:00
copilot-swe-agent[bot]
db75d46248
Bump @actions/* npm packages to latest versions
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 13:34:51 +00:00
copilot-swe-agent[bot]
a0fc644617
Initial plan
2025-12-16 13:29:18 +00:00
Henry Mercer
a2ee53c0d3
Use full names for GitHub variants
2025-12-16 13:23:24 +00:00
Michael B. Gale
b5e1a28b8a
Merge pull request #3365 from github/dependabot/github_actions/dot-github/workflows/actions/download-artifact-7
...
Bump actions/download-artifact from 6 to 7 in /.github/workflows
2025-12-16 12:17:14 +00:00
Michael B. Gale
c2d4383e64
Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/download-artifact-7
2025-12-15 22:00:03 +00:00
Michael B. Gale
d0ad1da72a
Merge pull request #3364 from github/dependabot/github_actions/dot-github/workflows/actions-minor-8751820eb1
...
Bump ruby/setup-ruby from 1.269.0 to 1.270.0 in /.github/workflows in the actions-minor group across 1 directory
2025-12-15 21:08:40 +00:00
Michael B. Gale
07cd437640
Merge pull request #3366 from github/dependabot/github_actions/dot-github/workflows/actions/upload-artifact-6
...
Bump actions/upload-artifact from 5 to 6 in /.github/workflows
2025-12-15 18:18:05 +00:00
Michael B. Gale
a682bbe410
Merge pull request #3309 from github/mbg/ff/make-new-upload-default
...
Remove `AnalyzeUseNewUpload` FF and make its behaviour the default
2025-12-15 17:24:57 +00:00
github-actions[bot]
7fd7db3f26
Rebuild
2025-12-15 17:20:17 +00:00
github-actions[bot]
d6c1a791b7
Rebuild
2025-12-15 17:20:02 +00:00
dependabot[bot]
034374eb3f
Bump actions/upload-artifact from 5 to 6 in /.github/workflows
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:40 +00:00
dependabot[bot]
6dbc22c93f
Bump actions/download-artifact from 6 to 7 in /.github/workflows
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 6 to 7.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:32 +00:00
dependabot[bot]
a539068a61
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.269.0 to 1.270.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/d697be2f83c6234b20877c3b5eac7a7f342f0d0c...ac793fdd38cc468a4dd57246fa9d0e868aba9085 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.270.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:28 +00:00
github-actions[bot]
e1058e4d74
Rebuild
2025-12-15 17:03:33 +00:00
dependabot[bot]
d4f39b0766
Bump the npm-minor group with 3 updates
...
Bumps the npm-minor group with 3 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@eslint/js` from 9.39.1 to 9.39.2
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.39.2/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.48.1 to 8.49.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.49.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.48.1 to 8.49.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.49.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.39.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.49.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.49.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:01:55 +00:00
Michael B. Gale
b30cb9ae2a
Merge branch 'main' into mbg/ff/make-new-upload-default
2025-12-15 16:28:30 +00:00
Michael B. Gale
009fe6b0c1
Remove AnalyzeUseNewUpload FF
2025-12-15 16:27:29 +00:00
Michael B. Gale
b1dea65f65
Make postProcessAndUploadSarif the default
2025-12-15 16:27:19 +00:00
Henry Mercer
7e0b77e3a8
Merge pull request #3349 from github/dependabot/github_actions/dot-github/workflows/actions-minor-dc476f2f5b
...
Bump the actions-minor group across 1 directory with 2 updates
2025-12-15 15:38:25 +00:00
Henry Mercer
0264b51610
Merge pull request #3348 from github/dependabot/npm_and_yarn/npm-minor-38a2a793c5
...
Bump the npm-minor group with 5 updates
2025-12-15 15:37:54 +00:00
Henry Mercer
2ac846d41e
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-38a2a793c5
2025-12-15 14:12:45 +00:00
Henry Mercer
5d063dd3af
Populate database upload results telemetry
2025-12-15 12:55:12 +00:00
Henry Mercer
8e921c3145
Return status report from cleanupAndUploadDatabases
2025-12-15 12:55:12 +00:00
Óscar San José
4b675e451b
Merge pull request #3356 from github/mergeback/v4.31.8-to-main-1b168cd3
...
Mergeback v4.31.8 refs/heads/releases/v4 into main
2025-12-12 10:48:29 +01:00
github-actions[bot]
65bad627f3
Rebuild
2025-12-12 08:52:54 +00:00
github-actions[bot]
4564f5e482
Update changelog and version after v4.31.8
2025-12-12 08:44:31 +00:00
Óscar San José
1b168cd394
Merge pull request #3355 from github/update-v4.31.8-1b0b941e1
...
Merge main into releases/v4
2025-12-12 09:43:00 +01:00
github-actions[bot]
120f277b16
Update changelog for v4.31.8
2025-12-11 17:23:34 +00:00
Óscar San José
1b0b941e1f
Merge pull request #3354 from github/update-bundle/codeql-bundle-v2.23.8
...
Update default bundle to 2.23.8
2025-12-11 17:25:18 +01:00
github-actions[bot]
db812c1ae6
Add changelog note
2025-12-11 15:46:24 +00:00
github-actions[bot]
2930dba17a
Update default bundle to codeql-bundle-v2.23.8
2025-12-11 15:46:14 +00:00
Nick Rolfe
805b7e1790
Clean up JavaMinimizeDependencyJars feature flag
2025-12-11 10:46:56 +00:00
Henry Mercer
da501245d4
Update PR template to include GHEC-DR
2025-12-10 17:41:20 +00:00
Henry Mercer
1fc7d3785d
Rename GHE_DOTCOM to GHEC_DR
...
This more closely reflects the published naming https://docs.github.com/en/enterprise-cloud@latest/admin/data-residency/about-github-enterprise-cloud-with-data-residency
2025-12-10 17:41:19 +00:00
Henry Mercer
7a55ffeaf1
Determine CodeQL version from feature flags on GHEC-DR
2025-12-10 17:35:27 +00:00
Kasper Svendsen
c43362b91a
Merge pull request #3340 from github/kaspersv/check-for-overlayBaseSpecifier
...
Overlay: Check database metadata for overlayBaseSpecifier
2025-12-09 11:37:30 +01:00
Kasper Svendsen
002a7f25fd
Overlay: log overlayBaseSpecifier at debug log-level
2025-12-09 09:44:56 +01:00
Kasper Svendsen
5b7e7fcc9c
Update src/codeql.ts
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2025-12-09 09:41:33 +01:00
github-actions[bot]
cd48547da5
Rebuild
2025-12-08 17:18:17 +00:00
dependabot[bot]
44570be32d
Bump the actions-minor group across 1 directory with 2 updates
...
Bumps the actions-minor group with 2 updates in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.268.0 to 1.269.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/8aeb6ff8030dd539317f8e1769a044873b56ea71...d697be2f83c6234b20877c3b5eac7a7f342f0d0c )
Updates `actions/create-github-app-token` from 2.2.0 to 2.2.1
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.2.0...v2.2.1 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.269.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
- dependency-name: actions/create-github-app-token
dependency-version: 2.2.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-08 17:16:45 +00:00
github-actions[bot]
b73d396b48
Rebuild
2025-12-08 17:03:51 +00:00
dependabot[bot]
0ffebf72b2
Bump the npm-minor group with 5 updates
...
Bumps the npm-minor group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [node-forge](https://github.com/digitalbazaar/forge ) | `1.3.2` | `1.3.3` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.48.0` | `8.48.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.48.0` | `8.48.1` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.0` | `0.27.1` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `61.4.1` | `61.5.0` |
Updates `node-forge` from 1.3.2 to 1.3.3
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.2...v1.3.3 )
Updates `@typescript-eslint/eslint-plugin` from 8.48.0 to 8.48.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.48.0 to 8.48.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.1/packages/parser )
Updates `esbuild` from 0.27.0 to 0.27.1
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.0...v0.27.1 )
Updates `eslint-plugin-jsdoc` from 61.4.1 to 61.5.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.4.1...v61.5.0 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.3.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.48.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.48.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-08 17:02:12 +00:00
Óscar San José
149d184a51
Merge pull request #3345 from github/mergeback/v4.31.7-to-main-cf1bb45a
...
Mergeback v4.31.7 refs/heads/releases/v4 into main
2025-12-05 21:43:41 +01:00
github-actions[bot]
97c2630b10
Rebuild
2025-12-05 17:21:46 +00:00
github-actions[bot]
b93926dc35
Update changelog and version after v4.31.7
2025-12-05 17:19:09 +00:00
Óscar San José
cf1bb45a27
Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
...
Merge main into releases/v4
2025-12-05 18:17:21 +01:00
github-actions[bot]
f4ebe95061
Update changelog for v4.31.7
2025-12-05 15:18:53 +00:00
Óscar San José
f5c63fadd5
Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
...
Update default bundle to 2.23.7
2025-12-05 15:06:47 +01:00
github-actions[bot]
a2c01e776e
Add changelog note
2025-12-05 13:39:53 +00:00
github-actions[bot]
ac34c13834
Update default bundle to codeql-bundle-v2.23.7
2025-12-05 13:39:45 +00:00
Michael B. Gale
267c4672a5
Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d26487b0
...
Bump @eslint/eslintrc from 3.3.1 to 3.3.3 in the npm-minor group
2025-12-03 14:27:03 +00:00
Michael B. Gale
aeabef7b69
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
2025-12-03 12:43:12 +00:00
Kasper Svendsen
c4efbda299
Overlay: Check database metadata for overlayBaseSpecifier
2025-12-03 13:40:24 +01:00
Kasper Svendsen
dd8914320f
CodeQL: Add resolveDatabase method
2025-12-03 13:40:24 +01:00
Michael B. Gale
78357d3fc9
Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
...
Update CLI config test to account for overlay db changes on PRs
2025-12-03 12:39:49 +00:00
Michael B. Gale
d61a6fa793
Update CLI config test to account for overlay db changes on PRs
2025-12-03 12:11:11 +00:00
github-actions[bot]
ce27e95f79
Rebuild
2025-12-01 18:32:19 +00:00
dependabot[bot]
43224eb34e
Bump @eslint/eslintrc from 3.3.1 to 3.3.3 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [@eslint/eslintrc](https://github.com/eslint/eslintrc ).
Updates `@eslint/eslintrc` from 3.3.1 to 3.3.3
- [Release notes](https://github.com/eslint/eslintrc/releases )
- [Changelog](https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslintrc/compare/v3.3.1...eslintrc-v3.3.3 )
---
updated-dependencies:
- dependency-name: "@eslint/eslintrc"
dependency-version: 3.3.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-01 18:30:33 +00:00
Michael B. Gale
f0ac9bfbe3
Merge pull request #3337 from github/mergeback/v4.31.6-to-main-fe4161a2
...
Mergeback v4.31.6 refs/heads/releases/v4 into main
2025-12-01 10:18:06 +00:00
github-actions[bot]
c1ca379fc0
Rebuild
2025-12-01 09:55:25 +00:00
github-actions[bot]
c3455c55c1
Update changelog and version after v4.31.6
2025-12-01 09:50:22 +00:00
Michael B. Gale
fe4161a26a
Merge pull request #3336 from github/update-v4.31.6-ecec1f887
...
Merge main into releases/v4
2025-12-01 09:48:24 +00:00
github-actions[bot]
88c2ab5eee
Update changelog for v4.31.6
2025-12-01 09:26:09 +00:00
Michael B. Gale
ecec1f8876
Merge pull request #3335 from github/mbg/ci/run-codeql-on-all-prs
...
Remove branch filter for PR event in CodeQL workflow
2025-11-28 12:19:33 +00:00
Kasper Svendsen
23da732778
Merge pull request #3334 from github/kaspersv/overlay-minor-comments
...
Overlay: Small code improvements
2025-11-28 10:26:32 +01:00
Michael B. Gale
f7abc748a3
Remove branch filter for PR event in CodeQL workflow
2025-11-28 09:13:23 +00:00
Kasper Svendsen
32ada5e061
Merge branch 'main' into kaspersv/overlay-minor-comments
2025-11-28 10:02:55 +01:00
Kasper Svendsen
75b2f49aea
Merge pull request #3333 from github/kaspersv/overlay-no-resource-checks-option
...
Overlay: Add feature flag to skip resource checks
2025-11-28 10:01:21 +01:00
Kasper Svendsen
f036b1cb78
Merge branch 'main' into kaspersv/overlay-no-resource-checks-option
2025-11-28 09:44:11 +01:00
Kasper Svendsen
58c5954801
Add comment to runnerSupportsOverlayAnalysis
2025-11-27 15:56:29 +01:00
Kasper Svendsen
b02fa13292
Order feature flags alphabetically
2025-11-27 15:56:29 +01:00
Kasper Svendsen
8d91fa189d
Rename getMemoryFlagValue
2025-11-27 15:56:29 +01:00
Kasper Svendsen
2f3bbce9a6
Overlay: Introduce overlay memory limit constant
2025-11-27 15:33:57 +01:00
Kasper Svendsen
c178e03ec8
Merge pull request #3332 from github/kaspersv/overlay-memory-limit
...
Overlay: Fall back to full analysis if memory flag is low
2025-11-27 15:26:02 +01:00
Henry Mercer
d29b97960c
Merge pull request #3331 from github/dependabot/npm_and_yarn/node-forge-1.3.2
...
Bump node-forge from 1.3.1 to 1.3.2
2025-11-27 11:44:32 +00:00
Kasper Svendsen
1ffb7dd0c8
Overlay: Add feature flag to skip resource checks
2025-11-27 12:30:23 +01:00
Kasper Svendsen
bd8d26b618
Overlay: Fall back to full analysis if memory flag is low
2025-11-27 09:16:35 +01:00
Kasper Svendsen
bd30e753a6
Simplify getOverlayDatabaseMode
2025-11-27 08:34:43 +01:00
github-actions[bot]
4822f934e3
Rebuild
2025-11-26 22:34:54 +00:00
dependabot[bot]
0c204fc557
Bump node-forge from 1.3.1 to 1.3.2
...
Bumps [node-forge](https://github.com/digitalbazaar/forge ) from 1.3.1 to 1.3.2.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.1...v1.3.2 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.3.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-26 22:33:20 +00:00
Michael B. Gale
59ce4c1340
Merge pull request #3286 from github/mbg/csharp/more-cache-locations
...
C#: Cache temporary dependency directory for BMN
2025-11-26 14:36:58 +00:00
Henry Mercer
3e939667ec
Merge branch 'main' into mbg/csharp/more-cache-locations
2025-11-26 14:12:07 +00:00
Michael B. Gale
7850b1c983
Merge pull request #3330 from github/mbg/ci/remove-push-from-groups
...
Remove `push` triggers from workflow collections
2025-11-26 10:52:53 +00:00
Henry Mercer
c370017ae8
Merge pull request #3325 from github/dependabot/npm_and_yarn/npm-minor-45ea8d913b
...
Bump the npm-minor group with 3 updates
2025-11-26 10:34:47 +00:00
Michael B. Gale
a6909455e4
Remove push triggers from workflow collections
2025-11-26 10:27:48 +00:00
github-actions[bot]
510d25ff7f
Rebuild
2025-11-26 10:15:27 +00:00
github-actions[bot]
85fd3e57b5
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_yarn/npm-minor-45ea8d913b
2025-11-26 10:14:31 +00:00
Henry Mercer
d8e497a759
Update version in package.json too
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-11-26 10:13:41 +00:00
Henry Mercer
99d80b4ea7
Merge pull request #3328 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-11-26 10:12:59 +00:00
Michael B. Gale
0155561719
Merge branch 'main' into mbg/csharp/more-cache-locations
2025-11-26 10:01:51 +00:00
github-actions[bot]
6b7e963cf1
Update supported GitHub Enterprise Server versions
2025-11-26 00:18:14 +00:00
Michael B. Gale
0e52774aee
Merge pull request #3326 from github/dependabot/github_actions/dot-github/workflows/actions-minor-8ee81fe642
...
Bump actions/create-github-app-token from 2.1.4 to 2.2.0 in /.github/workflows in the actions-minor group across 1 directory
2025-11-25 11:45:44 +00:00
Michael B. Gale
62e90525a0
Merge pull request #3327 from github/dependabot/github_actions/dot-github/workflows/actions/checkout-6
...
Bump actions/checkout from 5 to 6 in /.github/workflows
2025-11-25 11:20:57 +00:00
github-actions[bot]
8484f54a0a
Rebuild
2025-11-24 18:02:41 +00:00
dependabot[bot]
5bd8069afb
Bump actions/checkout from 5 to 6 in /.github/workflows
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 18:01:10 +00:00
dependabot[bot]
6feac2b36a
Bump actions/create-github-app-token
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `actions/create-github-app-token` from 2.1.4 to 2.2.0
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.1.4...v2.2.0 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 2.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 17:59:04 +00:00
github-actions[bot]
514279113a
Rebuild
2025-11-24 17:38:19 +00:00
dependabot[bot]
e2a623d7cf
Bump the npm-minor group with 3 updates
...
Bumps the npm-minor group with 3 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@typescript-eslint/eslint-plugin` from 8.46.4 to 8.48.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.4 to 8.48.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.0/packages/parser )
Updates `eslint-plugin-jsdoc` from 61.2.1 to 61.4.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Changelog](https://github.com/gajus/eslint-plugin-jsdoc/blob/main/.releaserc )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.2.1...v61.4.1 )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.48.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.48.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.4.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 17:36:24 +00:00
Paolo Tranquilli
52f930e50a
Merge pull request #3323 from github/mergeback/v4.31.5-to-main-fdbfb4d2
...
Mergeback v4.31.5 refs/heads/releases/v4 into main
2025-11-24 12:18:45 +01:00
github-actions[bot]
478350182f
Rebuild
2025-11-24 10:55:14 +00:00
github-actions[bot]
29e11fdce1
Update changelog and version after v4.31.5
2025-11-24 09:31:18 +00:00
Paolo Tranquilli
fdbfb4d275
Merge pull request #3322 from github/update-v4.31.5-ec2ee575c
...
Merge main into releases/v4
2025-11-24 10:29:19 +01:00
github-actions[bot]
81f6d649ae
Update changelog for v4.31.5
2025-11-24 09:03:58 +00:00
Paolo Tranquilli
ec2ee575c0
Merge pull request #3321 from github/update-bundle/codeql-bundle-v2.23.6
...
Update default bundle to 2.23.6
2025-11-24 09:14:29 +01:00
github-actions[bot]
ecc87875ee
Add changelog note
2025-11-24 07:51:53 +00:00
github-actions[bot]
1d2a238d7d
Update default bundle to codeql-bundle-v2.23.6
2025-11-24 07:51:46 +00:00
Michael B. Gale
b4db38273c
Add generated files to paths-ignore, if FF is enabled
2025-11-19 19:42:18 +00:00
Michael B. Gale
846f8590dc
Add IgnoreGeneratedFiles FF
2025-11-19 19:10:42 +00:00
Michael B. Gale
3eaf00092b
Add isCCR helper, and update isDefaultSetup
2025-11-19 19:07:21 +00:00
Michael B. Gale
1512f400b3
Add function to query git for all generated files
2025-11-19 15:35:46 +00:00
Henry Mercer
ce729e4d35
Merge pull request #3315 from github/henrymercer/dead-code-elimination
...
Delete unused exports
2025-11-19 15:24:22 +00:00
Henry Mercer
ac359aad20
Add return type
2025-11-19 14:59:16 +00:00
Henry Mercer
112cd075bd
Merge branch 'main' into henrymercer/dead-code-elimination
2025-11-19 14:56:28 +00:00
Michael B. Gale
0b4317954f
Merge pull request #3306 from github/dependabot/npm_and_yarn/types/sinon-21.0.0
...
Bump @types/sinon from 17.0.4 to 21.0.0
2025-11-19 14:13:16 +00:00
Michael B. Gale
e818008b54
Merge pull request #3305 from github/dependabot/npm_and_yarn/eslint/compat-2.0.0
...
Bump @eslint/compat from 1.4.1 to 2.0.0
2025-11-19 13:41:43 +00:00
Michael B. Gale
90871e185b
Merge pull request #3304 from github/dependabot/npm_and_yarn/npm-minor-7439af33e4
...
Bump the npm-minor group with 2 updates
2025-11-19 13:18:38 +00:00
Kasper Svendsen
a102014397
Merge pull request #3317 from github/kaspersv/bump-minimum-overlay-version
...
Overlay: Increase minimum CLI version required for overlay analysis
2025-11-19 14:18:24 +01:00
Kasper Svendsen
de74d762a3
Overlay: Increase minimum CLI version
2025-11-19 13:04:23 +01:00
Kasper Svendsen
ce07e7d196
Merge pull request #3310 from github/kaspersv/overlay-disk-available-limit
...
Overlay: Fall back to full analysis if runner disk space is low
2025-11-19 12:57:53 +01:00
Henry Mercer
86d2aa55c0
Merge pull request #3316 from github/henrymercer/upload-overlay-to-api
...
Upload overlay base DBs to GitHub API behind FF
2025-11-19 10:29:28 +00:00
Kasper Svendsen
4eccb3798e
Overlay: Round available disk space in MB
2025-11-19 08:40:56 +01:00
Kasper Svendsen
ed80d6e5e9
Overlay: Reorder available disk space check
2025-11-19 07:54:05 +01:00
Henry Mercer
378219ced2
Merge pull request #3313 from github/mergeback/v4.31.4-to-main-e12f0178
...
Mergeback v4.31.4 refs/heads/releases/v4 into main
2025-11-18 18:46:24 +00:00
Henry Mercer
c649c5993d
Upload overlay base DB to API behind FF
2025-11-18 18:43:19 +00:00
Henry Mercer
31042e9879
Rename function calls to make destructive operation clearer
2025-11-18 18:42:15 +00:00
Henry Mercer
5da2098551
Add feature flag for uploading overlay DBs to API
2025-11-18 18:40:51 +00:00
Henry Mercer
cac5926de5
Delete unused exports
2025-11-18 18:16:54 +00:00
Henry Mercer
e24190a70c
Remove unused dependencies
2025-11-18 18:14:49 +00:00
github-actions[bot]
ce9b526448
Rebuild
2025-11-18 16:17:35 +00:00
github-actions[bot]
28f4a61417
Merge remote-tracking branch 'origin/main' into mergeback/v4.31.4-to-main-e12f0178
2025-11-18 16:16:46 +00:00
github-actions[bot]
fea250010c
Update changelog and version after v4.31.4
2025-11-18 16:14:11 +00:00
Michael B. Gale
e12f017898
Merge pull request #3312 from github/update-v4.31.4-70434f6dd
...
Merge main into releases/v4
2025-11-18 16:12:25 +00:00
Michael B. Gale
249458aab2
Merge pull request #3296 from github/mbg/dependency-caching/skip-uploads-for-exact-matches
...
Skip uploading dependency caches if we know they exist
2025-11-18 15:44:06 +00:00
github-actions[bot]
c9cb6f9c13
Update changelog for v4.31.4
2025-11-18 15:18:43 +00:00
Henry Mercer
7bb4bfc7c2
Merge branch 'main' into henrymercer/generate-mergeback-last
2025-11-18 15:03:11 +00:00
Kasper Svendsen
726a2a01b8
Overlay: Increase disk storage threshold to 20GB
2025-11-18 15:37:27 +01:00
Michael B. Gale
70434f6dd2
Merge pull request #3311 from github/mbg/deps/bump-glob
...
Bump `glob` to at least `11.1.0`
2025-11-18 12:39:21 +00:00
Michael B. Gale
528362a7c1
Bump glob to at least 11.1.0
2025-11-18 12:20:00 +00:00
Michael B. Gale
de12435376
Merge pull request #3308 from github/mbg/pr-template/nov25
...
Add additional options to PR template and clarify some
2025-11-18 11:52:08 +00:00
Kasper Svendsen
4f746e4a60
Overlay: Fall back to full analysis if runner disk space is low
2025-11-18 08:19:13 +01:00
Michael B. Gale
ffa63f0dac
Merge pull request #3307 from github/dependabot/github_actions/dot-github/workflows/actions-minor-761b22fa12
...
Bump ruby/setup-ruby from 1.267.0 to 1.268.0 in /.github/workflows in the actions-minor group across 1 directory
2025-11-17 18:06:59 +00:00
Michael B. Gale
7bcdb4bc66
Add additional options to PR template and clarify some
2025-11-17 17:48:39 +00:00
Mario Campos
07eae6420a
Merge pull request #3303 from github/mario-campos/v3-core-warning
...
Change v3 deprecation message to warning.
2025-11-17 11:35:30 -06:00
github-actions[bot]
e546fff076
Rebuild
2025-11-17 17:18:36 +00:00
dependabot[bot]
c418a0fc93
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.267.0 to 1.268.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/d5126b9b3579e429dd52e51e68624dda2e05be25...8aeb6ff8030dd539317f8e1769a044873b56ea71 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.268.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:17:07 +00:00
Mario Campos
fc329e3bb5
Revert "Add CHANGELOG.md entry for "v3 deprecation" to warning change."
...
This reverts commit 023fd08cc9 .
2025-11-17 11:08:58 -06:00
github-actions[bot]
b595847fa5
Rebuild
2025-11-17 17:04:50 +00:00
github-actions[bot]
4f39cef4c6
Rebuild
2025-11-17 17:03:39 +00:00
github-actions[bot]
d4a7ccd1f0
Rebuild
2025-11-17 17:03:22 +00:00
dependabot[bot]
cd808e1260
Bump @types/sinon from 17.0.4 to 21.0.0
...
Bumps [@types/sinon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sinon ) from 17.0.4 to 21.0.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sinon )
---
updated-dependencies:
- dependency-name: "@types/sinon"
dependency-version: 21.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:02:13 +00:00
dependabot[bot]
01577d4797
Bump @eslint/compat from 1.4.1 to 2.0.0
...
Bumps [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) from 1.4.1 to 2.0.0.
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.0/packages/compat )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:01:53 +00:00
dependabot[bot]
3b635815d6
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@octokit/request-error](https://github.com/octokit/request-error.js ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@octokit/request-error` from 7.0.2 to 7.1.0
- [Release notes](https://github.com/octokit/request-error.js/releases )
- [Commits](https://github.com/octokit/request-error.js/compare/v7.0.2...v7.1.0 )
Updates `eslint-plugin-jsdoc` from 61.1.12 to 61.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Changelog](https://github.com/gajus/eslint-plugin-jsdoc/blob/main/.releaserc )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.1.12...v61.2.1 )
---
updated-dependencies:
- dependency-name: "@octokit/request-error"
dependency-version: 7.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.2.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:01:47 +00:00
Mario Campos
023fd08cc9
Add CHANGELOG.md entry for "v3 deprecation" to warning change.
2025-11-17 09:04:58 -06:00
Mario Campos
ed3a01336f
Change v3 deprecation message to warning.
2025-11-17 08:59:44 -06:00
Michael B. Gale
c1a2b73420
Merge pull request #3301 from github/dependabot/npm_and_yarn/js-yaml-4.1.1
...
Bump js-yaml from 4.1.0 to 4.1.1
2025-11-16 17:54:05 +00:00
github-actions[bot]
8c254d05f3
Rebuild
2025-11-15 10:57:22 +00:00
dependabot[bot]
b9620e1249
Bump js-yaml from 4.1.0 to 4.1.1
...
Bumps [js-yaml](https://github.com/nodeca/js-yaml ) from 4.1.0 to 4.1.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.0...4.1.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.1.1
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-15 10:55:57 +00:00
Michael B. Gale
1ed85b4501
Add test coverage for uploadDependencyCaches
2025-11-14 14:30:54 +00:00
Michael B. Gale
51c9af3a3b
Don't try to upload cache if we have restored a cache with the same key
2025-11-14 14:30:54 +00:00
Michael B. Gale
594c0cc369
Store restored keys in action state
2025-11-14 14:30:54 +00:00
Michael B. Gale
11889c27fd
Return keys of restored caches from downloadDependencyCaches
2025-11-14 14:30:54 +00:00
Kasper Svendsen
85f1517bb4
Merge pull request #3285 from github/kaspersv/remove-overlay-org-restriction
...
Overlay: Remove repository owner restriction
2025-11-14 08:28:09 +01:00
Michael B. Gale
86b7d4fc36
Merge pull request #3294 from github/mergeback/v4.31.3-to-main-014f16e7
...
Mergeback v4.31.3 refs/heads/releases/v4 into main
2025-11-13 22:22:18 +00:00
github-actions[bot]
246edb9b1d
Rebuild
2025-11-13 21:59:57 +00:00
github-actions[bot]
497c7f627a
Update changelog and version after v4.31.3
2025-11-13 21:54:56 +00:00
Michael B. Gale
014f16e7ab
Merge pull request #3293 from github/update-v4.31.3-8c10e89c7
...
Merge main into releases/v4
2025-11-13 21:53:12 +00:00
github-actions[bot]
14d898ef09
Update changelog for v4.31.3
2025-11-13 21:18:01 +00:00
Henry Mercer
6678cee8aa
Merge branch 'main' into henrymercer/generate-mergeback-last
2025-11-13 21:06:03 +00:00
Michael B. Gale
8c10e89c78
Merge pull request #3288 from github/update-bundle/codeql-bundle-v2.23.5
...
Update default bundle to 2.23.5
2025-11-13 20:50:51 +00:00
Michael B. Gale
9777b01a49
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.5
2025-11-13 20:11:59 +00:00
Henry Mercer
456a74a6fa
Merge pull request #3289 from github/mbg/ci/setup-dotnet
...
Add support for adding `setup-dotnet` steps to `sync.sh`
2025-11-13 20:11:33 +00:00
Michael B. Gale
3fac49c140
Update remaining workflows
2025-11-13 19:53:24 +00:00
Michael B. Gale
38a3a7258f
Enable installDotNet in all workflows that analyse C#
2025-11-13 19:48:37 +00:00
Michael B. Gale
58c9eb6c03
Add global.json
2025-11-13 19:48:37 +00:00
Michael B. Gale
f20e02164a
Add support for adding setup-dotnet steps to sync.sh
2025-11-13 18:58:54 +00:00
github-actions[bot]
8d3d4001e3
Add changelog note
2025-11-13 18:40:00 +00:00
github-actions[bot]
362f8d1d2d
Update default bundle to codeql-bundle-v2.23.5
2025-11-13 18:39:52 +00:00
Henry Mercer
79e9b8a130
Open mergeback PR last
...
This reduces the likelihood of publishing a tag but not a release.
2025-11-13 17:23:45 +00:00
Michael B. Gale
f5f9571d61
Configure temp dependency dir for C# extractor when FF is enabled
...
And also clean it up.
2025-11-13 14:03:44 +00:00
Michael B. Gale
ecaa6db95a
Include getCsharpTempDependencyDir in C# caches if FF is enabled
2025-11-13 13:40:58 +00:00
Michael B. Gale
a47d04cf9b
Add FF for extra C# cache contents
2025-11-13 13:40:57 +00:00
Michael B. Gale
d854ba6ec0
Pass FeatureEnablement to getDependencyPaths
2025-11-13 13:40:57 +00:00
Michael B. Gale
cf8b7a6e14
Refactor C# cache content paths into a function
2025-11-13 13:40:56 +00:00
Kasper Svendsen
5091e42a03
Overlay: Remove repository owner restriction
2025-11-13 10:48:25 +01:00
Michael B. Gale
ba454b8ab4
Merge pull request #3284 from github/mbg/ci/fix-enterprise-workflow
...
Fix `update-supported-enterprise-server-versions.yml` workflow
2025-11-12 15:35:56 +00:00
Michael B. Gale
7a7cd8565c
Don't push for PR event
2025-11-12 15:09:25 +00:00
Michael B. Gale
fd830db27b
Trigger on PR for relevant changes
2025-11-12 15:05:11 +00:00
Michael B. Gale
a7e52b690b
Perform sparse checkout
2025-11-12 15:04:21 +00:00
Michael B. Gale
71c3720f43
Run npm ci in update-supported-enterprise-server-versions.yml
2025-11-12 14:57:05 +00:00
Michael B. Gale
534824ea1b
Merge pull request #3117 from github/mbg/csharp/new-cache-key-calculation
...
Support non-lock files for C# cache key computation
2025-11-12 11:03:09 +00:00
Kasper Svendsen
4eb247591f
Move conversion of PR diff-range paths to absolute paths
2025-11-12 08:10:40 +01:00
Kasper Svendsen
df4e1992c0
Add unit test for diffRangeExtensionPackContents
2025-11-12 08:10:40 +01:00
Kasper Svendsen
d18f3acf74
Move diff-range extension pack generation into testable function
2025-11-12 08:10:39 +01:00
Kasper Svendsen
035c1179af
upload-lib: Unit test filterAlertsByDiffRange
2025-11-12 08:10:39 +01:00
Henry Mercer
1d9f357d01
Merge pull request #3281 from github/dependabot/npm_and_yarn/npm-minor-9dd9c1a8e4
...
Bump the npm-minor group with 4 updates
2025-11-11 10:21:24 +00:00
github-actions[bot]
3d7be7bf78
Rebuild
2025-11-10 17:49:58 +00:00
dependabot[bot]
63bb415fff
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [esbuild](https://github.com/evanw/esbuild ).
Updates `@eslint/js` from 9.39.0 to 9.39.1
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.39.1/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.46.3 to 8.46.4
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.4/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.3 to 8.46.4
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.4/packages/parser )
Updates `esbuild` from 0.25.12 to 0.27.0
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.12...v0.27.0 )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.39.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.46.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.46.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-10 17:48:25 +00:00
Michael B. Gale
04bd5c6aab
Merge pull request #3279 from github/mbg/lint/jsdoc-param-names
...
Linter: check JSDoc parameter names exist
2025-11-10 11:36:02 +00:00
Michael B. Gale
48a56f6b93
Add some tests for downloadDependencyCaches related to feature prefixes
2025-11-09 12:03:18 +00:00
Michael B. Gale
4885eb2ad9
Insert new featurePrefix after general cache key prefix
2025-11-09 11:17:02 +00:00
Michael B. Gale
a47d5507cf
Restore earlier log messages for checkHashPatterns
2025-11-09 11:11:10 +00:00
Michael B. Gale
b0e9dfce55
Restore missing status.push resulting from a bad merge
2025-11-09 11:10:27 +00:00
Michael B. Gale
35c91ef0af
Add tests for getCsharpHashPatterns
...
- Make the function more easily testable by allowing `makePatternCheck` to be stubbed.
- Use `makePatternCheck` for base patterns as well.
2025-11-09 11:03:15 +00:00
Michael B. Gale
71abac76d2
Fix comment in getCsharpHashPatterns
2025-11-09 10:32:10 +00:00
Michael B. Gale
5b58b8f9c5
Linter: check JSDoc parameter names exist
2025-11-09 10:26:36 +00:00
Michael B. Gale
46e03b48bc
Fix JSDoc param name
2025-11-09 10:05:18 +00:00
Henry Mercer
71d0a56d44
Merge pull request #3278 from github/henrymercer/type-fun
...
Use generic types for durations in status report
2025-11-06 10:47:44 +00:00
Henry Mercer
04285cbe85
Use generic types for durations in status report
...
This means we don't need to update this interface for every new language.
2025-11-05 18:54:44 +00:00
Michael B. Gale
26804552e4
Use undefined instead of NoMatchingFilesError
...
Add tests for `makePatternCheck` and `checkHashPatterns`
2025-11-05 17:23:22 +00:00
Michael B. Gale
03b2dc2a3f
Add and use getFeaturePrefix for dependency caching
2025-11-05 16:33:21 +00:00
Michael B. Gale
0cbd930deb
Move createCacheKeyHash to caching-utils
2025-11-05 16:15:26 +00:00
Michael B. Gale
0324490286
Use additional files for C# key hashes if Feature.CsharpNewCacheKey is enabled
2025-11-05 16:03:41 +00:00
Michael B. Gale
6b48207907
Move check whether there are files for hashing into getHashPatterns
2025-11-05 16:03:39 +00:00
Mario Campos
320a6b661b
Merge pull request #3272 from github/mario-campos/v4-warning
...
Update deprecation warnings for CodeQL Action to v4
2025-11-05 10:01:33 -06:00
Michael B. Gale
ab1c84236a
Change hash to be a function that can use Features
2025-11-05 15:57:57 +00:00
Michael B. Gale
2a7680fca6
Change getDefaultCacheConfig to be a const by turning paths into a function
...
Changing `paths` to be a function is necessary to allow `getTemporaryDirectory` to be called
2025-11-05 15:57:55 +00:00
Michael B. Gale
2aa1f55f3d
Propagate features into cachePrefix function
2025-11-05 15:54:28 +00:00
Michael B. Gale
1ca20ab026
Add CsharpNewCacheKey FF
2025-11-05 15:48:04 +00:00
Mario Campos
b5e5a258e6
Merge branch 'main' into mario-campos/v4-warning
2025-11-05 09:39:54 -06:00
Mario Campos
74f662193b
Reformat with eslint
2025-11-05 09:37:42 -06:00
Mario Campos
ecee3ea8f5
Update CHANGELOG.md.
2025-11-05 09:18:30 -06:00
Mario Campos
6a63bc6af3
Change warning message to just v3 (exclude v1, v2).
2025-11-05 09:15:53 -06:00
Henry Mercer
e2ef519c75
Merge pull request #3224 from github/henrymercer/clean-up-resolve-languages-ff
...
Clean up `resolve_supported_languages_using_cli` FF
2025-11-05 11:57:35 +00:00
Michael B. Gale
423d14e583
Merge pull request #3277 from github/mbg/ci/update-bundle-python
...
Install Python in `update-bundle` workflow
2025-11-05 11:53:17 +00:00
Michael B. Gale
6dd11f73d3
Update .github/workflows/script/bundle_changelog.py
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-11-05 11:34:26 +00:00
Michael B. Gale
c9f82f2adf
Move python script to file
2025-11-05 11:22:38 +00:00
Michael B. Gale
33684ef869
Add setup-python step to update-bundle workflow
2025-11-05 11:20:06 +00:00
Michael B. Gale
5aa2d63d5b
Merge branch 'main' into mario-campos/v4-warning
2025-11-05 11:03:25 +00:00
Michael B. Gale
862f5666b3
Merge pull request #3275 from github/mbg/checks/filter-ccr
...
Filter CCR jobs in `update-required-checks.sh`
2025-11-05 10:15:57 +00:00
Michael B. Gale
b00addd1d3
Merge pull request #3274 from github/mbg/macos-13
2025-11-05 09:01:53 +00:00
Michael B. Gale
d03fd76232
Filter CCR jobs in update-required-checks.sh
2025-11-04 22:23:12 +00:00
Michael B. Gale
9d5565fba2
Remove macos-13 from codeql workflow
2025-11-04 21:29:25 +00:00
Mario Campos
a570795dfc
Clarify the CHANGELOG.md entry to reflect the whole action, and not just init.
2025-11-04 12:02:15 -06:00
Mario Campos
9366f80399
Reference GHES 3.20 in the comment, not 3.19.
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-11-04 12:00:11 -06:00
Mario Campos
c443dff433
Simplify warning language to not enumerate deprecated versions.
2025-11-04 11:57:44 -06:00
Mario Campos
b32a1e0627
Update test cases for GitHub Enterprise Server versions 3.11 and 3.12 to reflect correct deprecation status
2025-11-04 11:51:23 -06:00
Mario Campos
08dc635f27
Restore use of sinon.match().
2025-11-04 11:11:08 -06:00
Mario Campos
f1ca6a4f47
Update tests to reflect deprecation status of CodeQL Action v3
2025-11-04 11:07:15 -06:00
Mario Campos
ba82f9bd34
Fix deprecation warning to reflect that v3 is not actually deprecated yet.
2025-11-04 10:13:07 -06:00
Mario Campos
5a9b49de7e
Update CHANGELOG to reflect warning for v3 users migrating to v4 of CodeQL Action
2025-11-04 10:09:47 -06:00
Mario Campos
1aade295bc
Update deprecation warnings for CodeQL Action to v4
2025-11-04 09:59:16 -06:00
Henry Mercer
95b1867cf7
Merge pull request #3269 from github/dependabot/npm_and_yarn/actions/io-2.0.0
...
Bump @actions/io from 1.1.3 to 2.0.0
2025-11-04 14:23:27 +00:00
github-actions[bot]
238f5f2946
Rebuild
2025-11-04 14:00:06 +00:00
dependabot[bot]
a53b4967d7
Bump @actions/io from 1.1.3 to 2.0.0
...
Bumps [@actions/io](https://github.com/actions/toolkit/tree/HEAD/packages/io ) from 1.1.3 to 2.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/io/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/io )
---
updated-dependencies:
- dependency-name: "@actions/io"
dependency-version: 2.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-04 13:58:17 +00:00
Henry Mercer
493ffd8e5c
Merge pull request #3268 from github/dependabot/npm_and_yarn/types/archiver-7.0.0
...
Bump @types/archiver from 6.0.4 to 7.0.0
2025-11-04 13:56:51 +00:00
github-actions[bot]
f23547cd26
Rebuild
2025-11-04 12:25:05 +00:00
dependabot[bot]
58f5e3dab8
Bump @types/archiver from 6.0.4 to 7.0.0
...
Bumps [@types/archiver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/archiver ) from 6.0.4 to 7.0.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/archiver )
---
updated-dependencies:
- dependency-name: "@types/archiver"
dependency-version: 7.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-04 12:19:24 +00:00
Henry Mercer
98e0ffef96
Merge pull request #3266 from github/dependabot/npm_and_yarn/npm-minor-29e8df1594
...
Bump the npm-minor group with 7 updates
2025-11-04 11:09:56 +00:00
github-actions[bot]
85eb524170
Rebuild
2025-11-04 10:34:56 +00:00
dependabot[bot]
a3ea4ef532
Bump the npm-minor group with 7 updates
...
Bumps the npm-minor group with 7 updates:
| Package | From | To |
| --- | --- | --- |
| [@octokit/request-error](https://github.com/octokit/request-error.js ) | `7.0.1` | `7.0.2` |
| [octokit](https://github.com/octokit/octokit.js ) | `5.0.4` | `5.0.5` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `1.4.0` | `1.4.1` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.38.0` | `9.39.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.46.2` | `8.46.3` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.46.2` | `8.46.3` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.25.11` | `0.25.12` |
Updates `@octokit/request-error` from 7.0.1 to 7.0.2
- [Release notes](https://github.com/octokit/request-error.js/releases )
- [Commits](https://github.com/octokit/request-error.js/compare/v7.0.1...v7.0.2 )
Updates `octokit` from 5.0.4 to 5.0.5
- [Release notes](https://github.com/octokit/octokit.js/releases )
- [Commits](https://github.com/octokit/octokit.js/compare/v5.0.4...v5.0.5 )
Updates `@eslint/compat` from 1.4.0 to 1.4.1
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v1.4.1/packages/compat )
Updates `@eslint/js` from 9.38.0 to 9.39.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.39.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.46.2 to 8.46.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.3/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.2 to 8.46.3
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.3/packages/parser )
Updates `esbuild` from 0.25.11 to 0.25.12
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.11...v0.25.12 )
---
updated-dependencies:
- dependency-name: "@octokit/request-error"
dependency-version: 7.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: octokit
dependency-version: 5.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@eslint/compat"
dependency-version: 1.4.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@eslint/js"
dependency-version: 9.39.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.46.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.46.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.25.12
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-03 18:47:33 +00:00
Henry Mercer
97580d7533
Merge pull request #3267 from github/dependabot/npm_and_yarn/octokit/types-16.0.0
...
Bump @octokit/types from 15.0.1 to 16.0.0
2025-11-03 18:12:51 +00:00
Henry Mercer
7ad64f0258
Merge pull request #3270 from github/dependabot/npm_and_yarn/actions/http-client-3.0.0
...
Bump @actions/http-client from 2.2.3 to 3.0.0
2025-11-03 18:11:30 +00:00
github-actions[bot]
61bcb70dce
Rebuild
2025-11-03 17:22:15 +00:00
github-actions[bot]
5313cd14a8
Rebuild
2025-11-03 17:21:50 +00:00
dependabot[bot]
8fa298d060
Bump @actions/http-client from 2.2.3 to 3.0.0
...
Bumps [@actions/http-client](https://github.com/actions/toolkit/tree/HEAD/packages/http-client ) from 2.2.3 to 3.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/http-client/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/http-client )
---
updated-dependencies:
- dependency-name: "@actions/http-client"
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-03 17:20:38 +00:00
dependabot[bot]
7d1bed2dd0
Bump @octokit/types from 15.0.1 to 16.0.0
...
Bumps [@octokit/types](https://github.com/octokit/types.ts ) from 15.0.1 to 16.0.0.
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v15.0.1...v16.0.0 )
---
updated-dependencies:
- dependency-name: "@octokit/types"
dependency-version: 16.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-03 17:20:12 +00:00
Michael B. Gale
338146ca93
Merge pull request #3264 from github/mbg/ci/publish-on-tag
...
Create immutable action version on tag push
2025-10-31 16:48:43 +00:00
Michael B. Gale
64db1da706
Create immutable action version on tag push
2025-10-31 16:24:23 +00:00
Henry Mercer
9bd8638576
Merge pull request #3262 from github/mergeback/v4.31.2-to-main-0499de31
...
Mergeback v4.31.2 refs/heads/releases/v4 into main
2025-10-30 15:07:33 +00:00
github-actions[bot]
65da12b256
Rebuild
2025-10-30 14:36:57 +00:00
github-actions[bot]
c228fecc25
Update changelog and version after v4.31.2
2025-10-30 14:33:10 +00:00
Henry Mercer
0499de31b9
Merge pull request #3261 from github/henrymercer/setup-python
...
Set up Python in mergeback workflow
2025-10-30 14:30:19 +00:00
Henry Mercer
3b96745d2b
Set up Python in mergeback workflow
2025-10-30 14:06:12 +00:00
Michael B. Gale
8a06050a8c
Merge pull request #3259 from github/update-v4.31.2-9576b5cbe
...
Merge main into releases/v4
2025-10-30 13:47:48 +00:00
github-actions[bot]
752a642cb2
Update changelog for v4.31.2
2025-10-30 13:27:33 +00:00
Michael B. Gale
9576b5cbe8
Merge pull request #3258 from github/mbg/enablement-errors/case-insensitive
...
Make `isEnablementError` case-insensitive
2025-10-30 11:59:43 +00:00
Henry Mercer
cc8843728c
Merge pull request #3257 from github/henrymercer/ubuntu-slim
...
Run lightweight workflows on `ubuntu-slim`
2025-10-30 11:44:22 +00:00
Michael B. Gale
f0e9bf07f4
Make isEnablementError case-insensitive
2025-10-30 11:37:07 +00:00
Henry Mercer
2a3599c520
Run lightweight workflows on ubuntu-slim
2025-10-30 11:25:32 +00:00
Henry Mercer
514ff4d116
Merge pull request #3256 from github/henrymercer/resolve-bad-merge
...
Remove unused `console-log-level` dependency
2025-10-30 11:19:24 +00:00
Henry Mercer
aab1c2f931
Merge pull request #3253 from github/mergeback/v4.31.1-to-main-5fe9434c
...
Mergeback v4.31.1 refs/heads/releases/v4 into main
2025-10-30 11:04:54 +00:00
Henry Mercer
b2bffa615d
Remove unused console-log-level dependency
...
This was added back by a bad merge.
2025-10-30 10:40:23 +00:00
github-actions[bot]
e7811794d3
Rebuild
2025-10-30 10:31:33 +00:00
github-actions[bot]
c7a5b09374
Merge remote-tracking branch 'origin/main' into mergeback/v4.31.1-to-main-5fe9434c
2025-10-30 10:30:29 +00:00
github-actions[bot]
cbcb06a3ae
Update changelog and version after v4.31.1
2025-10-30 10:29:22 +00:00
Henry Mercer
5fe9434cd2
Merge pull request #3252 from github/update-v4.31.1-777daa0c7
...
Merge main into releases/v4
2025-10-30 10:28:34 +00:00
Henry Mercer
8d50be301c
Merge pull request #3245 from github/dependabot/github_actions/dot-github/workflows/actions/download-artifact-6
...
Bump actions/download-artifact from 5 to 6 in /.github/workflows
2025-10-30 10:02:36 +00:00
github-actions[bot]
237497c8f0
Update changelog for v4.31.1
2025-10-30 09:40:55 +00:00
Michael B. Gale
777daa0c71
Merge pull request #3239 from github/mbg/remove/add-snippets
...
Remove `add-snippets` input
2025-10-29 13:32:20 +00:00
Michael B. Gale
74c8748a6f
Update analyze/action.yml
...
Co-authored-by: Esben Sparre Andreasen <esbena@github.com >
2025-10-29 10:34:13 +00:00
Michael B. Gale
34c50c1d29
Merge pull request #3251 from github/mbg/user-error/enablement
...
Turn enablement errors into configuration errors
2025-10-29 09:57:38 +00:00
Michael B. Gale
4ae68afd84
Warn if the add-snippets input is used
2025-10-29 09:29:28 +00:00
Michael B. Gale
52a7bd7b6e
Check for 403 status
2025-10-29 08:35:19 +00:00
Michael B. Gale
194ba0ee2d
Make error message tests less brittle
2025-10-29 08:29:11 +00:00
Michael B. Gale
53acf0b8aa
Turn enablement errors into configuration errors
2025-10-28 21:17:30 +00:00
Henry Mercer
ac9aeee226
Merge pull request #3249 from github/henrymercer/api-logging
...
Use Actions logger in API client
2025-10-28 17:05:58 +00:00
Henry Mercer
d49e837b8c
Merge branch 'main' into henrymercer/api-logging
2025-10-28 16:49:10 +00:00
Henry Mercer
3d988b275a
Pass minimal copy of core
2025-10-28 16:33:21 +00:00
Henry Mercer
8cc18acfa4
Merge pull request #3250 from github/henrymercer/prefer-fs-delete
...
Use Node `fs` APIs instead of `del`
2025-10-28 15:45:56 +00:00
Henry Mercer
ea5cb4a016
Merge branch 'main' into henrymercer/prefer-fs-delete
2025-10-28 15:26:42 +00:00
Henry Mercer
e1c8976a56
Merge pull request #3247 from github/henrymercer/disk-usage-node-api
...
Check disk usage using Node.js API
2025-10-28 15:24:12 +00:00
Henry Mercer
4256e2e2a0
Merge branch 'main' into henrymercer/disk-usage-node-api
2025-10-28 15:05:13 +00:00
Henry Mercer
66459ea37c
Apply suggestion
2025-10-28 15:04:31 +00:00
Henry Mercer
1af9394995
Merge pull request #3244 from github/dependabot/github_actions/dot-github/workflows/actions-minor-b11285d543
...
Bump ruby/setup-ruby from 1.265.0 to 1.267.0 in /.github/workflows in the actions-minor group across 1 directory
2025-10-28 13:28:36 +00:00
Henry Mercer
311fc42780
Merge pull request #3242 from github/dependabot/npm_and_yarn/npm-minor-75b724c14c
...
Bump the npm-minor group with 4 updates
2025-10-28 13:25:25 +00:00
Henry Mercer
284bf9b047
Merge pull request #3241 from github/dependabot/github_actions/dot-github/workflows/actions/upload-artifact-5
...
Bump actions/upload-artifact from 4 to 5 in /.github/workflows
2025-10-28 13:23:08 +00:00
Henry Mercer
a53e78ee2a
Merge pull request #3243 from github/dependabot/npm_and_yarn/actions/artifact-4.0.0
...
Bump @actions/artifact from 2.3.1 to 4.0.0
2025-10-28 13:12:23 +00:00
Henry Mercer
d84f470a9a
Improve method naming
2025-10-28 13:06:14 +00:00
Henry Mercer
41c0a26213
Use Node fs APIs instead of del
2025-10-28 13:00:25 +00:00
Henry Mercer
d4ba404a20
Tweak assertions
2025-10-28 12:50:22 +00:00
Henry Mercer
55895ef678
Stub GITHUB_WORKSPACE in test
2025-10-28 12:45:22 +00:00
Henry Mercer
fe16891f40
Add unit test for checkDiskUsage
2025-10-28 12:40:23 +00:00
Henry Mercer
57c7b6afb6
Disable SIP disablement check
2025-10-28 12:35:41 +00:00
Michael B. Gale
44aeac1a37
Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/download-artifact-6
2025-10-28 12:21:17 +00:00
Henry Mercer
8b1e55d11e
Use Actions logger in API client
...
This allows us to remove the `console-log-level` dependency.
2025-10-28 12:15:03 +00:00
Henry Mercer
20900ee769
Build: Run npm install when package-lock.json out of date
2025-10-28 11:52:42 +00:00
Michael B. Gale
ad8ad9829e
Merge pull request #3240 from github/mbg/allow-skip-workflow-validation
...
Support skipping workflow validation
2025-10-28 11:46:08 +00:00
Henry Mercer
239e305d18
Check disk usage using Node.js API
...
This was introduced in Node.js 18
2025-10-27 18:34:23 +00:00
dependabot[bot]
9c39f0afb0
Bump actions/download-artifact from 5 to 6 in /.github/workflows
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 5 to 6.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-27 18:05:01 +00:00
github-actions[bot]
fcc1377ac6
Rebuild
2025-10-27 17:54:41 +00:00
dependabot[bot]
b5bbb5ab73
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.265.0 to 1.267.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/ab177d40ee5483edb974554986f56b33477e21d0...d5126b9b3579e429dd52e51e68624dda2e05be25 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.267.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-27 17:52:58 +00:00
github-actions[bot]
723a9469fd
Rebuild
2025-10-27 17:41:35 +00:00
dependabot[bot]
f9eed03ba2
Bump @actions/artifact from 2.3.1 to 4.0.0
...
Bumps [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact ) from 2.3.1 to 4.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/@actions/cache@4.0.0/packages/artifact )
---
updated-dependencies:
- dependency-name: "@actions/artifact"
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-27 17:39:59 +00:00
github-actions[bot]
df9e49e9e8
Rebuild
2025-10-27 17:37:24 +00:00
dependabot[bot]
c9d47e2ee9
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@octokit/types](https://github.com/octokit/types.ts ), [@types/archiver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/archiver ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@octokit/types` from 15.0.0 to 15.0.1
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v15.0.0...v15.0.1 )
Updates `@types/archiver` from 6.0.3 to 6.0.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/archiver )
Updates `@typescript-eslint/eslint-plugin` from 8.46.1 to 8.46.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.2/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.1 to 8.46.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.2/packages/parser )
---
updated-dependencies:
- dependency-name: "@octokit/types"
dependency-version: 15.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@types/archiver"
dependency-version: 6.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.46.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.46.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-27 17:35:52 +00:00
github-actions[bot]
714962e17a
Rebuild
2025-10-27 17:30:37 +00:00
dependabot[bot]
42f957bb51
Bump actions/upload-artifact from 4 to 5 in /.github/workflows
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 4 to 5.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-27 17:28:57 +00:00
Michael B. Gale
52cec4178d
Downgrade log message from warning to debug level
2025-10-27 17:02:01 +00:00
Michael B. Gale
55c083790a
Move checkWorkflow to workflow.ts
2025-10-27 17:01:23 +00:00
Michael B. Gale
50601762ea
Also skip workflow validation for dynamic workflows
2025-10-27 16:10:08 +00:00
Michael B. Gale
06fbd897c4
Move workflow check to a function in init.ts and add tests
2025-10-27 15:57:44 +00:00
Michael B. Gale
127851b399
Add environment variable for skipping workflow validation
2025-10-27 15:42:43 +00:00
Kasper Svendsen
8d77149e0c
Merge pull request #3238 from github/kaspersv/extract-diff-range-computation
...
Move diff-range computation into utils
2025-10-27 15:40:12 +01:00
Michael B. Gale
db47d17142
Remove add-snippets input
2025-10-27 12:53:23 +00:00
Kasper Svendsen
cc17bed958
Move diff-range computation tests
2025-10-27 09:46:16 +01:00
Kasper Svendsen
91ec0ed58f
Move diff-range computation into utils for reuse
2025-10-27 09:43:11 +01:00
Kasper Svendsen
4e0b2cd814
Merge pull request #3232 from github/kaspersv/unique-overlay-base-keys
...
Ensure uniqueness of overlay-base database cache keys
2025-10-27 08:36:12 +01:00
Michael B. Gale
ae78991f55
Merge pull request #3236 from github/mergeback/v4.31.0-to-main-4e94bd11
...
Mergeback v4.31.0 refs/heads/releases/v4 into main
2025-10-24 18:30:37 +01:00
github-actions[bot]
dd565f3332
Rebuild
2025-10-24 17:11:09 +00:00
github-actions[bot]
fa46f22b12
Update changelog and version after v4.31.0
2025-10-24 17:08:58 +00:00
Michael B. Gale
4e94bd11f7
Merge pull request #3235 from github/update-v4.31.0-1d36546c1
...
Merge main into releases/v4
2025-10-24 18:08:08 +01:00
github-actions[bot]
8f11182164
Update changelog for v4.31.0
2025-10-24 16:33:59 +00:00
Michael B. Gale
1d36546c14
Merge pull request #3234 from github/mbg/changelog/post-processing
...
Add changelog entry for post-processing change
2025-10-24 17:26:22 +01:00
Michael B. Gale
08ada26e6a
Add changelog entry for post-processing change
2025-10-24 17:07:13 +01:00
Michael B. Gale
b843cbeed0
Merge pull request #3233 from github/mbg/getOptionalEnvVar
...
Add `getOptionalEnvVar` helper
2025-10-24 16:55:48 +01:00
Michael B. Gale
1ecd563919
Use getOptionalEnvVar in writePostProcessedFiles
2025-10-24 16:18:09 +01:00
Henry Mercer
e576807920
Merge pull request #3223 from github/henrymercer/bump-minimum
...
Bump minimum CodeQL Bundle version to 2.17.6
2025-10-24 15:11:27 +01:00
Michael B. Gale
ad35676669
Add getOptionalEnvVar function
...
Also add tests for it and `getRequiredEnvParam`
2025-10-24 15:00:42 +01:00
Michael B. Gale
d75645b13f
Merge pull request #3222 from github/mbg/upload-lib/post-process
...
Perform SARIF post-processing independently of upload
2025-10-24 14:59:04 +01:00
Kasper Svendsen
66759e57b2
Improve error handling for overlay-base cache key creation
2025-10-24 15:49:26 +02:00
Kasper Svendsen
cbcae45fff
Reorder components of overlay-base cache key postfix
2025-10-24 15:46:17 +02:00
Michael B. Gale
710606cc35
Check that outputPath is non-empty
2025-10-24 14:42:36 +01:00
Michael B. Gale
f0452d5366
Consistently use "post-processing"
2025-10-24 10:20:25 +01:00
Kasper Svendsen
956c56734d
Merge pull request #3231 from github/kaspersv/lower-overlay-base-size-limit
...
Overlay: Lower size limit for overlay base databases
2025-10-24 11:12:25 +02:00
Kasper Svendsen
b4ce335286
Ensure uniqueness of overlay-base database cache keys
2025-10-24 11:11:57 +02:00
Michael B. Gale
b9cd36824e
Merge remote-tracking branch 'origin/main' into mbg/upload-lib/post-process
2025-10-24 10:08:38 +01:00
Chuan-kai Lin
c4b73722ba
Add overlay-base database cache key tests
2025-10-24 10:47:17 +02:00
Kasper Svendsen
22d29ca74d
Overlay: Lower size limit for overlay base databases
2025-10-24 08:06:42 +02:00
Michael B. Gale
9625890712
Merge pull request #3227 from github/mbg/permission-warning
...
Update wording in some log messages
2025-10-23 16:30:13 +01:00
Michael B. Gale
690d276755
Merge branch 'main' into mbg/permission-warning
2025-10-23 15:50:48 +01:00
Michael B. Gale
1c3c8066c3
Merge pull request #3228 from github/mbg/test/timeout
...
Bump timeout for `analyze-action-env` test
2025-10-23 15:49:27 +01:00
Michael B. Gale
da64a41e37
Bump timeout for analyze-action-input test
2025-10-23 15:23:21 +01:00
Michael B. Gale
8376af204a
Bump timeout for analyze-action-env test
2025-10-23 13:39:38 +01:00
Michael B. Gale
f48b54af10
Fix fallback not being guarded by uploadKind check
2025-10-23 13:34:03 +01:00
Michael B. Gale
40b4cdd21f
Update status report messages
2025-10-23 13:12:19 +01:00
Michael B. Gale
e849c567ec
Update debug message
2025-10-23 13:04:06 +01:00
Michael B. Gale
d1b51f05c9
Update API permissions warning
2025-10-23 13:02:31 +01:00
Michael B. Gale
aed27f7231
Fix linter issue
2025-10-22 19:25:34 +01:00
Michael B. Gale
8ff870a6c2
Rename new input to processed-sarif-path
2025-10-22 19:12:57 +01:00
Michael B. Gale
6f0fcbeea7
Rename uploadSarif
2025-10-22 19:09:39 +01:00
Michael B. Gale
89d3359017
Improve test name
2025-10-22 19:05:05 +01:00
Michael B. Gale
d79c0a1339
Fix incomplete comment
2025-10-22 19:03:23 +01:00
Michael B. Gale
5e37670026
Use post-process-output in PR check
2025-10-22 19:01:42 +01:00
Michael B. Gale
def04c1c0e
Add test for uploadSarif with output directory
2025-10-22 19:01:42 +01:00
Michael B. Gale
12f3cfef09
Write processed SARIF files if post-process-output input is provided
2025-10-22 19:01:40 +01:00
Michael B. Gale
c2bec36917
Add post-process-output input to analyze action
2025-10-22 19:00:33 +01:00
Michael B. Gale
14139c9f77
Add test for uploadSarif with upload: never
2025-10-22 19:00:33 +01:00
Michael B. Gale
596de7f1bc
Move UploadKind check into uploadSarif
2025-10-22 19:00:29 +01:00
Michael B. Gale
899bf2fd1e
Use postProcessSarifFiles and uploadProcessedFiles in uploadSarif
2025-10-22 18:48:24 +01:00
Michael B. Gale
6fbdd5f4e9
Split SARIF uploading steps from uploadSpecifiedFiles into a function
2025-10-22 18:48:03 +01:00
Michael B. Gale
489ed914f1
Split SARIF post-processing steps from uploadSpecifiedFiles into a function
2025-10-22 18:48:00 +01:00
Michael B. Gale
42642085de
Merge pull request #3206 from github/mbg/analyze/use-upload-sarif
...
Use `uploadSarif` rather than `uploadFiles` in `analyze` action
2025-10-22 17:45:25 +01:00
Henry Mercer
4bd7dfe989
Merge pull request #3226 from github/henrymercer/prefer-optional-chaining
...
Linting: Prefer optional chaining
2025-10-22 17:13:00 +01:00
Michael B. Gale
ebd514f490
Address review comments
2025-10-22 17:11:19 +01:00
Henry Mercer
a691497d40
Clean up resolve_supported_languages_using_cli FF
2025-10-22 17:04:42 +01:00
Henry Mercer
e5f165b8f5
Linting: Prefer optional chaining
2025-10-22 16:55:06 +01:00
Michael B. Gale
c98d5a9a4f
Use checkoutPath and category constants consistently
2025-10-22 16:12:07 +01:00
Michael B. Gale
b7c814cb39
Gate uploadSarif behind FF, use old implementation otherwise
2025-10-22 15:54:51 +01:00
Michael B. Gale
f88cb01694
Add AnalyzeUseNewUpload feature
2025-10-22 15:49:28 +01:00
Henry Mercer
3cd3374657
Bump minor version number
2025-10-22 12:27:15 +01:00
Henry Mercer
3934593862
Remove analysisSummaryV2Default FF
2025-10-22 12:25:25 +01:00
Henry Mercer
bab3f2b5f5
Remove sarifMergeRunsFromEqualCategory FF
2025-10-22 12:22:55 +01:00
Henry Mercer
9924f476ba
Add changelog note
2025-10-22 12:20:17 +01:00
Henry Mercer
bd5f49c7ca
Bump minimum version to 2.17.6
2025-10-22 12:19:35 +01:00
Michael B. Gale
02b2c3aafc
Fix style inconsistency
2025-10-22 12:04:04 +01:00
Michael B. Gale
aa048acb05
Merge branch 'main' into mbg/analyze/use-upload-sarif
2025-10-22 00:42:55 +01:00
Michael B. Gale
0c5185d061
Merge pull request #3221 from github/mbg/code-quality/skip-db-upload
...
Always skip database upload if `AnalysisKind.CodeScanning` is not enabled
2025-10-21 13:10:37 +01:00
Michael B. Gale
79ed9569a3
Always skip database upload if AnalysisKind.CodeScanning is not enabled
2025-10-21 12:33:56 +01:00
Henry Mercer
8e53c48f94
Merge pull request #3217 from github/henrymercer/http-error-handling
...
Wrap API configuration errors when setting up CodeQL
2025-10-21 12:15:21 +01:00
Henry Mercer
804fc665f9
Merge branch 'main' into henrymercer/http-error-handling
2025-10-21 10:37:41 +01:00
Henry Mercer
e6e649a8f3
Simplify API error checks
2025-10-21 10:31:53 +01:00
Henry Mercer
40e26468f3
Require message field too
2025-10-21 10:27:54 +01:00
Michael B. Gale
9b0ac1cc3b
Merge pull request #3203 from github/mbg/errors/more-user-errors
...
Handle user errors for invalid `UserConfig`s and missing query files
2025-10-20 19:32:51 +01:00
Michael B. Gale
ffed63adb8
Merge pull request #3219 from github/dependabot/npm_and_yarn/npm-minor-5ed6ededba
...
Bump the npm-minor group with 5 updates
2025-10-20 19:14:12 +01:00
Michael B. Gale
bee06ec042
Merge pull request #3220 from github/dependabot/github_actions/dot-github/workflows/actions/setup-node-6
...
Bump actions/setup-node from 5 to 6 in /.github/workflows
2025-10-20 19:09:32 +01:00
github-actions[bot]
06f31ec789
Rebuild
2025-10-20 17:27:37 +00:00
dependabot[bot]
53588c5ad2
Bump actions/setup-node from 5 to 6 in /.github/workflows
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 5 to 6.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-20 17:26:07 +00:00
github-actions[bot]
2357c43cad
Rebuild
2025-10-20 17:18:26 +00:00
dependabot[bot]
a3ff966dbf
Bump the npm-minor group with 5 updates
...
Bumps the npm-minor group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [octokit](https://github.com/octokit/octokit.js ) | `5.0.3` | `5.0.4` |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.37.0` | `9.38.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.46.0` | `8.46.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.46.0` | `8.46.1` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.25.10` | `0.25.11` |
Updates `octokit` from 5.0.3 to 5.0.4
- [Release notes](https://github.com/octokit/octokit.js/releases )
- [Commits](https://github.com/octokit/octokit.js/compare/v5.0.3...v5.0.4 )
Updates `@eslint/js` from 9.37.0 to 9.38.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.38.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.46.0 to 8.46.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.0 to 8.46.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.1/packages/parser )
Updates `esbuild` from 0.25.10 to 0.25.11
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.10...v0.25.11 )
---
updated-dependencies:
- dependency-name: octokit
dependency-version: 5.0.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@eslint/js"
dependency-version: 9.38.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.46.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.46.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.25.11
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-20 17:17:00 +00:00
Henry Mercer
6562050a4e
Merge pull request #3218 from github/henrymercer/pr-sizes
...
Add experimental functionality for labelling PRs by their size
2025-10-20 17:45:46 +01:00
Henry Mercer
e9daf5bcd9
Comment version that is pinned
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2025-10-20 17:25:01 +01:00
Henry Mercer
c13672ee32
Bump sizes a bit
2025-10-20 16:48:51 +01:00
Henry Mercer
f2f52d0d47
Add score for XL
2025-10-20 15:13:53 +01:00
Henry Mercer
08e53bec85
Update .github/sizeup.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-10-20 15:12:50 +01:00
Henry Mercer
519594fe94
Update workflow name
2025-10-20 15:12:25 +01:00
Henry Mercer
8c324fe288
Add experimental functionality for labelling PRs by their size
2025-10-20 15:10:40 +01:00
Henry Mercer
a6b9514fab
Wrap API configuration errors when setting up CodeQL
2025-10-20 15:01:44 +01:00
Henry Mercer
c64c4070cc
Handle HTTP errors with httpStatusCode property
2025-10-20 14:38:02 +01:00
Henry Mercer
d88a5540c3
Merge pull request #3215 from github/mergeback/v4.30.9-to-main-16140ae1
...
Mergeback v4.30.9 refs/heads/releases/v4 into main
2025-10-17 17:06:54 +01:00
github-actions[bot]
aa0f6ea898
Rebuild
2025-10-17 15:40:22 +00:00
github-actions[bot]
b03dcd5d9d
Update changelog and version after v4.30.9
2025-10-17 15:23:37 +00:00
Henry Mercer
16140ae1a1
Merge pull request #3213 from github/update-v4.30.9-70205d3d1
...
Merge main into releases/v4
2025-10-17 16:22:48 +01:00
github-actions[bot]
30db5fee08
Update changelog for v4.30.9
2025-10-17 14:54:08 +00:00
Michael B. Gale
9ce56a247f
Make schema for QueryFilter less strict
2025-10-17 15:11:16 +01:00
Michael B. Gale
2c8f4891d1
Add FF for config validation
2025-10-17 15:11:13 +01:00
Michael B. Gale
d7a8ae5fdd
Include first 10 errors in exception message
2025-10-17 15:09:05 +01:00
Michael B. Gale
0822fb12e7
Log validation errors
2025-10-17 15:09:04 +01:00
Michael B. Gale
913cd47984
Add checkExpectedLogMessages function to testing-utils
2025-10-17 15:09:04 +01:00
Michael B. Gale
4f14649ced
Add additional regex to CliConfigErrorCategory.PackCannotBeFound
2025-10-17 15:09:03 +01:00
Michael B. Gale
ac922ab562
Add and validate UserConfig schema
2025-10-17 15:09:01 +01:00
Michael B. Gale
66df0bc515
Add and use parseUserConfig
...
- Throws a `ConfigurationError` if parsing the YAML fails
- Add a couple of tests for it
2025-10-17 15:08:59 +01:00
Michael B. Gale
70205d3d12
Merge pull request #3211 from github/mbg/init/starting-partial-config
...
Make analysis kinds available for `starting` status report
2025-10-17 14:46:51 +01:00
Michael B. Gale
697c209bfc
Merge remote-tracking branch 'origin/main' into mbg/init/starting-partial-config
2025-10-17 14:21:44 +01:00
Henry Mercer
1bd53ba38c
Merge pull request #3205 from github/update-bundle/codeql-bundle-v2.23.3
...
Update default bundle to 2.23.3
2025-10-17 14:18:19 +01:00
github-actions[bot]
cac4df0c79
Rebuild
2025-10-17 12:59:18 +00:00
Henry Mercer
77e5c0d0a2
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.3
2025-10-17 13:53:02 +01:00
Michael B. Gale
97a4f751be
Merge pull request #3204 from github/mbg/setup-codeql
...
Add `setup-codeql` action
2025-10-17 13:47:42 +01:00
Michael B. Gale
2d5512b361
Merge remote-tracking branch 'origin/main' into mbg/init/starting-partial-config
2025-10-17 13:44:28 +01:00
Michael B. Gale
fa7bdf0559
Call getAnalysisKinds a second time, and ignore exceptions thrown during the first call
2025-10-17 13:40:18 +01:00
Michael B. Gale
57c7b0a884
Rename initAnalysisKinds to getAnalysisKinds and cache results
2025-10-17 13:33:55 +01:00
Michael B. Gale
4874f90a8d
Merge branch 'main' into mbg/setup-codeql
2025-10-17 13:32:40 +01:00
Michael B. Gale
5a9e92afca
Merge pull request #3212 from github/mbg/ci/pin-python
...
Install Python 3.13 to fix failing PR checks with older CLI versions
2025-10-17 13:31:26 +01:00
Michael B. Gale
9bd9b03572
Remove now unused qualityQueriesInput from InitConfigInputs
2025-10-17 13:22:41 +01:00
Michael B. Gale
3569065d7e
Install Python 3.13, except for nightly-latest
2025-10-17 12:51:50 +01:00
Michael B. Gale
c0e8887d5a
Throw a ConfigurationError if setup-codeql has run before init
2025-10-17 12:17:47 +01:00
Michael B. Gale
3c8d00aea0
Initialise analysis kinds before starting status report
2025-10-17 11:46:35 +01:00
Michael B. Gale
bc93b04b0c
Add initAnalysisKinds for analysis-kinds enablement logic
2025-10-17 11:43:00 +01:00
Michael B. Gale
adf39dd33f
Add function for starting status report
2025-10-17 11:16:00 +01:00
Michael B. Gale
000295122d
Use failure instead of aborted
2025-10-16 19:05:03 +01:00
Michael B. Gale
2611d033d7
De-duplicate InitToolsDownloadFIelds definition
2025-10-16 19:03:46 +01:00
Michael B. Gale
ee753b4724
Merge pull request #3209 from github/mbg/code-quality/skip-failed-upload
...
Skip failed SARIF upload if Code Quality is the only analysis kind
2025-10-16 15:22:01 +01:00
Michael B. Gale
db6938a4d0
Change check to be restrictive by default
2025-10-16 15:06:19 +01:00
Michael B. Gale
d02f50ee62
Update changelog for setup-codeql
2025-10-16 14:50:16 +01:00
Michael B. Gale
f4237b7e76
Add setup-codeql to README
2025-10-16 14:48:35 +01:00
Michael B. Gale
302fc5e00d
Update docs
2025-10-16 14:46:35 +01:00
Michael B. Gale
c77b3fb96e
Skip failed SARIF upload if analysis-kinds: code-quality
2025-10-16 14:27:17 +01:00
Michael B. Gale
2a54ab5016
Fix init-action-post-helper tests using broken Configs
2025-10-16 14:18:51 +01:00
Michael B. Gale
2ade8a09a3
Use uploadSarif rather than uploadFiles in analyze action
2025-10-14 19:49:42 +01:00
github-actions[bot]
a60e5ce8ec
Add changelog note
2025-10-14 12:53:29 +00:00
github-actions[bot]
8d0251c1f7
Update default bundle to codeql-bundle-v2.23.3
2025-10-14 12:53:17 +00:00
Michael B. Gale
80220dcd46
Use setup-codeql action in bundle-from-toolcache check
2025-10-12 14:14:07 +01:00
Michael B. Gale
e72fd9acb1
Add initial setup-codeql action
2025-10-12 14:14:06 +01:00
Michael B. Gale
17783bfb99
Merge pull request #3199 from github/mergeback/v4.30.8-to-main-f443b600
...
Mergeback v4.30.8 refs/heads/releases/v4 into main
2025-10-10 18:16:14 +01:00
Henry Mercer
3c764cd93a
Only create GitHub release if it doesn't already exist
2025-10-10 17:54:08 +01:00
Henry Mercer
e1968324ff
Merge branch 'releases/v4' into mergeback/v4.30.8-to-main-f443b600
2025-10-10 17:53:24 +01:00
Henry Mercer
2a6736cca7
Merge pull request #3200 from github/henrymercer/backport-hotfix
...
Revert "Rebuild" commit rather than "Update dependencies"
2025-10-10 17:47:40 +01:00
Henry Mercer
c8765c966b
Revert "Rebuild" commit rather than "Update dependencies"
2025-10-10 17:23:02 +01:00
github-actions[bot]
61789e2fdb
Rebuild
2025-10-10 15:59:22 +00:00
github-actions[bot]
5cd2d139cb
Update changelog and version after v4.30.8
2025-10-10 15:55:20 +00:00
Michael B. Gale
f443b600d9
Merge pull request #3198 from github/update-v4.30.8-527f0f324
...
Merge main into releases/v4
2025-10-10 16:54:36 +01:00
github-actions[bot]
7a2cb623ed
Update changelog for v4.30.8
2025-10-10 14:34:56 +00:00
Henry Mercer
527f0f324a
Merge pull request #3195 from github/dependabot/npm_and_yarn/npm-minor-37415c9066
...
Bump the npm-minor group with 3 updates
2025-10-10 15:22:52 +01:00
Henry Mercer
f402506f0f
Merge pull request #3196 from github/dependabot/github_actions/dot-github/workflows/actions-minor-945aab589d
...
Bump ruby/setup-ruby from 1.263.0 to 1.265.0 in /.github/workflows in the actions-minor group across 1 directory
2025-10-10 15:20:16 +01:00
Henry Mercer
f5e53f9476
Merge pull request #3197 from github/dependabot/github_actions/dot-github/workflows/github/codeql-action-4
...
Bump github/codeql-action from 3 to 4 in /.github/workflows
2025-10-10 15:13:23 +01:00
Michael B. Gale
4e90a42a3e
Merge pull request #3193 from github/mbg/ff/tools-toolcache
...
Gate `tools: toolcache` behind FF
2025-10-10 15:09:00 +01:00
github-actions[bot]
413a4a4df1
Rebuild
2025-10-10 13:49:43 +00:00
dependabot[bot]
452186448a
Bump github/codeql-action from 3 to 4 in /.github/workflows
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3 to 4.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-10 13:48:11 +00:00
dependabot[bot]
eadf14bf6e
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.263.0 to 1.265.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/0481980f17b760ef6bca5e8c55809102a0af1e5a...ab177d40ee5483edb974554986f56b33477e21d0 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.265.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-10 13:48:07 +00:00
github-actions[bot]
e1257b6fda
Rebuild
2025-10-10 13:47:47 +00:00
dependabot[bot]
b516b1d4bc
Bump the npm-minor group with 3 updates
...
Bumps the npm-minor group with 3 updates: [semver](https://github.com/npm/node-semver ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `semver` from 7.7.2 to 7.7.3
- [Release notes](https://github.com/npm/node-semver/releases )
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md )
- [Commits](https://github.com/npm/node-semver/compare/v7.7.2...v7.7.3 )
Updates `@typescript-eslint/eslint-plugin` from 8.45.0 to 8.46.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.45.0 to 8.46.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.46.0/packages/parser )
---
updated-dependencies:
- dependency-name: semver
dependency-version: 7.7.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.46.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.46.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-10 13:46:16 +00:00
Henry Mercer
168b2dee16
Merge pull request #3194 from github/henrymercer-patch-1
...
Dependabot: Only group minor and patch updates
2025-10-10 14:44:22 +01:00
Michael B. Gale
4704ab1869
Fix swapped log levels
2025-10-10 14:42:09 +01:00
Michael B. Gale
dc2ced8385
Add tests for scenarios where the feature is unavailable
2025-10-10 14:39:59 +01:00
Michael B. Gale
5c752c85dd
Add test macro for fallback tests
2025-10-10 14:39:58 +01:00
Henry Mercer
e74435a1da
Dependabot: Only group minor and patch updates
...
Major updates are likely to include breaking changes and are worth reviewing individually.
2025-10-10 14:28:32 +01:00
Michael B. Gale
524b9a00e8
Fix log message swap
2025-10-10 14:04:39 +01:00
Michael B. Gale
a512fe0868
Gate tools: toolcache behind FF
...
Mainly to allow us to disable it, if needed.
2025-10-10 13:49:06 +01:00
Michael B. Gale
62f0f21c3c
Add AllowToolcacheInput feature
2025-10-10 13:27:50 +01:00
Paolo Tranquilli
a8440d08d5
Merge pull request #3185 from github/redsun82/skip-sarif-upload-tests
...
Add unit tests for `uploadPayload`
2025-10-10 14:00:05 +02:00
Paolo Tranquilli
610c7c68e3
Address review
2025-10-09 15:24:02 +02:00
Paolo Tranquilli
ff2fc66cc1
Simplify uploadPayload tests
2025-10-09 12:31:00 +02:00
Paolo Tranquilli
a841c540b7
Scratch uploadSpecifiedFiles tests, make uploadPayload tests instead
2025-10-09 12:18:14 +02:00
Paolo Tranquilli
aeb12f6eaa
Merge branch 'main' into redsun82/skip-sarif-upload-tests
2025-10-09 11:38:10 +02:00
Henry Mercer
6fd4ceb7bb
Merge pull request #3189 from github/henrymercer/download-codeql-rate-limit
...
Add configuration error for rate limited CodeQL download
2025-10-08 15:11:29 +01:00
Michael B. Gale
196a3e577b
Merge pull request #3188 from github/mbg/telemetry/partial-config
...
Allow `Partial<Config>` for `createStatusReportBase`
2025-10-08 14:59:05 +01:00
Henry Mercer
98abb870dc
Add configuration error for rate limited CodeQL download
2025-10-08 14:43:54 +01:00
Michael B. Gale
bdd2cdf891
Also include language in error status report for start-proxy, if available
2025-10-08 13:13:04 +01:00
Michael B. Gale
fb148789ab
Include languages in start-proxy telemetry
2025-10-08 13:01:35 +01:00
Michael B. Gale
2ff418f28a
Parse language before calling getCredentials
2025-10-08 13:01:35 +01:00
Michael B. Gale
527501d15d
Allow createStatusReportBase to accept a Partial<Config>
2025-10-08 13:01:35 +01:00
Paolo Tranquilli
621809b239
Address copilot review
2025-10-08 12:24:49 +02:00
Paolo Tranquilli
8301b8b096
Merge pull request #3180 from github/redsun82/skip-sarif-upload
...
Introduce `CODEQL_ACTION_SKIP_SARIF_UPLOAD`
2025-10-08 12:09:54 +02:00
Nick Rolfe
7bdfa9736a
Merge pull request #3184 from github/nickrolfe/go-overlay
...
Overlays: allow any build mode for Go
2025-10-08 10:48:40 +01:00
Paolo Tranquilli
a57997f2d2
Fix test after rebase
2025-10-08 09:34:48 +02:00
Paolo Tranquilli
4489a63a9d
Add unit tests for uploadSpecifiedFiles
2025-10-08 09:34:48 +02:00
Paolo Tranquilli
1707898e5b
Merge branch 'main' into redsun82/skip-sarif-upload
2025-10-08 09:34:05 +02:00
Paolo Tranquilli
d05f2255a0
Tweak comment
2025-10-08 09:34:01 +02:00
Nick Rolfe
7892cb2362
Overlays: allow any build mode for Go
...
We have a check that a traced language can only run overlay analysis
with build-mode: none, but Go does not currently declare support for
BMN, even though it has a similar autobuild mode that will work for
overlay analysis.
This commit adds a hard-coded exception to that check, allowing any
build mode for Go. This is intended as a short-term solution until Go
declares BMN support. It should be safe, since we can choose not to
enable the feature flag for Go repos using traced builds.
2025-10-07 17:45:08 +01:00
Mario Campos
8a6b62bc2d
Merge pull request #3186 from github/mergeback/v4.30.7-to-main-e296a935
...
Mergeback v4.30.7 refs/heads/releases/v4 into main
2025-10-07 11:20:49 -05:00
github-actions[bot]
d95a3b53f8
Rebuild
2025-10-07 16:01:48 +00:00
github-actions[bot]
257e42ce3d
Merge remote-tracking branch 'origin/main' into mergeback/v4.30.7-to-main-e296a935
2025-10-07 16:01:00 +00:00
github-actions[bot]
074940162c
Update changelog and version after v4.30.7
2025-10-07 15:22:00 +00:00
Mario Campos
e296a93559
Merge pull request #3183 from github/update-v4.30.7-55283843c
...
Merge main into releases/v4
2025-10-07 10:21:14 -05:00
Paolo Tranquilli
df65651d4f
Merge branch 'main' into redsun82/skip-sarif-upload
2025-10-07 17:17:13 +02:00
Paolo Tranquilli
1b09eb4ccc
Address review
2025-10-07 17:17:06 +02:00
Michael B. Gale
2f11c17b09
Merge pull request #3175 from github/mbg/setup/toolcache
...
Support requesting latest version from toolcache with `tools: toolcache`
2025-10-07 10:32:03 +01:00
Michael B. Gale
0ba4970165
Merge branch 'main' into mbg/setup/toolcache
2025-10-07 10:09:12 +01:00
Michael B. Gale
5431b6a308
Merge pull request #3176 from github/mbg/pr-template/tests
...
Add more questions to the PR template
2025-10-07 10:05:07 +01:00
Michael B. Gale
7f5db167b6
Merge branch 'main' into mbg/pr-template/tests
2025-10-07 09:48:29 +01:00
Michael B. Gale
239d7b286f
Merge pull request #3181 from github/mbg/pr-checks/upload-sarif
...
Add more end-to-end tests for `upload-sarif`
2025-10-07 09:48:05 +01:00
Paolo Tranquilli
86b2ad6646
Remove unneeded comment
2025-10-07 10:36:45 +02:00
Paolo Tranquilli
5dfb610e99
Merge branch 'main' into redsun82/skip-sarif-upload
2025-10-07 10:36:12 +02:00
Henry Mercer
1491baa17e
Merge branch 'main' into mbg/pr-checks/upload-sarif
2025-10-07 09:28:42 +01:00
Henry Mercer
db562a696f
Merge pull request #3182 from github/dependabot/npm_and_yarn/npm-b02b6854f6
...
Bump the npm group with 4 updates
2025-10-07 09:16:58 +01:00
github-actions[bot]
93c16735fa
Update changelog for v4.30.7
2025-10-06 18:19:26 +00:00
Mario Campos
55283843ca
Merge pull request #3169 from github/mario-campos/node24
...
[v4] Upgrade Node.js runtime from v20 to v24
2025-10-06 12:52:46 -05:00
github-actions[bot]
6877465dc1
Rebuild
2025-10-06 17:03:52 +00:00
dependabot[bot]
ff23a55f4d
Bump the npm group with 4 updates
...
Bumps the npm group with 4 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [typescript](https://github.com/microsoft/TypeScript ).
Updates `@eslint/js` from 9.36.0 to 9.37.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.37.0/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.44.1 to 8.45.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.45.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.44.1 to 8.45.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.45.0/packages/parser )
Updates `typescript` from 5.9.2 to 5.9.3
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release-publish.yml )
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.9.2...v5.9.3 )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.37.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.45.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.45.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: typescript
dependency-version: 5.9.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-06 17:02:21 +00:00
Mario Campos
b66db86c84
Hoist CHANGELOG note back to "UNRELEASED" section.
2025-10-06 11:40:43 -05:00
Paolo Tranquilli
00a6e13cbf
Tweak SARIF skipping logs
2025-10-06 17:03:29 +02:00
Paolo Tranquilli
25c8db918a
Revert "Specify reason for skipping SARIF upload in logs"
...
This reverts commit 680b07003d .
2025-10-06 16:59:45 +02:00
Michael B. Gale
dabf6fc578
Adjust step names to be clearer
2025-10-06 15:40:35 +01:00
Michael B. Gale
14c5d77032
Fix: Update payload.json path in with-checkout-path test
2025-10-06 15:28:40 +01:00
Michael B. Gale
380e002752
Add explicit category values
2025-10-06 15:15:43 +01:00
Paolo Tranquilli
680b07003d
Specify reason for skipping SARIF upload in logs
2025-10-06 15:39:29 +02:00
Michael B. Gale
22aba57acf
Include analysis kind in payloadSaveFile path in uploadPayload
2025-10-06 14:30:30 +01:00
Paolo Tranquilli
11e4034414
Clarify comment about SKIP_SARIF_UPLOAD setting
2025-10-06 15:23:18 +02:00
Paolo Tranquilli
882667e383
Update src/util.ts
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-10-06 15:22:34 +02:00
Michael B. Gale
6f964b7776
Cover more cases in upload-sarif check
2025-10-06 14:10:49 +01:00
Michael B. Gale
6bdf5d3d00
Run upload-sarif check for all analysis-kinds values
2025-10-06 13:56:19 +01:00
Michael B. Gale
9b3ade946d
Rename upload-quality-sarif.yml workflow
2025-10-06 13:50:21 +01:00
Paolo Tranquilli
e0b9da7b0a
Introduce CODEQL_ACTION_SKIP_SARIF_UPLOAD
...
This triggers a subset of the behavior of `CODEQL_ACTION_TEST_MODE`,
specifically just skipping the SARIF upload step. This is required for
our internal testing where we want the SARIF file (via
`CODEQL_ACTION_DUMP_SARIF_DIR`) but don't want to actually upload it,
but we don't want the rest of the behaviour of `CODEQL_ACTION_TEST_MODE`
that is specific for `codeql-action` own CI checks.
2025-10-06 14:38:32 +02:00
Michael B. Gale
726a341ed4
Restrict when tools: toolcache can be used
2025-10-06 13:16:16 +01:00
Michael B. Gale
1cc5eb6636
Use semver.compare instead of semver.lt
2025-10-06 12:58:00 +01:00
Michael B. Gale
43ce7ef399
Add isDynamicWorkflow function
2025-10-06 12:55:54 +01:00
Michael B. Gale
4d0c164f60
Remove toolcache option description from action.yml
2025-10-06 12:53:17 +01:00
Mario Campos
b2e22323e2
Merge remote-tracking branch 'origin/main' into mario-campos/node24
...
# Conflicts:
# lib/analyze-action-post.js
# lib/analyze-action.js
# lib/autobuild-action.js
# lib/init-action-post.js
# lib/init-action.js
# lib/resolve-environment-action.js
# lib/start-proxy-action-post.js
# lib/start-proxy-action.js
# lib/upload-lib.js
# lib/upload-sarif-action-post.js
# lib/upload-sarif-action.js
# package-lock.json
# package.json
2025-10-03 12:59:21 -05:00
Michael B. Gale
dd9e24a8a4
Add more questions to the PR template
2025-10-03 16:27:36 +01:00
Michael B. Gale
13a3a6890f
Add basic PR check for tools: toolcache
2025-10-03 15:49:29 +01:00
Michael B. Gale
7d468c931c
Accept toolcache as version value for prepare-test
2025-10-03 15:48:04 +01:00
Michael B. Gale
425ef85595
Support requesting CLI from toolcache with tools: toolcache
2025-10-03 15:40:33 +01:00
Michael B. Gale
297313df79
Add getLatestToolcacheVersion with tests
2025-10-03 14:40:34 +01:00
Michael B. Gale
065c6cfb78
Merge pull request #3174 from github/mbg/fix/start-proxy-matrix
...
Make `matrix` available to `start-proxy` action
2025-10-03 12:26:10 +01:00
Michael B. Gale
7fb8378d93
Re-throw exception in createStatusReportBase when in test mode
2025-10-03 11:59:36 +01:00
Mario Campos
dddf033776
Revert changes to build.mjs
2025-10-02 14:32:40 -05:00
Mario Campos
54ae8ba5b1
Simplify PR check by reverting changes to @types/node.
2025-10-02 14:24:46 -05:00
Michael B. Gale
65e9e640ee
Make matrix available to start-proxy action
2025-10-02 17:45:22 +01:00
Nick Rolfe
21a7ba37dd
Merge pull request #3173 from github/mergeback/v3.30.6-to-main-64d10c13
...
Mergeback v3.30.6 refs/heads/releases/v3 into main
2025-10-02 15:15:57 +01:00
github-actions[bot]
70836b1ec4
Rebuild
2025-10-02 13:55:07 +00:00
github-actions[bot]
205744e04f
Update changelog and version after v3.30.6
2025-10-02 13:53:03 +00:00
Nick Rolfe
64d10c1313
Merge pull request #3172 from github/update-v3.30.6-10feb5d2a
...
Merge main into releases/v3
2025-10-02 14:52:21 +01:00
github-actions[bot]
909610e8a8
Update changelog for v3.30.6
2025-10-02 13:28:36 +00:00
Henry Mercer
d899b2ed98
Merge branch 'main' into mario-campos/node24
2025-10-02 12:36:53 +01:00
Michael B. Gale
10feb5d2a2
Merge pull request #3167 from github/mbg/upload-sarif/find-then-filter
...
Find, then filter, SARIF files for `upload-sarif` Action
2025-10-02 11:51:47 +01:00
Nick Rolfe
4182ea3d4e
Merge pull request #3168 from github/update-bundle/codeql-bundle-v2.23.2
...
Update default bundle to 2.23.2
2025-10-02 11:25:07 +01:00
Michael B. Gale
34afe5b7b1
Merge pull request #3171 from github/mbg/start-proxy/telemetry
...
Add basic telemetry for `start-proxy` Action
2025-10-02 11:23:10 +01:00
Nick Rolfe
096fe67f97
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.2
2025-10-02 11:08:29 +01:00
Michael B. Gale
b4964014ad
Merge pull request #3170 from github/mbg/start-proxy/remove-update-workflow
...
Remove `update-proxy-release` workflow
2025-10-02 11:05:22 +01:00
Michael B. Gale
d573787cca
Report registry types that are configured for CodeQL in start-proxy telemetry
2025-10-01 16:00:05 +01:00
Michael B. Gale
15916800df
Send a basic status report in start-proxy Action if it succeeds
2025-10-01 15:55:20 +01:00
Michael B. Gale
cb5a2849ac
Send status report when start-proxy fails
2025-10-01 15:52:28 +01:00
Michael B. Gale
6de1d741f6
Move error handling from startProxy to runWrapper in start-proxy action
2025-10-01 15:43:43 +01:00
Michael B. Gale
a506145f31
Add StartProxy to ActionName enum
2025-10-01 15:42:08 +01:00
Michael B. Gale
aac66ec793
Remove update-proxy-release workflow
2025-10-01 15:30:18 +01:00
Michael B. Gale
91a63dc72c
Remove undefined values from results of unsafeEntriesInvariant
2025-10-01 15:28:56 +01:00
Michael B. Gale
d25fa60a90
ESLint: Disable no-unused-vars for parameters starting with _
2025-10-01 15:28:31 +01:00
Mario Campos
3adb1ff7b8
Reorder supported tags in descending order
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2025-10-01 09:04:18 -05:00
Mario Campos
d4b5380db4
Document Node.js 24 change in CHANGELOG.md.
2025-09-30 14:11:13 -05:00
Mario Campos
d4bbcb74ca
Implement simultaneous PR checks for Node.js v20, v24.
...
Copied from #2006 .
2025-09-30 14:11:13 -05:00
Mario Campos
180438161e
Specify Node.js v24 in actions/setup-node steps.
2025-09-30 14:11:13 -05:00
Mario Campos
d7ada03e02
Downgrade upload-sarif@v4 -> v3
...
I got ahead of myself; v4 hasn't been tagged yet.
2025-09-30 14:11:13 -05:00
Mario Campos
30445af89f
Rebuild JS after upgrading to Node.js 24.
2025-09-30 14:11:04 -05:00
Mario Campos
7434149006
Upgrade Node.js version to 24.
...
This requires creating a new major-version (v4) of codeql-action.
2025-09-30 13:56:31 -05:00
Michael B. Gale
9a0b46abff
Rename keys and entries helpers and update docs
2025-09-30 12:52:04 +01:00
Michael B. Gale
b8c496644d
Rename variables in getGroupedSarifFilePaths
2025-09-30 12:05:59 +01:00
Michael B. Gale
ad086e4d90
Use path.extname for some extension checks
2025-09-30 11:55:04 +01:00
github-actions[bot]
47b5ac77ee
Add changelog note
2025-09-30 08:31:56 +00:00
github-actions[bot]
b5caf1196e
Update default bundle to codeql-bundle-v2.23.2
2025-09-30 08:31:45 +00:00
Michael B. Gale
80cb6b56b9
Merge pull request #3136 from github/mbg/dep-caching/telemetry
...
Add telemetry for dependency caching
2025-09-29 16:01:30 +01:00
Michael B. Gale
d44c8b3e18
Fix comments
2025-09-29 15:45:07 +01:00
Michael B. Gale
93711d3d89
Print a warning when there are sarifFiles in getGroupedSarifFilePaths that don't belong to an analysis kind
2025-09-29 15:07:16 +01:00
Michael B. Gale
056fb86575
Call fixCategory in uploadSpecifiedFiles
...
Since `fixCategory` is now part of `AnalysisConfig`, we don't have to remember to do it at the call site for `uploadSpecifiedFiles` or `uploadFiles` anymore.
2025-09-29 15:07:16 +01:00
Michael B. Gale
63d1b25e97
Use getGroupedSarifFilePaths for upload-sarif Action
2025-09-29 15:07:16 +01:00
Michael B. Gale
717d581574
Add fixCategory to AnalysisConfig
2025-09-29 15:07:15 +01:00
Michael B. Gale
0417531633
Add keysTyped and entriesTyped helpers
2025-09-29 15:07:15 +01:00
Michael B. Gale
13ae3d4328
Add and use getAnalysisConfig
2025-09-29 15:07:14 +01:00
Michael B. Gale
fe0376ed1f
Add getGroupedSarifFilePaths with tests
2025-09-29 15:07:13 +01:00
Michael B. Gale
36adfa7b0f
Merge pull request #3166 from github/mbg/upload-sarif/add-tests
...
Add tests for `upload-sarif`
2025-09-29 15:06:31 +01:00
Michael B. Gale
97159624c3
Fix condition in test workflow
2025-09-29 14:34:50 +01:00
Óscar San José
f0a08a4bf5
Merge pull request #3159 from github/oscarsj/update-brace-expansion-dep
...
Update vulnerable dependency brace-expansion
2025-09-29 12:13:53 +02:00
Michael B. Gale
73fbfb0bbf
Update src/upload-sarif.test.ts
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-09-29 09:11:01 +01:00
Michael B. Gale
5fd2cfe1ef
Fail if no SARIF files were uploaded
2025-09-29 09:04:44 +01:00
Michael B. Gale
2adc894410
Tests: ensure uploadSpecifiedFiles wasn't called if we don't expect it to be
2025-09-29 09:01:28 +01:00
Michael B. Gale
5b3f0ded91
Test that uploaded files match expectations for each analysis kind
2025-09-29 09:01:07 +01:00
Michael B. Gale
6e0b0872fa
Add some tests for findAndUpload and uploadSarif
2025-09-29 09:01:02 +01:00
Michael B. Gale
9f452fad0f
Move core upload-sarif logic to upload-sarif module
...
Note that this also fixes the format of the `sarif-ids` outputs to match what is documented
2025-09-29 08:57:52 +01:00
Michael B. Gale
5fc9e66105
Move findAndUpload to a new module
2025-09-29 08:44:44 +01:00
Michael B. Gale
e6768a18cf
Merge branch 'main' into mbg/dep-caching/telemetry
2025-09-29 08:39:48 +01:00
Michael B. Gale
6a87ebe42b
Merge pull request #3162 from github/mergeback/v3.30.5-to-main-3599b3ba
...
Mergeback v3.30.5 refs/heads/releases/v3 into main
2025-09-26 19:07:29 +01:00
github-actions[bot]
b66e847aaf
Rebuild
2025-09-26 17:35:46 +00:00
github-actions[bot]
1733a23b20
Update changelog and version after v3.30.5
2025-09-26 17:30:55 +00:00
Michael B. Gale
3599b3baa1
Merge pull request #3161 from github/update-v3.30.5-0a67bd46a
...
Merge main into releases/v3
2025-09-26 18:30:21 +01:00
github-actions[bot]
2ca0085e58
Update changelog for v3.30.5
2025-09-26 17:09:07 +00:00
Michael B. Gale
0a67bd46a0
Merge pull request #3160 from github/mbg/fix/upload-sarif
...
Hotfix `upload-sarif` not uploading non-`.sarif` files
2025-09-26 18:06:08 +01:00
Michael B. Gale
8e34f2f3bf
Add changelog
2025-09-26 17:52:17 +01:00
Michael B. Gale
0b7fc56648
Fix upload-sarif not uploading non-.sarif files
2025-09-26 17:47:59 +01:00
Óscar San José
2f0649510e
Build lib
2025-09-26 16:45:21 +02:00
Óscar San José
f19a3e769f
Update vulnerable dependencies brace-expansion
2025-09-26 16:41:06 +02:00
Michael B. Gale
31bfb99f0d
Do not use stringified objects for dependency caching telemetry
2025-09-26 00:26:09 +01:00
Michael B. Gale
94a9b7a110
Merge pull request #3155 from github/mbg/node/no-install-in-actions
...
Don't run `npm install` when in an Actions workflow
2025-09-25 22:47:04 +01:00
Michael B. Gale
ed57767898
Don't measure size of downloaded cache
2025-09-25 21:02:43 +01:00
Michael B. Gale
2ff902e1f1
Rename CacheHitResult and hit
2025-09-25 20:53:23 +01:00
Michael B. Gale
a0ae9ba202
Log what the script is doing
2025-09-25 20:25:59 +01:00
Michael B. Gale
b27a8ef21f
Exit if running in an Actions workflow
2025-09-25 20:25:59 +01:00
Henry Mercer
65925679a3
Merge pull request #3139 from github/henrymercer/fix-log-message
...
Fix `tools: linked` log message
2025-09-25 16:48:44 +01:00
Michael B. Gale
fa64a7dee6
Merge pull request #3154 from github/mbg/node/check-up-to-date-deps
...
Add script to check whether `npm i` needs to be run
2025-09-25 15:04:03 +01:00
Michael B. Gale
455038c8a7
Add script to check whether npm i needs to be run
...
and add it to the `build` command
2025-09-25 14:45:55 +01:00
Michael B. Gale
853decd26b
Merge pull request #3152 from github/mbg/node/individual-test-cmd
...
Add `npm run ava` command, update instructions, and exclude files from VSCode search
2025-09-25 14:42:35 +01:00
Michael B. Gale
48be21c31e
Use npm run ava in justfile
2025-09-25 14:22:38 +01:00
Michael B. Gale
77a9259761
Exclude transpiled code and dependencies from VSCode search
2025-09-25 14:22:38 +01:00
Michael B. Gale
e2e1db3e4e
Update CONTRIBUTING.md with npm run ava
2025-09-25 14:22:38 +01:00
Michael B. Gale
a645d167d6
Add npm run ava command (for ava without a specific path)
2025-09-25 14:22:38 +01:00
Michael B. Gale
8fca38155e
Merge pull request #3153 from github/mbg/ci/improve-unit-tests
...
Improve `pr-checks` workflow
2025-09-25 14:21:26 +01:00
Michael B. Gale
4e65cda8c2
Add generated workflow diff to job summary if changed
2025-09-25 13:30:00 +01:00
Michael B. Gale
b4db1860cd
Reset working directory before failing in check-js.sh
2025-09-25 13:27:45 +01:00
Michael B. Gale
9cf3a96f63
Add transpiled JS to job summary if changed
2025-09-25 13:27:39 +01:00
Michael B. Gale
6a72568b19
Run more checks in unit-tests job, even when previous checks failed
2025-09-25 13:27:32 +01:00
Henry Mercer
b1d32cf356
Merge branch 'main' into henrymercer/fix-log-message
2025-09-25 13:06:54 +01:00
Henry Mercer
5235174f0e
Merge pull request #3137 from github/henrymercer/slim-pr-checks
...
Only run PR checks on Ubuntu by default
2025-09-25 12:57:21 +01:00
Michael B. Gale
f3bf6463e1
Merge pull request #3151 from github/mbg/ci/rollback-test-triggers
...
Don't dry-run `rollback-release` workflow on release branches
2025-09-25 12:48:18 +01:00
Michael B. Gale
c5ce5e5d1c
Don't dry-run rollback-release workflow on release branches
2025-09-25 12:12:42 +01:00
Henry Mercer
79dc6cc78c
Merge pull request #3150 from github/mergeback/v3.30.4-to-main-303c0aef
...
Mergeback v3.30.4 refs/heads/releases/v3 into main
2025-09-25 12:08:26 +01:00
github-actions[bot]
4d32274da6
Rebuild
2025-09-25 10:50:17 +00:00
github-actions[bot]
0a3e31778d
Update changelog and version after v3.30.4
2025-09-25 10:19:26 +00:00
Ian Lynagh
303c0aef88
Merge pull request #3149 from github/update-v3.30.4-e4b85ab65
...
Merge main into releases/v3
2025-09-25 11:18:49 +01:00
github-actions[bot]
333a673809
Update changelog for v3.30.4
2025-09-25 09:54:23 +00:00
Henry Mercer
5445d1a09c
Merge branch 'main' into henrymercer/slim-pr-checks
2025-09-25 10:42:10 +01:00
Chuan-kai Lin
e4b85ab654
Merge pull request #3148 from github/cklin/just-test_file-serial
...
build: use --serial in 'just test_file'
2025-09-24 14:47:17 -07:00
Chuan-kai Lin
1e72556714
build: use --serial in 'just test_file'
...
Some tests require the --serial flag to pass.
2025-09-24 11:10:24 -07:00
Michael B. Gale
39842d8f83
Merge pull request #3146 from github/mbg/start-proxy/authenticate
...
Provide `Authorization` header when downloading `update-job-proxy`
2025-09-24 19:09:40 +01:00
Michael B. Gale
6ccec2ac14
Remove url from log messages
2025-09-24 18:54:49 +01:00
Henry Mercer
435f474d1e
Merge pull request #3147 from github/dependabot/npm_and_yarn/npm-76d2ab1078
...
Bump @actions/cache from 4.0.5 to 4.1.0 in the npm group
2025-09-24 18:47:44 +01:00
Henry Mercer
a34e1cd60b
Merge branch 'main' into henrymercer/slim-pr-checks
2025-09-24 19:29:32 +02:00
github-actions[bot]
f134e09015
Rebuild
2025-09-24 15:14:06 +00:00
dependabot[bot]
50a31df6ba
Bump @actions/cache from 4.0.5 to 4.1.0 in the npm group
...
Bumps the npm group with 1 update: [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ).
Updates `@actions/cache` from 4.0.5 to 4.1.0
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
---
updated-dependencies:
- dependency-name: "@actions/cache"
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-24 15:12:49 +00:00
Henry Mercer
8e25b3435d
Merge pull request #3144 from github/henrymercer/dependabot
...
Update Dependabot configuration for GitHub Actions
2025-09-24 16:09:27 +01:00
Michael B. Gale
4e820a4ca4
Apply review feedback
2025-09-24 15:50:19 +01:00
Michael B. Gale
5a9c44b3b2
Merge pull request #3145 from github/mbg/ci/skip-checks-for-dependabot
...
Skip PR checks for events triggered by Dependabot
2025-09-24 13:58:23 +01:00
Michael B. Gale
3183e6b8f9
Skip non-generated workflows for Dependabot
2025-09-24 12:49:31 +01:00
Michael B. Gale
d43f46c39c
Set Authorization header for downloading update-job-proxy
2025-09-24 12:41:54 +01:00
Michael B. Gale
efcf614b5d
Refactor assembling Authorization header value into its own function
2025-09-24 12:40:15 +01:00
Henry Mercer
4082f8c39f
Install yq
2025-09-24 13:33:10 +02:00
Michael B. Gale
cec0b17b93
Skip PR checks for events triggered by Dependabot
2025-09-24 12:08:05 +01:00
Henry Mercer
83fdfaf3fc
Merge branch 'main' into henrymercer/slim-pr-checks
2025-09-24 13:03:53 +02:00
Henry Mercer
86de17c44d
Update Dependabot configuration for GitHub Actions
2025-09-24 11:54:39 +01:00
Henry Mercer
ba58de7d61
Run resolve environment test against Ubuntu only
...
There isn't really anything platform-specific at the moment.
2025-09-24 12:51:03 +02:00
Henry Mercer
8633a151d5
Remove unnecessary "test" prefix from check names
2025-09-24 12:45:10 +02:00
Henry Mercer
79bbb1744e
Remove PR checks that are now duplicated
...
Direct tracing is now enabled by default.
2025-09-24 12:44:21 +02:00
Henry Mercer
67a0080933
Test all-platform bundle on all platforms
2025-09-24 12:36:35 +02:00
Henry Mercer
a8eeef9291
Merge pull request #3143 from github/dependabot/npm_and_yarn/npm-1a46694d8a
...
Bump the npm group with 3 updates
2025-09-24 11:31:35 +01:00
github-actions[bot]
f54c1c0b33
Rebuild
2025-09-24 10:14:58 +00:00
dependabot[bot]
c6674f9abd
Bump the npm group with 3 updates
...
Bumps the npm group with 3 updates: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@eslint/compat` from 1.3.2 to 1.4.0
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v1.4.0/packages/compat )
Updates `@typescript-eslint/eslint-plugin` from 8.44.0 to 8.44.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.44.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.44.0 to 8.44.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.44.1/packages/parser )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 1.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.44.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.44.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-24 10:13:41 +00:00
Henry Mercer
0890b56a8a
Merge pull request #3140 from github/henrymercer/dependabot-rebuild-actions
...
Trigger sync back script automatically
2025-09-24 11:11:54 +01:00
Ian Lynagh
c6e30a2b5a
Merge pull request #3118 from github/update-bundle/codeql-bundle-v2.23.1
...
Update default bundle to 2.23.1
2025-09-23 14:25:40 +01:00
Henry Mercer
1b12ed7ea8
Run resolve environment PR checks cross-platform
2025-09-23 15:15:15 +02:00
Henry Mercer
d92eef9c9e
Merge pull request #3138 from github/dependabot/github_actions/actions-a14fb9fd22
...
Bump the actions group across 1 directory with 2 updates
2025-09-23 14:11:12 +01:00
Henry Mercer
d34e247444
Enable Dependabot updates for other Actions in .github/actions
2025-09-23 15:00:15 +02:00
Henry Mercer
78e8dc0161
Trigger sync back script automatically
2025-09-23 14:59:56 +02:00
github-actions[bot]
a29637ac01
Rebuild
2025-09-23 12:54:09 +00:00
Henry Mercer
50fc7e9236
Fix tools: linked log message
2025-09-23 14:53:29 +02:00
dependabot[bot]
1ba789f617
Bump the actions group across 1 directory with 2 updates
...
Bumps the actions group with 2 updates in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.257.0 to 1.263.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/44511735964dcb71245e7e55f72539531f7bc0eb...0481980f17b760ef6bca5e8c55809102a0af1e5a )
Updates `actions/create-github-app-token` from 2.1.1 to 2.1.4
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.1.1...v2.1.4 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.263.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: actions/create-github-app-token
dependency-version: 2.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-23 12:52:28 +00:00
Henry Mercer
944aa7df3d
Merge pull request #3088 from github/dependabot/github_actions/actions-f739f361ea
...
Bump the actions group with 4 updates
2025-09-23 13:48:16 +01:00
Henry Mercer
29a4b8731d
Run code scanning config tests on Linux only
2025-09-23 14:40:02 +02:00
Henry Mercer
3df807292a
Only run PR checks on Ubuntu by default
2025-09-23 14:38:33 +02:00
Henry Mercer
c656a2569b
Merge pull request #3094 from github/copilot/stack-pr-3088
...
Sync Action version updates back to the source templates in the `pr-checks` directory
2025-09-23 13:31:55 +01:00
Michael B. Gale
eb05da905d
Specify Accept header for toolcache.downloadTool
2025-09-23 13:27:06 +01:00
github-actions[bot]
e8921f7eff
Add changelog note
2025-09-23 13:27:06 +01:00
github-actions[bot]
2bbfe979c3
Update default bundle to codeql-bundle-v2.23.1
2025-09-23 13:27:06 +01:00
Kasper Svendsen
5c8c613b75
Merge pull request #3062 from github/kaspersv/bump-minimum-overlay-codeql-version
...
Bump minimum CLI version for overlay analysis
2025-09-23 13:56:54 +02:00
Michael B. Gale
7dfbfdcb01
Report overall cache usage for CodeQL dependency caches
2025-09-23 12:28:42 +01:00
Michael B. Gale
3d7d7c978e
Fix comment
2025-09-23 11:56:50 +01:00
Michael B. Gale
249a3cbb5c
Add telemetry for storing dependency caches
2025-09-23 11:52:46 +01:00
Michael B. Gale
11480e326c
Add telemetry for restoring dependency caches
2025-09-23 11:50:15 +01:00
Kasper Svendsen
e2f4bf692b
Bump minimum CLI version for overlay analysis
2025-09-23 12:08:15 +02:00
Henry Mercer
2885255647
Only sync back versions on Dependabot update PRs
2025-09-23 11:29:23 +02:00
Michael B. Gale
665891b4f2
Merge pull request #3126 from github/mbg/add/properties-api
...
Add support for the repository properties API
2025-09-23 10:17:52 +01:00
Michael B. Gale
5a4aa83242
Always log when combining queries is disabled in the repo properties
2025-09-23 09:49:29 +01:00
Michael B. Gale
54bbe822cc
Always log when queries are configured in the repository properties
2025-09-23 09:44:52 +01:00
Michael B. Gale
4178e15b0a
Only disable loadPropertiesFromApi on GHES
2025-09-23 09:41:53 +01:00
Michael B. Gale
7f44048739
Merge pull request #3133 from github/dependabot/npm_and_yarn/npm-4684794bae
...
Bump the npm group with 5 updates
2025-09-23 09:34:15 +01:00
Michael B. Gale
205b6ba838
Rebuild
2025-09-23 09:29:04 +01:00
Michael B. Gale
0a75581cde
Check that we are on dotcom
2025-09-23 09:22:07 +01:00
Michael B. Gale
7f73f8c235
Add unit tests for properties module
2025-09-23 09:16:28 +01:00
Michael B. Gale
07920e84f8
Fix using keys instead of values
...
Also add `logger.debug` call with keys from API response
2025-09-23 09:12:16 +01:00
Michael B. Gale
40262b1861
Add getRepositoryProperties to api-client, for easier mocking
2025-09-23 09:11:10 +01:00
Michael B. Gale
b4f966a31a
Add FF to control whether to fetch repository properties
2025-09-22 20:26:56 +01:00
github-actions[bot]
8a84c17a9d
Rebuild
2025-09-22 17:08:30 +00:00
dependabot[bot]
3837f2e205
Bump the npm group with 5 updates
...
Bumps the npm group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ) | `9.35.0` | `9.36.0` |
| [@octokit/types](https://github.com/octokit/types.ts ) | `14.1.0` | `15.0.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.43.0` | `8.44.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.43.0` | `8.44.0` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.25.9` | `0.25.10` |
Updates `@eslint/js` from 9.35.0 to 9.36.0
- [Release notes](https://github.com/eslint/eslint/releases )
- [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslint/commits/v9.36.0/packages/js )
Updates `@octokit/types` from 14.1.0 to 15.0.0
- [Release notes](https://github.com/octokit/types.ts/releases )
- [Commits](https://github.com/octokit/types.ts/compare/v14.1.0...v15.0.0 )
Updates `@typescript-eslint/eslint-plugin` from 8.43.0 to 8.44.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.44.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.43.0 to 8.44.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.44.0/packages/parser )
Updates `esbuild` from 0.25.9 to 0.25.10
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.9...v0.25.10 )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.36.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@octokit/types"
dependency-version: 15.0.0
dependency-type: direct:development
update-type: version-update:semver-major
dependency-group: npm
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.44.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.44.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
- dependency-name: esbuild
dependency-version: 0.25.10
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-22 17:07:06 +00:00
Michael B. Gale
05310c6f55
Ignore repository property query config if CQ-only analysis
2025-09-22 16:32:28 +01:00
Michael B. Gale
889d482c54
Add logging to combineQueries
2025-09-22 16:32:26 +01:00
Henry Mercer
e9d7b2dd99
Remove unnecessary test cases
2025-09-22 16:49:11 +02:00
Henry Mercer
d9ad6a31c3
Error if sync.py not found
2025-09-22 16:49:11 +02:00
Henry Mercer
fbe415d86f
Remove misleading test case
2025-09-22 16:49:11 +02:00
Henry Mercer
8df00436ea
Remove half baked dry run functionality
2025-09-22 16:49:11 +02:00
Henry Mercer
bb07e07aff
Remove trailing whitespace
2025-09-22 16:49:11 +02:00
Henry Mercer
86ed2117d5
Note limitation of looking for uses: in pattern
2025-09-22 16:49:11 +02:00
Henry Mercer
5065ea8eef
Improve comment
2025-09-22 16:49:11 +02:00
Henry Mercer
ee37081d03
Remove docs about sync back workflow
...
In favour of docs in the script itself
2025-09-22 16:48:46 +02:00
Henry Mercer
5df1d6e0db
Remove redundant check
2025-09-22 15:39:05 +01:00
Henry Mercer
b8806eca8c
Merge pull request #3131 from github/henrymercer/required-checks-safety
...
CI: Improve safety of update required checks script
2025-09-22 15:37:35 +01:00
Henry Mercer
33da5f0b36
Use jq to check array length
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-09-22 15:21:20 +01:00
Henry Mercer
8a9ef89a8a
Update required checks: Fail if no check runs found
2025-09-22 16:08:45 +02:00
Henry Mercer
6b6d1ddcf9
Update required checks: Fail on error
2025-09-22 16:08:31 +02:00
Henry Mercer
2b07444ab3
Merge pull request #3130 from github/henrymercer/request-nightly
...
Support requesting latest nightly with `tools: nightly`
2025-09-22 14:59:43 +01:00
Michael B. Gale
54746c8dad
Fix expected-config-file-contents
2025-09-22 14:56:51 +01:00
Henry Mercer
5ab5aef079
Document nightly tools input in action.yml
2025-09-22 15:48:23 +02:00
Michael B. Gale
6bb4ad3009
Update .github/actions/check-codescanning-config/index.ts
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-09-22 13:11:32 +01:00
Henry Mercer
4901f549de
Lint
2025-09-22 14:01:09 +02:00
Michael B. Gale
d46a178adb
Sort queries array in check-codescanning-config
2025-09-22 13:00:15 +01:00
Henry Mercer
e2e36b17af
Add helper function for reserved tools values
2025-09-22 13:59:40 +02:00
Henry Mercer
bd516303e1
Specify bundle URL in local bundle PR check
2025-09-22 13:32:04 +02:00
Michael B. Gale
6117099fe1
Merge pull request #3127 from github/mbg/refactor/db-config-and-errors
...
Refactor database configuration from `config-utils` into its own file
2025-09-22 12:23:54 +01:00
Henry Mercer
79e0afb999
Run local CodeQL check using linked bundle
2025-09-22 13:21:11 +02:00
Henry Mercer
a25c57cebe
Wrap API call to provide better error message
2025-09-22 13:20:16 +02:00
Henry Mercer
48017e960d
Add changelog note
2025-09-22 12:57:53 +02:00
Henry Mercer
39be66afb0
Add log message
2025-09-22 12:54:42 +02:00
Henry Mercer
67427c612a
Update prepare-test docs
2025-09-22 12:49:36 +02:00
Henry Mercer
9e8cbee7cb
Process nightly CI runs using tools: nightly
2025-09-22 12:49:36 +02:00
Henry Mercer
0f4529ee05
Enable requesting latest nightly with "tools: nightly"
2025-09-22 12:49:35 +02:00
Michael B. Gale
0c4919df84
Merge pull request #3128 from github/mbg/ci/concurrency
2025-09-22 11:45:22 +01:00
Michael B. Gale
2d8d6395ef
Add missing "not" in comment
2025-09-20 14:23:28 +01:00
Michael B. Gale
6fcf631e73
Add concurrency settings to PR checks
2025-09-20 14:19:07 +01:00
Michael B. Gale
a067418f51
Ava: Run all tests in src/ directory
2025-09-20 14:10:04 +01:00
Michael B. Gale
c7eb488f8f
Add tests
2025-09-20 14:09:08 +01:00
Michael B. Gale
d14a2122fd
Include repo property queries in combineQueries
2025-09-20 14:09:08 +01:00
Michael B. Gale
1bfb67dae0
Refactor combining queries into its own function
2025-09-20 14:09:08 +01:00
Michael B. Gale
781a65ae32
Use appropriate error message in parseQueriesFromInput for repo property input
2025-09-20 14:09:08 +01:00
Michael B. Gale
ed216a06d2
Include queries from repo properties in AugmentationProperties
2025-09-20 14:09:07 +01:00
Michael B. Gale
6150aff57f
Add and use QuerySpec type
2025-09-20 14:09:07 +01:00
Michael B. Gale
3b00d03019
Load repository properties and store them in the Config
2025-09-20 14:09:07 +01:00
Michael B. Gale
4f9b2f7f06
Add initial client for repository properties
2025-09-20 14:09:06 +01:00
Michael B. Gale
96ca55b157
Ava: Run all tests in src/ directory
2025-09-20 14:06:54 +01:00
Michael B. Gale
0337c4c06e
Merge pull request #3123 from github/mbg/fix/upload-sarif-cq-only
2025-09-19 18:48:48 +01:00
Chuan-kai Lin
c22ae04dd3
Merge pull request #3125 from github/cklin/overlay-restore-timeout
...
Overlay: use restoreCache() timeout
2025-09-19 10:25:21 -07:00
Chuan-kai Lin
80273e2bc1
Overlay: use restoreCache() timeout
...
This commit changes overlay-base database download to pass the
segmentTimeoutInMs option to restoreCache(), so that restoreCache()
itself can properly abort slow downloads.
The waitForResultWithTimeLimit() wrapper around restoreCache() remains
as a second line of defense, but with a higher 10-minute time limit, to
guard against cache restore hangs outside segment downloads.
2025-09-19 09:40:09 -07:00
Michael B. Gale
dc1166cacb
Move tests for functions now in db-config
2025-09-19 17:16:41 +01:00
Michael B. Gale
ddc6d540f0
Move AugmentationProperties out of config-utils
2025-09-19 17:08:17 +01:00
Michael B. Gale
6222edff53
Move error messages from config-utils to their own file
2025-09-19 17:08:09 +01:00
Michael B. Gale
3305d21389
Move UserConfig to its own file
2025-09-19 17:08:00 +01:00
Michael B. Gale
db37d924ee
Fix condition
2025-09-19 16:17:34 +01:00
Michael B. Gale
6249793233
Disable cpp in upload-quality-sarif check
2025-09-19 16:17:33 +01:00
Michael B. Gale
e33b0ab3ac
Update upload-quality-sarif check to only use code-quality
2025-09-19 16:17:33 +01:00
Michael B. Gale
7bea0e2e12
Fix outdated comment
2025-09-19 16:17:33 +01:00
Michael B. Gale
d378195403
Add new sarif-ids output to upload-sarif action
...
Unlike `sarif-id` which is for the single Code Scanning SARIF id, `sarif-ids` contains stringified JSON object with details of all SARIF ids.
2025-09-19 16:17:31 +01:00
Chuan-kai Lin
12dda79905
Merge pull request #3124 from github/cklin/rename-withtimeout
...
Rename withTimeout() to waitForResultWithTimeLimit()
2025-09-18 13:34:56 -07:00
Michael B. Gale
a2ce099060
Use findAndUpload for Code Scanning
2025-09-18 16:29:25 +01:00
Michael B. Gale
696b467654
Handle single file case in findAndUpload
2025-09-18 16:29:23 +01:00
Michael B. Gale
c8e017d3e7
Move isDirectory check into findAndUpload
2025-09-18 16:28:39 +01:00
Chuan-kai Lin
8185897cad
Rename withTimeout() to waitForResultWithTimeLimit()
...
The name withTimeout() gives the impression that it would limit the
execution of the promise to the given time bound. But that is not the
case: it is only the _waiting_ that is limited, and the promise would
keep running beyond the time bound.
This commit renames withTimeout() to waitForResultWithTimeLimit() so
that developers are more likely to understand the actual behavior of
this function.
2025-09-18 08:27:36 -07:00
Michael B. Gale
a6161a8092
Call lstatSync on sarifPath earlier and check that the path exists then
2025-09-18 14:13:17 +01:00
Michael B. Gale
35454d39b2
Refactor CQ SARIF upload in upload-sarif into a function
2025-09-18 14:13:14 +01:00
Henry Mercer
b73659a4ff
Merge pull request #3122 from felickz/main
...
Update ref description in action.ymls to include expected format for uploads
2025-09-18 09:52:36 +01:00
Chad Bentz
2f35a47982
Update upload-sarif/action.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-09-17 19:07:57 -04:00
Chad Bentz
242ca1c0a1
Update ref description in action.ymls to include expected format for uploads
2025-09-17 19:02:50 -04:00
Henry Mercer
573acd9552
Merge pull request #3115 from github/dependabot/npm_and_yarn/npm-75b7851ed5
...
Bump uuid from 12.0.0 to 13.0.0 in the npm group
2025-09-15 18:38:40 +01:00
github-actions[bot]
668f0f00da
Rebuild
2025-09-15 17:18:08 +00:00
dependabot[bot]
0b263ec528
Bump uuid from 12.0.0 to 13.0.0 in the npm group
...
Bumps the npm group with 1 update: [uuid](https://github.com/uuidjs/uuid ).
Updates `uuid` from 12.0.0 to 13.0.0
- [Release notes](https://github.com/uuidjs/uuid/releases )
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md )
- [Commits](https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0 )
---
updated-dependencies:
- dependency-name: uuid
dependency-version: 13.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-15 17:16:56 +00:00
Michael B. Gale
9e5383b3b1
Merge pull request #3113 from github/nickrolfe/minimize-jars-followup
...
Only enable Java dependency minimisation when caching is enabled
2025-09-15 16:57:27 +01:00
Henry Mercer
8279538f3d
Merge pull request #3114 from github/henrymercer/pr-checks-codeql-2.22
...
Run PR checks over CodeQL v2.22 release series
2025-09-15 16:52:03 +01:00
Henry Mercer
86f23c3336
Run PR checks over CodeQL v2.22 release series
2025-09-15 16:34:20 +01:00
Henry Mercer
77c3d2533d
Merge pull request #3112 from github/henrymercer/scan-python
...
CI: Configure Python analysis
2025-09-15 16:25:56 +01:00
Henry Mercer
1069ace04e
Update .github/workflows/codeql.yml
2025-09-15 16:09:21 +01:00
Nick Rolfe
4014b75309
Only enable JAVA dependency minimisation when caching is enabled
2025-09-15 15:11:28 +01:00
Henry Mercer
bce0fa7b27
Remove build mode from matrix
2025-09-15 14:45:40 +01:00
Henry Mercer
8105843d42
Specify paths-ignore for other languages
2025-09-15 14:20:15 +01:00
Henry Mercer
61b8b636e3
Only upload a single matrix case for JS
2025-09-15 14:15:05 +01:00
Henry Mercer
73ead84d0a
Reorder strategy properties
2025-09-15 14:12:47 +01:00
Henry Mercer
793fe1783c
CI: Configure Python analysis
2025-09-15 14:10:32 +01:00
Henry Mercer
c9d2739db2
Use more generic regexp for sync.py changes
2025-09-10 18:24:51 +01:00
Henry Mercer
d0f02ad683
Simplify import
2025-09-10 18:24:38 +01:00
Henry Mercer
1343eba2d0
Remove unused imports
2025-09-10 18:14:20 +01:00
Henry Mercer
cde0d796a6
Run sync back script separately
2025-09-10 18:14:08 +01:00
Henry Mercer
d08f929510
Run test script in CI
2025-09-10 18:12:29 +01:00
Henry Mercer
d9bc711b1c
Rename script for consistency
2025-09-10 18:12:20 +01:00
copilot-swe-agent[bot]
f537110285
Add sync-back script execution to rebuild workflow
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-09-10 16:59:28 +00:00
copilot-swe-agent[bot]
5d79536231
Remove regular workflow file updates from sync-back script
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-09-10 16:53:17 +00:00
copilot-swe-agent[bot]
f77ed607fd
Improve sync-back automation with automatic action detection, comment preservation, and tests
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-09-10 16:00:52 +00:00
copilot-swe-agent[bot]
8d31b533a2
Add sync-back automation for Dependabot action version updates
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-09-10 09:39:16 +00:00
copilot-swe-agent[bot]
436471d2fb
Initial plan
2025-09-09 16:16:43 +00:00
dependabot[bot]
1a80c9b44e
Bump the actions group with 4 updates
...
Bumps the actions group with 4 updates: [actions/setup-go](https://github.com/actions/setup-go ), [actions/github-script](https://github.com/actions/github-script ), [actions/setup-node](https://github.com/actions/setup-node ) and [actions/setup-python](https://github.com/actions/setup-python ).
Updates `actions/setup-go` from 5 to 6
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/v5...v6 )
Updates `actions/github-script` from 7 to 8
- [Release notes](https://github.com/actions/github-script/releases )
- [Commits](https://github.com/actions/github-script/compare/v7...v8 )
Updates `actions/setup-node` from 4 to 5
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v4...v5 )
Updates `actions/setup-python` from 5 to 6
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/github-script
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/setup-node
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/setup-python
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-09-08 17:54:44 +00:00