Michael B. Gale
a723e99345
Merge pull request #3868 from github/mergeback/v4.35.3-to-main-e46ed2cb
...
Mergeback v4.35.3 refs/heads/releases/v4 into main
2026-05-01 14:34:01 +00:00
github-actions[bot]
fbba1e03be
Rebuild
2026-05-01 14:09:49 +00:00
github-actions[bot]
933238e8d5
Update changelog and version after v4.35.3
2026-05-01 14:06:46 +00:00
Michael B. Gale
e46ed2cbd0
Merge pull request #3867 from github/update-v4.35.3-8c6e48dbe
...
Merge main into releases/v4
2026-05-01 15:05:28 +01:00
Michael B. Gale
b73d1d1634
Add changelog entry for #3853
2026-05-01 14:09:58 +01:00
Michael B. Gale
24e0bb00a9
Reorder changelog entries
2026-05-01 14:07:12 +01:00
github-actions[bot]
ec298daba7
Update changelog for v4.35.3
2026-05-01 12:57:50 +00:00
Henry Mercer
8c6e48dbe0
Merge pull request #3865 from github/update-bundle/codeql-bundle-v2.25.3
...
Update default bundle to 2.25.3
2026-04-30 16:07:18 +00:00
github-actions[bot]
719098349e
Add changelog note
2026-04-30 15:31:49 +00:00
github-actions[bot]
2bb209555a
Update default bundle to codeql-bundle-v2.25.3
2026-04-30 15:31:40 +00:00
Michael B. Gale
7851e55dc3
Merge pull request #3850 from github/mbg/private-registry/cloudsmith-gcp
...
Private registries: Add support for Cloudsmith and GCP OIDC configurations
2026-04-30 13:33:44 +00:00
Michael B. Gale
262a15f6cf
Add generic non-printable chars test for OIDC configs
2026-04-30 14:10:36 +01:00
Michael B. Gale
a6109b1c07
Merge pull request #3853 from github/mbg/start-proxy/improved-checks
...
Improve connection tests
2026-04-30 12:48:34 +00:00
Michael B. Gale
022ff3c73f
Merge remote-tracking branch 'origin/main' into mbg/private-registry/cloudsmith-gcp
2026-04-30 13:43:29 +01:00
Michael B. Gale
0a4d574ac4
Add changelog entry
2026-04-30 13:42:29 +01:00
Michael B. Gale
d1edf2e4de
Improve replaces-base validation and add tests
2026-04-30 13:41:13 +01:00
Henry Mercer
facd53f789
Merge pull request #3859 from github/dependabot/npm_and_yarn/ava/typescript-7.0.0
...
Bump @ava/typescript from 6.0.0 to 7.0.0
2026-04-30 12:30:35 +00:00
Michael B. Gale
b77983290b
Fix permutations comment
2026-04-30 13:28:42 +01:00
Henry Mercer
fcf29e3d86
Merge pull request #3862 from github/dependabot/github_actions/dot-github/workflows/actions-minor-933f87fbf1
...
Bump ruby/setup-ruby from 1.301.0 to 1.305.0 in /.github/workflows in the actions-minor group across 1 directory
2026-04-30 12:17:13 +00:00
Henry Mercer
1fed3e9ba8
Merge branch 'main' into dependabot/npm_and_yarn/ava/typescript-7.0.0
2026-04-30 13:10:19 +01:00
Michael B. Gale
549683cee5
Make it clearer what the expectations for isUsernamePassword are
2026-04-30 12:49:49 +01:00
Michael B. Gale
7a6ed56219
Modify FromSchema so that optional properties are actually optional
2026-04-30 11:54:21 +01:00
Michael B. Gale
91fbc51606
Improve validateSchema comment
2026-04-30 11:46:01 +01:00
Michael B. Gale
35715ef8fe
Improve typing of cloneCredential
2026-04-30 11:43:54 +01:00
Michael B. Gale
bac7fdaf42
Fix linter error
2026-04-30 11:26:12 +01:00
Henry Mercer
1517969c90
Merge pull request #3837 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2026-04-30 10:16:37 +00:00
github-actions[bot]
f073360456
Rebuild
2026-04-29 18:02:23 +00:00
dependabot[bot]
5145c112e7
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.301.0 to 1.305.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/4c56a21280b36d862b5fc31348f463d60bdc55d5...0cb964fd540e0a24c900370abf38a33466142735 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.305.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-29 18:00:14 +00:00
dependabot[bot]
7108503ac6
Bump @ava/typescript from 6.0.0 to 7.0.0
...
Bumps [@ava/typescript](https://github.com/avajs/typescript ) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/avajs/typescript/releases )
- [Commits](https://github.com/avajs/typescript/compare/v6.0.0...v7.0.0 )
---
updated-dependencies:
- dependency-name: "@ava/typescript"
dependency-version: 7.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-29 17:59:33 +00:00
Henry Mercer
4fe9b1e243
Merge pull request #3856 from github/henrymercer/overlay-add-log-group
...
Add log group for downloading overlay-base DB
2026-04-29 10:51:09 +00:00
Henry Mercer
56733fb5ae
Add log group for downloading overlay-base DB
2026-04-28 19:00:28 +01:00
Henry Mercer
0a636086c9
Add GHES 3.21 to supported versions table
2026-04-28 15:32:55 +01:00
Henry Mercer
97be3af35a
Deprecate CodeQL versions 2.19.3 and earlier
2026-04-28 15:32:55 +01:00
github-actions[bot]
de303a9db5
Update supported GitHub Enterprise Server versions
2026-04-28 15:24:46 +01:00
Michael B. Gale
7a818e6977
Log disclaimer about connection tests, with link to docs
2026-04-28 13:45:53 +01:00
Michael B. Gale
30e0f4391d
Use /v3/index.json for NuGet feed check
2026-04-28 13:45:52 +01:00
Henry Mercer
7c5585e5cf
Merge pull request #3852 from github/henrymercer/avoid-diagnostic-collisions
...
Add random suffix when writing diagnostics to avoid filename collisions
2026-04-28 12:04:59 +00:00
Henry Mercer
245f6828c4
Use a counter instead of Math.random for diagnostic filename suffix
2026-04-28 12:42:42 +01:00
Henry Mercer
c109008fac
Add changelog note
2026-04-28 11:40:03 +01:00
Henry Mercer
e73c940c9b
Defensively sanitize timestamp
2026-04-28 11:40:02 +01:00
Henry Mercer
cdb655d6d4
Add random suffix when writing diagnostics to avoid filename collisions
2026-04-28 11:39:40 +01:00
Michael B. Gale
6153577cab
Switch from HEAD to GET requests
...
Not all registry implementations support `HEAD` correctly.
2026-04-28 10:42:27 +01:00
Michael B. Gale
0ed734b61b
Ignore test files
2026-04-25 18:36:22 +01:00
Michael B. Gale
efdcb31f11
Accept replaces-base option
2026-04-25 18:36:22 +01:00
Michael B. Gale
4d2c7c6e10
Validate GCP OIDC configurations
2026-04-25 18:36:22 +01:00
Michael B. Gale
70b2658d23
Validate Cloudsmith OIDC configurations
2026-04-25 18:36:21 +01:00
Michael B. Gale
530fcb3bbf
Group OIDC schemas into an array
2026-04-25 18:36:19 +01:00
Michael B. Gale
2acf81942b
Add tests for getAuthConfig
2026-04-25 18:34:00 +01:00
Michael B. Gale
d2a54a4507
Add schemas for basic credential types
2026-04-25 18:33:01 +01:00
Michael B. Gale
bc4097bbe1
Simplify credential cloning in getAuthConfig
2026-04-25 18:23:11 +01:00
Michael B. Gale
c8e26e209a
Move getAuthConfig out of start-proxy.ts
2026-04-25 16:49:05 +01:00
Michael B. Gale
0752451507
Use schema/validation for existing OIDC config types
2026-04-25 16:49:05 +01:00
Michael B. Gale
243c274daf
Add simple JSON schema / validation helpers
2026-04-25 15:35:50 +01:00
Henry Mercer
19b3a84f58
Merge pull request #3849 from github/henrymercer/simplify-diff-range-interface
...
Simplify `writeDiffRangeDataExtensionPack` interface
2026-04-23 20:29:05 +00:00
Henry Mercer
858a6149c1
Simplify writeDiffRangeDataExtensionPack interface
2026-04-23 16:47:15 +01:00
Henry Mercer
c60c75576d
Merge pull request #3848 from github/dependabot/npm_and_yarn/fast-xml-parser-5.7.1
...
Bump fast-xml-parser from 5.5.7 to 5.7.1
2026-04-22 23:03:27 +00:00
Henry Mercer
59aede2113
Merge pull request #3847 from github/dependabot/npm_and_yarn/uuid-14.0.0
...
Bump uuid from 13.0.0 to 14.0.0
2026-04-22 23:02:16 +00:00
github-actions[bot]
6c35f8607b
Rebuild
2026-04-22 21:54:06 +00:00
github-actions[bot]
c486cacf49
Rebuild
2026-04-22 21:53:49 +00:00
dependabot[bot]
365478cc5b
Bump fast-xml-parser from 5.5.7 to 5.7.1
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.5.7 to 5.7.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.7...v5.7.1 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.7.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 21:52:05 +00:00
dependabot[bot]
f0e6490756
Bump uuid from 13.0.0 to 14.0.0
...
Bumps [uuid](https://github.com/uuidjs/uuid ) from 13.0.0 to 14.0.0.
- [Release notes](https://github.com/uuidjs/uuid/releases )
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md )
- [Commits](https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0 )
---
updated-dependencies:
- dependency-name: uuid
dependency-version: 14.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 21:51:48 +00:00
Henry Mercer
860353f245
Merge pull request #3840 from github/dependabot/npm_and_yarn/npm-minor-580efa6e3b
...
Bump the npm-minor group across 1 directory with 3 updates
2026-04-22 20:59:20 +00:00
Henry Mercer
4fb8483ef0
Merge pull request #3835 from github/dependabot/npm_and_yarn/eslint-import-resolver-typescript-4.4.4
...
Bump eslint-import-resolver-typescript from 3.8.7 to 4.4.4
2026-04-22 20:33:35 +00:00
dependabot[bot]
c2574efbee
Bump the npm-minor group across 1 directory with 3 updates
...
Bumps the npm-minor group with 3 updates in the / directory: [globals](https://github.com/sindresorhus/globals ), [sinon](https://github.com/sinonjs/sinon ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `globals` from 17.4.0 to 17.5.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.4.0...v17.5.0 )
Updates `sinon` from 21.0.3 to 21.1.2
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.3...v21.1.2 )
Updates `typescript-eslint` from 8.58.1 to 8.58.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.2/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.1.2
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.58.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 17:58:53 +00:00
Henry Mercer
4cbe7bef85
Merge pull request #3839 from github/henrymercer/workflow-run-triggers
...
Escape "+"s in `on.workflow_run.workflows`
2026-04-22 10:44:53 +00:00
Henry Mercer
f6a5638305
Escape "+"s in on.workflow_run.workflows
2026-04-22 11:14:07 +01:00
Henry Mercer
1dcdb940d5
Merge pull request #3830 from github/henrymercer/deflake
...
Add workflow to rerun potentially transient failures
2026-04-21 10:57:19 +00:00
Henry Mercer
0b7b740d4c
Merge pull request #3831 from github/dependabot/npm_and_yarn/npm-minor-f46f1f14d7
...
Bump the npm-minor group across 1 directory with 2 updates
2026-04-16 11:08:29 +00:00
Henry Mercer
0ac85966ba
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-f46f1f14d7
2026-04-16 11:49:39 +01:00
dependabot[bot]
5019ed041c
Bump eslint-import-resolver-typescript from 3.8.7 to 4.4.4
...
Bumps [eslint-import-resolver-typescript](https://github.com/import-js/eslint-import-resolver-typescript ) from 3.8.7 to 4.4.4.
- [Release notes](https://github.com/import-js/eslint-import-resolver-typescript/releases )
- [Changelog](https://github.com/import-js/eslint-import-resolver-typescript/blob/master/CHANGELOG.md )
- [Commits](https://github.com/import-js/eslint-import-resolver-typescript/compare/v3.8.7...v4.4.4 )
---
updated-dependencies:
- dependency-name: eslint-import-resolver-typescript
dependency-version: 4.4.4
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 17:58:58 +00:00
dependabot[bot]
d64d81d41f
Bump the npm-minor group across 1 directory with 2 updates
...
Bumps the npm-minor group with 2 updates in the / directory: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `@eslint/compat` from 2.0.4 to 2.0.5
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.5/packages/compat )
Updates `typescript-eslint` from 8.58.0 to 8.58.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.58.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 17:58:27 +00:00
Henry Mercer
6777c894e9
Merge pull request #3811 from github/henrymercer/record-all-builtin-languages
...
Store all built-in languages
2026-04-15 17:57:19 +00:00
Henry Mercer
79f9c0517c
Merge remote-tracking branch 'origin/main' into henrymercer/record-all-builtin-languages
...
# Conflicts:
# lib/start-proxy-action.js
# src/known-language-aliases.json
2026-04-15 18:36:47 +01:00
Henry Mercer
3b3a77544b
Rename job
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-04-15 18:34:13 +01:00
Henry Mercer
9f95de42d6
Add workflow to rerun potentially transient failures
2026-04-15 18:28:17 +01:00
Henry Mercer
e2d518d895
Merge pull request #3827 from github/dependabot/npm_and_yarn/follow-redirects-1.16.0
...
Bump follow-redirects from 1.15.11 to 1.16.0
2026-04-15 12:47:52 +00:00
github-actions[bot]
9df9e9176e
Rebuild
2026-04-15 12:20:46 +00:00
dependabot[bot]
6847a42aa8
Bump follow-redirects from 1.15.11 to 1.16.0
...
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects ) from 1.15.11 to 1.16.0.
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases )
- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.11...v1.16.0 )
---
updated-dependencies:
- dependency-name: follow-redirects
dependency-version: 1.16.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-15 12:18:36 +00:00
Henry Mercer
f820c80d4d
Merge pull request #3825 from github/mergeback/v4.35.2-to-main-95e58e9a
...
Mergeback v4.35.2 refs/heads/releases/v4 into main
2026-04-15 11:56:45 +00:00
github-actions[bot]
ca7d6d3b79
Rebuild
2026-04-15 11:27:36 +00:00
github-actions[bot]
8d9c36a0ce
Update changelog and version after v4.35.2
2026-04-15 11:24:19 +00:00
Henry Mercer
95e58e9a2c
Merge pull request #3824 from github/update-v4.35.2-d2e135a73
...
Merge main into releases/v4
2026-04-15 12:22:51 +01:00
github-actions[bot]
6f31bfe060
Update changelog for v4.35.2
2026-04-15 10:56:23 +00:00
Henry Mercer
d2e135a73a
Merge pull request #3823 from github/update-bundle/codeql-bundle-v2.25.2
...
Update default bundle to 2.25.2
2026-04-15 10:06:23 +00:00
github-actions[bot]
60abb65df0
Add changelog note
2026-04-15 09:39:31 +00:00
github-actions[bot]
5a0a562209
Update default bundle to codeql-bundle-v2.25.2
2026-04-15 09:39:24 +00:00
Henry Mercer
f8b62132ab
Include experimental languages
2026-04-14 17:38:26 +01:00
Henry Mercer
65216971a1
Merge pull request #3820 from github/dependabot/github_actions/dot-github/workflows/actions-minor-cc17fecf2b
...
Bump the actions-minor group across 1 directory with 2 updates
2026-04-13 18:04:26 +00:00
Henry Mercer
3c45af2dd2
Merge pull request #3821 from github/dependabot/npm_and_yarn/npm-minor-345b938e93
...
Bump the npm-minor group across 1 directory with 6 updates
2026-04-13 17:59:04 +00:00
github-actions[bot]
f1c339364c
Rebuild
2026-04-13 17:31:19 +00:00
github-actions[bot]
1024fc496c
Rebuild
2026-04-13 17:30:13 +00:00
dependabot[bot]
9dd4cfed96
Bump the npm-minor group across 1 directory with 6 updates
...
Bumps the npm-minor group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@octokit/plugin-retry](https://github.com/octokit/plugin-retry.js ) | `8.0.3` | `8.1.0` |
| [jsonschema](https://github.com/tdegrunt/jsonschema ) | `1.4.1` | `1.5.0` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `2.0.3` | `2.0.4` |
| [@types/sinon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sinon ) | `21.0.0` | `21.0.1` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.4` | `0.28.0` |
| [nock](https://github.com/nock/nock ) | `14.0.11` | `14.0.12` |
Updates `@octokit/plugin-retry` from 8.0.3 to 8.1.0
- [Release notes](https://github.com/octokit/plugin-retry.js/releases )
- [Commits](https://github.com/octokit/plugin-retry.js/compare/v8.0.3...v8.1.0 )
Updates `jsonschema` from 1.4.1 to 1.5.0
- [Commits](https://github.com/tdegrunt/jsonschema/commits )
Updates `@eslint/compat` from 2.0.3 to 2.0.4
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.4/packages/compat )
Updates `@types/sinon` from 21.0.0 to 21.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sinon )
Updates `esbuild` from 0.27.4 to 0.28.0
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.4...v0.28.0 )
Updates `nock` from 14.0.11 to 14.0.12
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.11...v14.0.12 )
---
updated-dependencies:
- dependency-name: "@octokit/plugin-retry"
dependency-version: 8.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: jsonschema
dependency-version: 1.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@eslint/compat"
dependency-version: 2.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@types/sinon"
dependency-version: 21.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.28.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: nock
dependency-version: 14.0.12
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-13 17:29:04 +00:00
dependabot[bot]
c1403f094c
Bump the actions-minor group across 1 directory with 2 updates
...
Bumps the actions-minor group with 2 updates in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.295.0 to 1.300.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/319994f95fa847cf3fb3cd3dbe89f6dcde9f178f...4c56a21280b36d862b5fc31348f463d60bdc55d5 )
Updates `actions/create-github-app-token` from 3.0.0 to 3.1.1
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v3.0.0...v3.1.1 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.300.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
- dependency-name: actions/create-github-app-token
dependency-version: 3.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-13 17:27:57 +00:00
Henry Mercer
90d7616015
Merge branch 'main' into henrymercer/record-all-builtin-languages
2026-04-13 18:00:09 +01:00
Henry Mercer
1aef4ed505
Exclude new TypeScript code from package tests
...
Avoid new source code changing expected output
2026-04-13 17:37:29 +01:00
Henry Mercer
cb52ba6486
Refactoring: Split up script
2026-04-13 17:03:20 +01:00
Henry Mercer
7c9e131894
Add constant for builtin languages file path
2026-04-13 16:57:47 +01:00
Henry Mercer
130ab2d721
Improve JSDoc
2026-04-13 16:54:06 +01:00
Henry Mercer
8cf2dc52f9
Fix casing mismatch
2026-04-13 16:49:31 +01:00
Henry Mercer
8339b9254e
Merge pull request #3819 from github/henrymercer/refactor-overlay-caching
...
Refactoring: Introduce `overlay/caching.ts`
2026-04-13 15:49:12 +00:00
Henry Mercer
97bcdd8c1e
Move script to pr-checks directory
2026-04-13 16:49:10 +01:00
Henry Mercer
e6c21da23c
Refactoring: Rename KnownLanguage to BuiltInLanguage
2026-04-10 19:09:47 +01:00
Henry Mercer
bad0a744dd
Store all built-in languages
...
While we want the CodeQL Action to work with third-party language support, having a list of all built-in languages can help us create better type-level checks to ensure that we don't miss things that we want to customize for each of our built-in languages.
2026-04-10 19:09:46 +01:00
Michael B. Gale
ee09113642
Merge pull request #3810 from github/mbg/ts6/fix-pr-checks
...
Fix `pr-checks/tsconfig.json` for TS6
2026-04-10 18:02:01 +00:00
Michael B. Gale
b669eab7e3
Explicitly add pr-checks to Dependabot config
2026-04-10 16:58:30 +01:00
Henry Mercer
4e8c9ce33c
Refactoring: Introduce overlay/caching.ts
2026-04-10 14:55:12 +01:00
Michael B. Gale
1cf0431149
Set module option for pr-checks/tsconfig.json
2026-04-10 13:22:36 +01:00
Michael B. Gale
a26cb68cc7
Merge pull request #3807 from github/mbg/start-proxy/fix-field-names
...
Fix OIDC credential property names
2026-04-10 09:18:24 +00:00
Henry Mercer
60991e61ac
Merge pull request #3806 from github/henrymercer/store-language-aliases
...
Store language aliases from linked CLI
2026-04-10 09:16:45 +00:00
Michael B. Gale
7197c2b792
Add changelog entry
2026-04-09 19:01:45 +01:00
Henry Mercer
597e12aa85
Merge pull request #3801 from github/henrymercer/swift-incompatible-os
...
Mark Swift incompatible OS as configuration error
2026-04-09 17:30:06 +00:00
Michael B. Gale
d277a56348
Fix OIDC credential property names
2026-04-09 17:48:52 +01:00
Henry Mercer
111a537cd9
Update start-proxy Action to use known language aliases
2026-04-09 17:10:15 +01:00
Henry Mercer
51d833290e
Store language aliases from linked CLI
2026-04-09 17:10:15 +01:00
Henry Mercer
5a17511bf0
Throw error on Windows too
2026-04-09 16:52:50 +01:00
Henry Mercer
43d8420a42
Do not run Swift in debug artifacts after failure check
2026-04-09 15:18:51 +01:00
Henry Mercer
76a687e1d8
Merge pull request #3804 from github/dependabot/npm_and_yarn/npm-minor-e84c604a08
...
Bump eslint-plugin-jsdoc from 62.8.1 to 62.9.0 in the npm-minor group
2026-04-09 13:04:00 +00:00
dependabot[bot]
751f3e2f7c
Bump eslint-plugin-jsdoc from 62.8.1 to 62.9.0 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.8.1 to 62.9.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.8.1...v62.9.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.9.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-08 17:53:21 +00:00
Henry Mercer
808513f048
Update language aliases test
2026-04-08 16:38:23 +01:00
Henry Mercer
e452857e57
Throw error early rather than warning
2026-04-08 16:33:19 +01:00
Mario Campos
b623f5fd57
Merge pull request #3799 from github/mario-campos/test-multiple-registries
...
Add tests for getCredentials with multiple goproxy_servers and maven_…
2026-04-07 14:52:14 +00:00
Mario Campos
35a38985d3
Specify "Java" for a test case
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-04-07 09:01:00 -05:00
Mario Campos
14ed573199
Specify "Go" for a test case
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-04-07 09:01:00 -05:00
Mario Campos
43d8864b35
Run npm run lint-fix to format the code
2026-04-07 09:01:00 -05:00
Mario Campos
f8aff3ad8b
Add tests for getCredentials with multiple goproxy_servers and maven_repositories
2026-04-07 09:01:00 -05:00
Henry Mercer
e6c83948f5
Merge pull request #3802 from github/dependabot/npm_and_yarn/lodash-4.18.1
...
Bump lodash from 4.17.23 to 4.18.1
2026-04-07 10:12:08 +00:00
Henry Mercer
347f0c676d
Merge pull request #3803 from github/dependabot/npm_and_yarn/npm-minor-113ae615b7
...
Bump eslint-plugin-jsdoc from 62.8.0 to 62.8.1 in the npm-minor group across 1 directory
2026-04-07 10:08:35 +00:00
dependabot[bot]
6eed62b035
Bump eslint-plugin-jsdoc in the npm-minor group across 1 directory
...
Bumps the npm-minor group with 1 update in the / directory: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.8.0 to 62.8.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.8.0...v62.8.1 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.8.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-07 09:36:59 +00:00
dependabot[bot]
de1752b85d
Bump lodash from 4.17.23 to 4.18.1
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.18.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-07 09:36:15 +00:00
Henry Mercer
1065967b50
Merge pull request #3800 from github/henrymercer/typescript-6
...
Upgrade to TypeScript 6
2026-04-07 09:14:42 +00:00
Henry Mercer
e25c0a535a
Merge pull request #3795 from github/henrymercer/deprecate-trap-caching-cleanup
...
Deprecate TRAP cache cleanup
2026-04-07 09:14:31 +00:00
Henry Mercer
5f323cad05
Mark Swift incompatible OS as configuration error
2026-04-02 18:46:26 +01:00
Henry Mercer
212e28374b
Upgrade to TypeScript 6
...
tsconfig changes:
- Specify `moduleResolution: bundler` since we use a bundler
- Specify `types: ["node"]` to speed up build
- Remove `alwaysStrict` as this is now deprecated
- Specify `skipLibCheck: true` to speed up build
- Specify Octokit types.d.ts path manually to address compiler not being able to find types with `moduleResolution: bundler`
2026-04-02 18:32:58 +01:00
Henry Mercer
36075a4980
Deprecate TRAP cache cleanup
2026-04-01 15:31:15 +01:00
Michael B. Gale
34950e1b11
Merge pull request #3792 from github/mario-campos/issue-1664
...
Extend start-proxy.yml to test multiple registry support
2026-04-01 13:59:59 +00:00
Henry Mercer
57ec7e1000
Merge pull request #3794 from github/henrymercer/cleanup
...
Python: Disable standard library extraction on GHES
2026-04-01 11:37:34 +00:00
Henry Mercer
311573e58e
Add changelog note
2026-04-01 12:19:11 +01:00
Henry Mercer
1f4c852aeb
Clean up Python extract stdlib feature flag
2026-04-01 12:08:06 +01:00
Michael B. Gale
2e3aaaefca
Merge pull request #3787 from github/mbg/bundle/metadata
...
Generate and analyse esbuild bundle metadata
2026-04-01 10:29:27 +00:00
Mario Campos
e2203c62cf
Delete fromJSON() calls in test validation step
2026-03-31 13:19:33 -05:00
Mario Campos
7b0c5b1669
Keep validation steps named consistently
2026-03-31 12:49:07 -05:00
Mario Campos
faf45e07f9
Use different maven URL for start-proxy.yml test
2026-03-31 12:44:43 -05:00
Mario Campos
8b5e60477c
Use maven_repository, not maven-repository
...
The registry/language mapping table does not map the one with hyphens.
2026-03-31 11:36:17 -05:00
Mario Campos
99b8dd4d57
Run pr-checks/sync.sh to generate __start-proxy.yml.
2026-03-31 09:32:42 -05:00
Henry Mercer
c618c9bddb
Merge pull request #3789 from github/henrymercer/lower-minimum-git-if-no-submodules
...
Overlay: Only require Git 2.36.0 for repos that contain submodules
2026-03-31 10:10:05 +00:00
Mario Campos
9fd9b64766
Replace jq with Actions expression for proxy_urls validation
...
For the sake of consistency with the other pre-existing validation code.
2026-03-30 22:47:06 -05:00
Mario Campos
0c7c298b2a
Extend start-proxy.yml to test multiple registry support
2026-03-30 18:35:04 -05:00
Henry Mercer
a507a542a4
Test fallback when repo has no submodules
2026-03-30 15:58:58 +01:00
Henry Mercer
be0a156326
Save a computation of the git root
2026-03-30 13:37:14 +01:00
Michael B. Gale
f98bf5e347
Output relative to __dirname
2026-03-27 19:21:14 +00:00
Michael B. Gale
3db32b5d27
Fix outputs type
2026-03-27 19:13:22 +00:00
Michael B. Gale
4e0952a3c0
Output largest inputs
2026-03-27 19:13:02 +00:00
Henry Mercer
0592832ed8
Add changelog note
2026-03-27 18:58:05 +00:00
Henry Mercer
88a7e5118e
Don't disable if we don't need the git version
2026-03-27 18:54:26 +00:00
Henry Mercer
6643a7d207
Only require Git 2.36.0 when repo contains submodules
2026-03-27 18:54:24 +00:00
Michael B. Gale
47f1709a3c
Add basic metadata analysis script
2026-03-27 18:19:57 +00:00
Michael B. Gale
b1981a5480
Move getApiClient out of sync-checks.ts
2026-03-27 18:13:48 +00:00
Henry Mercer
a899987af2
Merge pull request #3786 from github/henrymercer/faster-interactive-jobs
...
Move time-sensitive Actions workflows to `ubuntu-latest`
2026-03-27 18:08:16 +00:00
Michael B. Gale
4ed3c0efe6
Generate esbuild metadata file
2026-03-27 17:54:29 +00:00
Henry Mercer
191d7c6f13
Merge pull request #3783 from github/mergeback/v4.35.1-to-main-c10b8064
...
Mergeback v4.35.1 refs/heads/releases/v4 into main
2026-03-27 17:11:42 +00:00
Henry Mercer
aa69c483cd
Merge pull request #3779 from github/henrymercer/remove-unused-dependency
...
Remove unused `@schemastore/package` dependency
2026-03-27 17:11:32 +00:00
Henry Mercer
fe775da508
Merge pull request #3780 from github/dependabot/npm_and_yarn/brace-expansion-1.1.13
...
Bump brace-expansion from 1.1.12 to 1.1.13
2026-03-27 17:11:18 +00:00
Henry Mercer
353802f9f2
Move time-sensitive Actions workflows to ubuntu-latest
...
We originally moved these to `ubuntu-slim`, but there is a significant performance difference. Since we often find ourselves waiting on these jobs, let's use the faster runners.
2026-03-27 16:22:19 +00:00
github-actions[bot]
cc7db4a1f9
Rebuild
2026-03-27 16:20:01 +00:00
github-actions[bot]
6010f9d8e2
Update changelog and version after v4.35.1
2026-03-27 16:10:47 +00:00
Henry Mercer
c10b8064de
Merge pull request #3782 from github/update-v4.35.1-d6d1743b8
...
Merge main into releases/v4
2026-03-27 16:07:37 +00:00
github-actions[bot]
c5ffd06837
Update changelog for v4.35.1
2026-03-27 15:39:16 +00:00
Henry Mercer
d6d1743b8e
Merge pull request #3781 from github/henrymercer/update-git-minimum-version
...
Update minimum Git version for overlay to 2.36.0
2026-03-27 14:59:36 +00:00
github-actions[bot]
999119ba45
Rebuild
2026-03-27 14:00:54 +00:00
Henry Mercer
65d2efa733
Add changelog note
2026-03-27 14:00:27 +00:00
Henry Mercer
2437b20ab3
Update minimum git version for overlay to 2.36.0
2026-03-27 14:00:17 +00:00
dependabot[bot]
f13c600724
Bump brace-expansion from 1.1.12 to 1.1.13
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 1.1.12 to 1.1.13.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.13 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.13
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 13:58:43 +00:00
Henry Mercer
7dcea06663
Remove unused @schemastore/package dependency
2026-03-27 13:57:52 +00:00
Michael B. Gale
ea5f71947c
Merge pull request #3775 from github/dependabot/npm_and_yarn/node-forge-1.4.0
...
Bump node-forge from 1.3.3 to 1.4.0
2026-03-27 13:47:55 +00:00
Henry Mercer
45ceeea896
Merge pull request #3777 from github/mergeback/v4.35.0-to-main-b8bb9f28
...
Mergeback v4.35.0 refs/heads/releases/v4 into main
2026-03-27 13:36:14 +00:00
github-actions[bot]
24448c9843
Rebuild
2026-03-27 12:23:25 +00:00
github-actions[bot]
7c51060631
Update changelog and version after v4.35.0
2026-03-27 12:14:07 +00:00
Óscar San José
b8bb9f28b8
Merge pull request #3776 from github/update-v4.35.0-0078ad667
...
Merge main into releases/v4
2026-03-27 13:11:18 +01:00
github-actions[bot]
e9cf68bb33
Update changelog for v4.35.0
2026-03-27 11:44:34 +00:00
github-actions[bot]
36791d8d66
Rebuild
2026-03-27 10:27:12 +00:00
dependabot[bot]
22eba96a28
Bump node-forge from 1.3.3 to 1.4.0
...
Bumps [node-forge](https://github.com/digitalbazaar/forge ) from 1.3.3 to 1.4.0.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.3...v1.4.0 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.4.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 10:25:06 +00:00
Óscar San José
0078ad667e
Merge pull request #3773 from github/update-bundle/codeql-bundle-v2.25.1
...
Update default bundle to 2.25.1
2026-03-27 10:02:52 +00:00
github-actions[bot]
fa7a15b909
Add changelog note
2026-03-27 09:43:23 +00:00
github-actions[bot]
8c29faa7ab
Update default bundle to codeql-bundle-v2.25.1
2026-03-27 09:43:12 +00:00
Henry Mercer
f94817b9f0
Merge pull request #3772 from github/dependabot/npm_and_yarn/yaml-2.8.3
...
Bump yaml from 2.8.2 to 2.8.3
2026-03-26 19:43:58 +00:00
dependabot[bot]
dd060970a5
Bump yaml from 2.8.2 to 2.8.3
...
Bumps [yaml](https://github.com/eemeli/yaml ) from 2.8.2 to 2.8.3.
- [Release notes](https://github.com/eemeli/yaml/releases )
- [Commits](https://github.com/eemeli/yaml/compare/v2.8.2...v2.8.3 )
---
updated-dependencies:
- dependency-name: yaml
dependency-version: 2.8.3
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-26 18:26:45 +00:00
Michael B. Gale
5cc552f43e
Merge pull request #3768 from github/dependabot/npm_and_yarn/npm-minor-3536e7c6f0
...
Bump the npm-minor group with 5 updates
2026-03-26 17:46:04 +00:00
Michael B. Gale
6b1a9f2131
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-3536e7c6f0
2026-03-26 16:36:54 +00:00
Michael B. Gale
9d3ec5727a
Merge pull request #3770 from github/dependabot/github_actions/dot-github/workflows/actions-minor-266139ee1d
...
Bump ruby/setup-ruby from 1.288.0 to 1.295.0 in /.github/workflows in the actions-minor group across 1 directory
2026-03-26 16:32:19 +00:00
Michael B. Gale
3ff82aacd0
Merge pull request #3575 from github/mbg/ts/sync-checks
...
Convert `release-branches.py` and `update-required-checks.sh` to TypeScript
2026-03-26 15:47:43 +00:00
Sam Robson
4bdd4e7526
Merge pull request #3554 from github/sam-robson/overlay-include-diff
...
feat: always include files from diff in overlay changed files
2026-03-26 10:57:24 +00:00
Sam Robson
23a0098b57
fix: improve error handling and logging for diff range path resolution
2026-03-25 19:53:21 +00:00
github-actions[bot]
ea7b090925
Rebuild
2026-03-25 18:01:40 +00:00
dependabot[bot]
a663d0174a
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.288.0 to 1.295.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/09a7688d3b55cf0e976497ff046b70949eeaccfd...319994f95fa847cf3fb3cd3dbe89f6dcde9f178f )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.295.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-25 17:59:44 +00:00
dependabot[bot]
b659882aae
Bump the npm-minor group with 5 updates
...
Bumps the npm-minor group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.3` | `0.27.4` |
| [eslint-plugin-import-x](https://github.com/un-ts/eslint-plugin-import-x ) | `4.16.1` | `4.16.2` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.7.1` | `62.8.0` |
| [sinon](https://github.com/sinonjs/sinon ) | `21.0.2` | `21.0.3` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ) | `8.57.0` | `8.57.1` |
Updates `esbuild` from 0.27.3 to 0.27.4
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.3...v0.27.4 )
Updates `eslint-plugin-import-x` from 4.16.1 to 4.16.2
- [Release notes](https://github.com/un-ts/eslint-plugin-import-x/releases )
- [Changelog](https://github.com/un-ts/eslint-plugin-import-x/blob/master/CHANGELOG.md )
- [Commits](https://github.com/un-ts/eslint-plugin-import-x/compare/v4.16.1...v4.16.2 )
Updates `eslint-plugin-jsdoc` from 62.7.1 to 62.8.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.7.1...v62.8.0 )
Updates `sinon` from 21.0.2 to 21.0.3
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.2...v21.0.3 )
Updates `typescript-eslint` from 8.57.0 to 8.57.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: esbuild
dependency-version: 0.27.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-import-x
dependency-version: 4.16.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.8.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.57.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-25 17:53:49 +00:00
Sam Robson
d5bb39fa0b
refactor: single source of truth for getDiffRangesJsonFilePath and simplified getDiffRangeFilePaths
2026-03-25 15:51:51 +00:00
Sam Robson
521c3536d3
feat: always include files from diff in overlay changed files
2026-03-25 15:51:51 +00:00
Michael B. Gale
972365e142
Fix comment
2026-03-25 14:15:39 +00:00
Michael B. Gale
8a0b4f2746
fixup! Update CONTRIBUTING.md
2026-03-25 14:14:49 +00:00
Michael B. Gale
a5418e172c
Delete releases.ini
2026-03-25 13:49:47 +00:00
Michael B. Gale
fae4c28b51
Update CONTRIBUTING.md
2026-03-25 13:48:55 +00:00
Michael B. Gale
661a8fbbe3
Default ref to main
2026-03-25 13:40:05 +00:00
Michael B. Gale
e7c7b68c5f
Remove update-required-checks.sh
2026-03-25 13:38:28 +00:00
Michael B. Gale
fa568ebc69
Delete release-branches.py
2026-03-25 13:37:41 +00:00
Michael B. Gale
0da3139813
Rename to branchName
2026-03-25 13:35:02 +00:00
Michael B. Gale
0abe92ed20
Configure ESLint import/no-extraneous-dependencies rule for pr-checks
2026-03-25 13:17:37 +00:00
Michael B. Gale
07f235e5f2
Add --verbose option
2026-03-25 13:17:37 +00:00
Michael B. Gale
9fd40ff508
Tidy up pr-checks/package.json
2026-03-25 13:17:37 +00:00
Michael B. Gale
75ed461aaa
Add excluded.yml path to config.ts
2026-03-25 13:16:35 +00:00
Michael B. Gale
cfc18781e0
Rebuild
2026-03-25 13:16:34 +00:00
Michael B. Gale
9fe42f69b7
Add some unit tests for sync-checks.ts
2026-03-25 13:16:33 +00:00
Michael B. Gale
c5a984e1aa
Update CONTRIBUTING.md
2026-03-25 13:16:33 +00:00
Michael B. Gale
0543156694
Actually perform the update when necessary and requested
2026-03-25 13:16:33 +00:00
Michael B. Gale
4cec5d2830
Call updateBranch for main
2026-03-25 13:16:32 +00:00
Michael B. Gale
74dd691a45
Identify changes before applying them
2026-03-25 13:16:32 +00:00
Michael B. Gale
a5244bf7dd
Fetch release branches and identify major versions
2026-03-25 13:16:32 +00:00
Michael B. Gale
1bc611ed0c
Fetch and filter check runs for ref
2026-03-25 13:16:32 +00:00
Michael B. Gale
d2008eee7c
Add type to represent exclusions.yml and loading helper
2026-03-25 13:16:32 +00:00
Michael B. Gale
9481177f3d
Initialise API client
2026-03-25 13:16:31 +00:00
Michael B. Gale
9813849e61
Add initial TS implementation of update-required-checks.sh
2026-03-25 13:16:31 +00:00
Michael B. Gale
4867f5927a
Add config file for excluded checks from update-required-checks.sh
2026-03-25 13:16:31 +00:00
Michael B. Gale
49af37b7ab
Add tests for release-branches.ts
2026-03-25 13:16:31 +00:00
Michael B. Gale
b72f4fec40
Validate inputs
2026-03-25 13:16:30 +00:00
Michael B. Gale
0d87a75829
Refactor backport computation into computeReleaseBranches
2026-03-25 13:16:30 +00:00
Michael B. Gale
3db9a05c73
Replace release-branches.py with TS version in release-branches action
2026-03-25 13:16:30 +00:00
Michael B. Gale
aa2773169b
Install node in release-initialise action
2026-03-25 13:16:30 +00:00
Michael B. Gale
054745baee
Convert release-branches.py to TypeScript
2026-03-25 13:16:30 +00:00
Michael B. Gale
3d564d9359
Merge pull request #3579 from github/mbg/start-proxy/token-check-fixes
...
Fix warning for PAT-like token with username
2026-03-25 13:02:47 +00:00
Michael B. Gale
137e0dec2b
Merge remote-tracking branch 'origin/main' into mbg/start-proxy/token-check-fixes
2026-03-25 12:39:48 +00:00
Michael B. Gale
d128e5daa8
Fix test names
2026-03-25 12:39:42 +00:00
Henry Mercer
eedab83377
Merge pull request #3767 from github/henrymercer/overlay-reduce-minimum-git-version
...
Reduce the minimum Git version required for overlay
2026-03-24 11:26:07 +00:00
Henry Mercer
8c023a6b07
Add changelog note
2026-03-23 18:40:55 +00:00
Henry Mercer
28f56f2bed
Update minimum Git version required for overlay
2026-03-23 18:36:25 +00:00
Henry Mercer
d48d054533
Use --stage instead of --format in git ls-files
2026-03-23 18:33:59 +00:00
Henry Mercer
72c0b0efb7
Merge pull request #3587 from github/dependabot/npm_and_yarn/fast-xml-parser-5.5.7
...
Bump fast-xml-parser from 5.5.6 to 5.5.7
2026-03-23 14:22:53 +00:00
Henry Mercer
05b1a5d28f
Merge pull request #3764 from github/mergeback/v4.34.1-to-main-38697555
...
Mergeback v4.34.1 refs/heads/releases/v4 into main
2026-03-20 18:38:55 +00:00
github-actions[bot]
8dc2e5d9d2
Rebuild
2026-03-20 18:19:40 +00:00
github-actions[bot]
8fd6c0e573
Update changelog and version after v4.34.1
2026-03-20 18:14:55 +00:00
Henry Mercer
3869755554
Merge pull request #3763 from github/update-v4.34.1-095e0fe50
...
Merge main into releases/v4
2026-03-20 18:10:50 +00:00
github-actions[bot]
20e68ac12b
Update changelog for v4.34.1
2026-03-20 17:33:39 +00:00
Henry Mercer
095e0fe505
Merge pull request #3762 from github/henrymercer/downgrade-default-bundle
...
Downgrade default bundle to 2.24.3
2026-03-20 17:06:34 +00:00
Henry Mercer
47b94fe61c
Add changelog note
2026-03-20 16:46:45 +00:00
Henry Mercer
51a1d6917f
Downgrade default bundle to codeql-bundle-v2.24.3
2026-03-20 16:45:20 +00:00
Óscar San José
510cf736e3
Merge pull request #3589 from github/mergeback/v4.34.0-to-main-c6f93110
...
Mergeback v4.34.0 refs/heads/releases/v4 into main
2026-03-20 15:15:34 +00:00
github-actions[bot]
89f0c86efa
Rebuild
2026-03-20 12:03:59 +00:00
github-actions[bot]
c3f90ba975
Update changelog and version after v4.34.0
2026-03-20 11:56:24 +00:00
Óscar San José
c6f931105c
Merge pull request #3588 from github/update-v4.34.0-30c555a52
...
Merge main into releases/v4
2026-03-20 12:53:53 +01:00
github-actions[bot]
eeb9b3f424
Update changelog for v4.34.0
2026-03-20 10:35:57 +00:00
github-actions[bot]
64507ed148
Rebuild
2026-03-20 01:40:06 +00:00
dependabot[bot]
1a45a9b9d0
Bump fast-xml-parser from 5.5.6 to 5.5.7
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.5.6 to 5.5.7.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.6...v5.5.7 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.5.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 01:38:13 +00:00
Idriss Riouak
30c555a528
Merge pull request #3584 from github/idrissrio/cpp/overlay
...
Feature flag: C/C++ overlay
2026-03-19 15:26:48 +00:00
Idriss Riouak
39191bd27f
Merge branch 'main' into idrissrio/cpp/overlay
2026-03-19 15:42:47 +01:00
Óscar San José
147e93e5dc
Merge pull request #3585 from github/update-bundle/codeql-bundle-v2.25.0
...
Update default bundle to 2.25.0
2026-03-19 14:14:03 +00:00
Idriss Riouak
e6d83bce6d
Update CHANGELOG.md
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2026-03-19 14:58:16 +01:00
idrissrio
0d057ccbce
Add changelog note for C/C++ overlay
2026-03-19 14:11:02 +01:00
idrissrio
074a0dbd16
Feature flag: update test without overlay support
2026-03-19 14:11:02 +01:00
idrissrio
ab3b6fd199
Feature flag: address copilot comment
...
Wire C/C++ overlay feature flags into overlay mapping
2026-03-19 14:11:00 +01:00
idrissrio
ce4a1feb6a
Feature flag: update generated lib after build
2026-03-19 14:10:57 +01:00
idrissrio
899a672743
Feature flag: C/C++ overlay
2026-03-19 14:10:56 +01:00
github-actions[bot]
f4be604881
Add changelog note
2026-03-19 12:01:31 +00:00
github-actions[bot]
0bc1b6f632
Update default bundle to codeql-bundle-v2.25.0
2026-03-19 12:01:20 +00:00
Henry Mercer
3d8036cf7f
Merge pull request #3583 from github/dependabot/github_actions/dot-github/workflows/actions/create-github-app-token-3.0.0
...
Bump actions/create-github-app-token from 2.2.1 to 3.0.0 in /.github/workflows
2026-03-19 10:37:38 +00:00
Henry Mercer
9fecf32c77
Merge pull request #3581 from github/dependabot/npm_and_yarn/npm-minor-a87b0427cc
...
Bump the npm-minor group with 2 updates
2026-03-19 10:34:28 +00:00
Henry Mercer
07d509fbaf
Merge pull request #3569 from github/henrymercer/overlay-no-trap-caching
...
Disable TRAP caching when overlay is enabled
2026-03-19 10:12:30 +00:00
dependabot[bot]
23674c1f2a
Bump actions/create-github-app-token in /.github/workflows
...
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token ) from 2.2.1 to 3.0.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.2.1...v3.0.0 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 18:10:06 +00:00
dependabot[bot]
ecd1c77ffa
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `@eslint/compat` from 2.0.2 to 2.0.3
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.3/packages/compat )
Updates `typescript-eslint` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 17:53:32 +00:00
Henry Mercer
5b630489d6
Fix changelog automerge
2026-03-18 17:10:57 +00:00
Henry Mercer
582d08c553
Explicitly set C/C++ trap caching env var to false
2026-03-18 17:10:13 +00:00
Henry Mercer
60a0dce0ad
Merge branch 'main' into henrymercer/overlay-no-trap-caching
...
# Conflicts:
# lib/start-proxy-action.js
2026-03-18 16:35:51 +00:00
Henry Mercer
7da6361ba5
Merge pull request #3580 from github/dependabot/npm_and_yarn/fast-xml-parser-5.5.6
...
Bump fast-xml-parser from 5.4.1 to 5.5.6
2026-03-18 11:50:18 +00:00
Sam Robson
08d1198b01
Merge pull request #3248 from github/kaspersv/move-diff-range-absolute-path-conversion
...
Move conversion of PR diff-range paths to absolute paths
2026-03-18 11:41:58 +00:00
Sam Robson
5e54629286
Merge branch 'main' into kaspersv/move-diff-range-absolute-path-conversion
...
* main: (112 commits)
Rebuild
Update changelog and version after v4.33.0
Add changelog entry for #3570
Bump minor version
Update changelog for v4.32.7
Only emit one message with accumulated property names
Remove `cache-dependency-path` options as well
Remove `package-lock.json` that's no longer needed
Add step (in root directory) to install dependencies
Add explicit cache dependency paths in `pr-checks.yml`
Fix linter errors in `sync-back.test.ts`
Fix linter errors in `sync-back.ts`
Rename `sync_back` to `sync-back`
Fix linter errors in `sync.ts`
Add eslint configuration for `pr-checks`
Add minimal `Step` type
Add `workspaces` to root `package.json`
Avoid bundling `package.json`
Move `ava` config out of `package.json`
Emit warning for unrecognised repo properties with our common prefix
...
# Conflicts:
# lib/init-action-post.js
2026-03-18 10:47:46 +00:00
github-actions[bot]
f254006ed7
Rebuild
2026-03-18 01:38:11 +00:00
dependabot[bot]
573e7dd341
Bump fast-xml-parser from 5.4.1 to 5.5.6
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.4.1 to 5.5.6.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.4.1...v5.5.6 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.5.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-18 01:36:15 +00:00
Michael B. Gale
f88d49ee5d
Fix warning for PAT-like token with username
2026-03-16 19:34:33 +00:00
Michael B. Gale
28f515d9ad
Add tests for the absence of the warning
2026-03-16 19:34:33 +00:00
Michael B. Gale
de06821112
Add hasMessage to RecordingLogger
2026-03-16 19:34:33 +00:00
Michael B. Gale
ddafddb826
Replace getRecordingLogger implementation with RecordingLogger
2026-03-16 19:34:32 +00:00
Michael B. Gale
740f177889
Add assertNotLogged test helper
2026-03-16 19:34:32 +00:00
Michael B. Gale
0393130759
Add "token without a username" test
2026-03-16 19:34:32 +00:00
Michael B. Gale
f86097dfdb
Add params for credentials and checkAccepted to testPATWarning
2026-03-16 19:34:32 +00:00
Michael B. Gale
6e67ef61f2
Refactor PAT test into a test.macro
2026-03-16 19:34:32 +00:00
Michael B. Gale
193dd19c2d
Add snippet to scaffold test.macros
2026-03-16 19:34:32 +00:00
Michael B. Gale
fd1ca02d0d
Merge pull request #3576 from github/mergeback/v4.33.0-to-main-b1bff819
...
Mergeback v4.33.0 refs/heads/releases/v4 into main
2026-03-16 12:22:52 +00:00
github-actions[bot]
a0e3ed6555
Rebuild
2026-03-16 09:08:32 +00:00
github-actions[bot]
fbb2eb9556
Update changelog and version after v4.33.0
2026-03-16 09:03:58 +00:00
Michael B. Gale
b1bff81932
Merge pull request #3574 from github/update-v4.32.7-7dd76e6bf
...
Merge main into releases/v4
2026-03-16 09:01:14 +00:00
Michael B. Gale
e682234222
Add changelog entry for #3570
2026-03-16 08:43:35 +00:00
Michael B. Gale
95be291f41
Bump minor version
2026-03-16 08:38:13 +00:00
github-actions[bot]
59bcb6025e
Update changelog for v4.32.7
2026-03-16 08:20:09 +00:00
Michael B. Gale
7dd76e6bf7
Merge pull request #3572 from github/mbg/pr-checks/eslint
...
Add eslint for `pr-checks`
2026-03-13 18:51:29 +00:00
Michael B. Gale
e3200e331b
Merge pull request #3563 from github/mbg/private-registry/oidc
...
Accept OIDC configurations in `start-proxy`
2026-03-13 11:58:36 +00:00
Michael B. Gale
4c356c71a2
Merge pull request #3570 from github/mbg/repo-props/warn-on-unexpected-props
...
Emit warning for unrecognised repo properties with our common prefix
2026-03-13 11:13:21 +00:00
Michael B. Gale
b4937c19e5
Only emit one message with accumulated property names
2026-03-13 10:56:36 +00:00
Michael B. Gale
136b8ab377
Remove cache-dependency-path options as well
2026-03-13 10:46:40 +00:00
Michael B. Gale
a5aba5952c
Remove package-lock.json that's no longer needed
...
Since `pr-checks` is now a workspace of the main `package.json`
2026-03-13 10:43:43 +00:00
Michael B. Gale
dafe74070a
Merge pull request #3573 from github/mbg/esbuild/no-package-json
...
Avoid bundling `package.json` in JavaScript files
2026-03-13 10:38:58 +00:00
Michael B. Gale
fc8d303906
Add step (in root directory) to install dependencies
2026-03-12 22:39:45 +00:00
Michael B. Gale
3bc3228be2
Add explicit cache dependency paths in pr-checks.yml
2026-03-12 22:39:45 +00:00
Michael B. Gale
b4cb1049fb
Fix linter errors in sync-back.test.ts
2026-03-12 22:39:45 +00:00
Michael B. Gale
b171c1c6d9
Fix linter errors in sync-back.ts
2026-03-12 22:39:44 +00:00
Michael B. Gale
967ca853e1
Rename sync_back to sync-back
2026-03-12 22:39:44 +00:00
Michael B. Gale
7950e47b7f
Fix linter errors in sync.ts
2026-03-12 22:39:44 +00:00
Michael B. Gale
e608db4784
Add eslint configuration for pr-checks
2026-03-12 22:39:44 +00:00
Michael B. Gale
7df3db2b6f
Add minimal Step type
2026-03-12 22:39:44 +00:00
Michael B. Gale
b5e1fb009d
Add workspaces to root package.json
2026-03-12 22:39:44 +00:00
Michael B. Gale
ea703668e0
Avoid bundling package.json
...
- `package.json` is bundled by `esbuild` because we depend on it in `actions-util.ts`
- That is so we can access the `version` property
- We now use `build.mjs` to define a constant for it instead
- We also set this constant in `ava.setup.mjs` for tests
- This reduces the size of the generated `.js` files and avoids changing them entirely in some cases
2026-03-12 18:55:03 +00:00
Michael B. Gale
c183dca871
Move ava config out of package.json
2026-03-12 18:43:14 +00:00
Michael B. Gale
a717db1a90
Emit warning for unrecognised repo properties with our common prefix
2026-03-12 11:49:17 +00:00
Henry Mercer
1dbebad653
Merge pull request #3566 from github/dependabot/npm_and_yarn/npm-minor-aebc49e072
...
Bump the npm-minor group with 2 updates
2026-03-11 20:49:27 +00:00
Henry Mercer
82d7a77abc
Merge pull request #3567 from github/dependabot/npm_and_yarn/ava-7.0.0
...
Bump ava from 6.4.1 to 7.0.0
2026-03-11 20:47:14 +00:00
Henry Mercer
926e6dfee5
Stub RUNNER_NAME in unit tests
2026-03-11 20:16:47 +00:00
Henry Mercer
b1f1e7bd31
Add changelog note
2026-03-11 19:56:42 +00:00
Henry Mercer
a91b7a3e57
Add unit tests for isTrapCachingEnabled
2026-03-11 19:52:12 +00:00
github-actions[bot]
0d0df94d93
Rebuild
2026-03-11 19:51:54 +00:00
github-actions[bot]
373dec9f22
Rebuild
2026-03-11 19:51:53 +00:00
Henry Mercer
9771a765ac
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-aebc49e072
2026-03-11 19:49:56 +00:00
Henry Mercer
363219d88d
Merge branch 'main' into dependabot/npm_and_yarn/ava-7.0.0
2026-03-11 19:49:53 +00:00
Henry Mercer
556dd79c4b
Drive-by comment fixes
2026-03-11 19:33:57 +00:00
Henry Mercer
19544bb9b4
Remove dead Python library extraction code
2026-03-11 19:32:36 +00:00
Henry Mercer
d74701caa1
Drive-by cleanup: Always use --cache-cleanup
2026-03-11 19:31:03 +00:00
Henry Mercer
d05b50b13f
Clean up: Remove unneeded CodeQL version guard
2026-03-11 19:30:13 +00:00
Henry Mercer
70d5cccce1
Disable TRAP caching when conditions met
2026-03-11 19:25:29 +00:00
Henry Mercer
b04e63ffdf
Enablement: Move TRAP caching check after overlay
2026-03-11 19:21:17 +00:00
Henry Mercer
378e4b367d
Merge pull request #3568 from github/henrymercer/fix-rebuild
...
Fix rebuild Action
2026-03-11 19:18:28 +00:00
Henry Mercer
309fd2aac7
Merge pull request #3565 from github/henrymercer/go-macos-checks
...
PR checks: Only run Go macOS tests on latest CodeQL versions
2026-03-11 19:11:16 +00:00
Henry Mercer
b0f877255d
Add FF for disabling TRAP caching when overlay enabled
2026-03-11 18:44:41 +00:00
Henry Mercer
567ca73ff8
Address review comments
2026-03-11 18:40:22 +00:00
Henry Mercer
5f3f250f83
Fix finishing up in progress merge
2026-03-11 18:24:00 +00:00
Henry Mercer
6fb1c2a300
Fix merge in progress detection
2026-03-11 18:23:04 +00:00
Henry Mercer
44720043ea
CI: Set up Node.js 24 in rebuild workflow
2026-03-11 18:18:30 +00:00
dependabot[bot]
f9f5edb76f
Bump ava from 6.4.1 to 7.0.0
...
Bumps [ava](https://github.com/avajs/ava ) from 6.4.1 to 7.0.0.
- [Release notes](https://github.com/avajs/ava/releases )
- [Commits](https://github.com/avajs/ava/compare/v6.4.1...v7.0.0 )
---
updated-dependencies:
- dependency-name: ava
dependency-version: 7.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-11 17:53:48 +00:00
dependabot[bot]
de2997a8c8
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [globals](https://github.com/sindresorhus/globals ) and [sinon](https://github.com/sinonjs/sinon ).
Updates `globals` from 17.3.0 to 17.4.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.3.0...v17.4.0 )
Updates `sinon` from 21.0.1 to 21.0.2
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.1...v21.0.2 )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-11 17:53:18 +00:00
Henry Mercer
117bf916af
Sort OS list and versions consistently
2026-03-11 17:11:07 +00:00
Henry Mercer
30ecc82e64
PR checks: Replace inline arrays
...
Lists are easier to modify
2026-03-11 17:11:07 +00:00
Henry Mercer
4174779474
PR checks: Only run Go macOS tests on latest CodeQL versions
2026-03-11 17:10:56 +00:00
Henry Mercer
2bc06587aa
PR checks: Add support for per-OS CodeQL version
2026-03-11 17:10:45 +00:00
Michael B. Gale
6c99ca514e
Merge remote-tracking branch 'origin/main' into mbg/private-registry/oidc
2026-03-11 16:15:07 +00:00
Michael B. Gale
1a97b0f94e
Merge pull request #3541 from github/mbg/pr-checks/validation-jobs
...
Add support for validation jobs to `sync.ts`, and refactor
2026-03-11 14:43:46 +00:00
Michael B. Gale
d1a7580bd3
Verify PR checks in a different job, with newer Node
2026-03-11 12:29:36 +00:00
Michael B. Gale
89f63211ed
Use version in error message
2026-03-11 12:18:41 +00:00
Michael B. Gale
6570ad3440
Extend base tsconfig.json
2026-03-11 12:16:28 +00:00
Michael B. Gale
be7fe2bca6
Make it more explicit by construction that known inputs always have the same specifications
2026-03-11 12:14:41 +00:00
Michael B. Gale
2e1f08fe70
Remove installPython condition in sync.ts
...
The behaviour of `installPython` now mirrors other `install*` options
2026-03-11 11:55:59 +00:00
Michael B. Gale
b9b42bed94
Remove last use of installPython
...
- Add explicit `setup-python` step with condition to the workflow that was still using it
- This allows simplifying the logic in `sync.ts`
2026-03-11 11:55:16 +00:00
Henry Mercer
997acaf7eb
Merge pull request #3562 from github/henrymercer/skip-file-coverage-rollout
...
Prepare for rolling out skipping computing file coverage information on PRs
2026-03-11 11:33:21 +00:00
Henry Mercer
2e7e91fd63
Merge pull request #3550 from github/sam-robson/overlay-per-lang-min-bundle-version
...
feat: add minimumVersion values for language overlay flags
2026-03-11 10:28:14 +00:00
Henry Mercer
5cb13d6ab8
Merge pull request #3564 from github/henrymercer/fix-database-upload-retries
...
Fix retries when uploading databases
2026-03-10 16:56:27 +00:00
Henry Mercer
a63886bff5
Refactor: Extract separate function for uploadBundledDatabase
2026-03-10 16:36:02 +00:00
Henry Mercer
a11c6cbbc8
Merge branch 'main' into henrymercer/skip-file-coverage-rollout
2026-03-10 16:25:21 +00:00
Michael B. Gale
048d0ea295
Address review comments
2026-03-10 15:54:58 +00:00
Henry Mercer
cf972cde0e
Update database upload tests to use checkExpectedLogMessages
2026-03-10 15:52:14 +00:00
Henry Mercer
ee5ede79f7
Address review comments
2026-03-10 15:51:28 +00:00
Henry Mercer
e07c3055d7
Tweak changelog formatting
2026-03-10 15:43:28 +00:00
Henry Mercer
55a0f2b2aa
Add environment variable override
2026-03-10 15:41:40 +00:00
Michael B. Gale
c92efdb98d
Type result of parsing JSON as unknown until narrowed
2026-03-10 15:31:21 +00:00
Michael B. Gale
c6e75ac1e8
Add JSON helper types and functions
2026-03-10 15:31:21 +00:00
Sam Robson
79ea59d97e
Merge branch 'main' into sam-robson/overlay-per-lang-min-bundle-version
2026-03-10 14:13:22 +00:00
Michael B. Gale
823869da10
Use isDefined for password and token in credentialToStr
2026-03-10 13:30:52 +00:00
Michael B. Gale
131392e95f
Fix changelog entry
2026-03-10 13:23:16 +00:00
Henry Mercer
bef08edf32
Update to log deprecation warning
...
Move rollout to April
2026-03-10 13:14:00 +00:00
Henry Mercer
edfcb0a509
Update tests
2026-03-10 12:49:58 +00:00
Henry Mercer
ca969a91db
Add changelog note
2026-03-10 12:34:47 +00:00
Henry Mercer
13c548978d
Fix retries when uploading databases
2026-03-10 12:34:18 +00:00
Michael B. Gale
87c3b7b6a1
Merge pull request #3519 from github/mbg/csra/upload-failed-sarif-artifact
...
Upload failed SARIF for risk assessments in `init-post` step
2026-03-10 11:53:12 +00:00
Henry Mercer
ce321daddb
Merge branch 'main' into henrymercer/skip-file-coverage-rollout
2026-03-10 11:46:08 +00:00
Henry Mercer
55ae11793a
Reduce duplication of getFileCoverageInformationEnabled
2026-03-10 11:42:53 +00:00
Henry Mercer
3d2bdbbd3b
Simplify default repo properties
2026-03-10 11:33:00 +00:00
Michael B. Gale
e90d128a3c
Add preliminary change note
2026-03-10 02:14:53 +00:00
Michael B. Gale
88bd340eb0
Add OIDC tests for getCredentials
2026-03-10 02:14:52 +00:00
Michael B. Gale
4649e158bc
Fix old test
2026-03-10 02:14:52 +00:00
Michael B. Gale
3d574205fc
Run more start-proxy tests in parallel
2026-03-10 02:14:52 +00:00
Michael B. Gale
e168f8e52a
Move credentialToStr and update it
2026-03-10 02:14:52 +00:00
Michael B. Gale
7263be2084
Extract AuthConfig from Credential
2026-03-10 01:26:15 +00:00
Michael B. Gale
37eb89b173
Add predicates for Auth types
2026-03-10 01:26:15 +00:00
Michael B. Gale
9e26f9e6e0
Add OIDC config types
2026-03-10 01:26:15 +00:00
Michael B. Gale
01b52624a0
Move out auth config from Credential type
2026-03-10 01:26:15 +00:00
Sam Robson
8bddab0644
Merge branch 'main' into sam-robson/overlay-per-lang-min-bundle-version
2026-03-09 20:23:29 +00:00
Michael B. Gale
65f7f36302
Extend isPrintable check to all keys with string values
2026-03-09 19:06:06 +00:00
Michael B. Gale
746f940d10
Merge remote-tracking branch 'origin/main' into mbg/csra/upload-failed-sarif-artifact
2026-03-09 18:32:36 +00:00
Michael B. Gale
babab88e54
Merge pull request #3561 from github/henrymercer/eslint-unused-vars
...
Linting: Require unused function parameters to start with `_`
2026-03-09 18:00:46 +00:00
Michael B. Gale
0ad7d7be2f
Merge pull request #3560 from github/henrymercer/ghes-3.13-cleanup
...
Clean up pre GHES 3.14 code paths
2026-03-09 18:00:31 +00:00
Michael B. Gale
8ba8180559
Merge remote-tracking branch 'origin/main' into mbg/pr-checks/validation-jobs
2026-03-09 17:58:41 +00:00
Henry Mercer
3592fe5d7a
Address review comments
2026-03-09 17:32:57 +00:00
Henry Mercer
3c97288d80
Merge pull request #3559 from github/henrymercer/ghes-repository-properties
...
Load custom repository properties on GHES and remove feature flag
2026-03-09 17:26:59 +00:00
Henry Mercer
6773afd159
Add changelog note
2026-03-09 17:14:12 +00:00
Henry Mercer
a3fdd0e0b5
Add telemetry diagnostic to track whether repo property is used
2026-03-09 17:13:41 +00:00
Henry Mercer
9e8c05933f
Add ability to override via repository property
2026-03-09 17:08:13 +00:00
Henry Mercer
c102a6d8cd
Require tools feature flag
...
And now that we have this, drop the restriction to `github` org.
2026-03-09 17:07:10 +00:00
Sam Robson
867f2b0e0a
test: verify overlay analysis is disabled for languages without per-language feature flags
2026-03-09 16:46:38 +00:00
Sam Robson
e04697664c
feat: add minimumVersion values for existing language-specific overlay feature flags
2026-03-09 16:45:20 +00:00
Henry Mercer
fdecf48e22
Linting: Require unused function parameters to start with _
2026-03-09 16:43:17 +00:00
Henry Mercer
ab180c9eeb
Clean up pre GHES 3.14 code paths
2026-03-09 16:35:29 +00:00
Henry Mercer
1b7fa1a121
Drop unused variable
2026-03-09 16:30:34 +00:00
Henry Mercer
b0642f9e86
Remove unused imports
2026-03-09 16:25:20 +00:00
Henry Mercer
a770e76359
Add changelog note
2026-03-09 16:20:52 +00:00
Henry Mercer
8924dfb7d0
Remove GHES feature gate
...
All supported versions of GHES support the repository properties API.
2026-03-09 16:19:32 +00:00
Henry Mercer
b35c0d37b1
Clean up repository properties feature flag
2026-03-09 16:15:04 +00:00
Michael B. Gale
b39251fe78
Merge pull request #3557 from github/mbg/repo-props/multi-select
...
Fix handling of non-`string` values from repository properties API
2026-03-09 14:48:17 +00:00
Michael B. Gale
f054eea342
Merge pull request #3549 from github/mbg/pr-checks/remove-python-setup
...
Remove `installPython` from checks which should no longer need it
2026-03-09 14:48:05 +00:00
Michael B. Gale
6f90eb695f
Add changelog entry
2026-03-09 14:24:29 +00:00
Michael B. Gale
5ddbbbe614
Install python if there is no matrix.version
2026-03-09 14:16:23 +00:00
Michael B. Gale
da11f44114
Run prepare-test after setup steps
2026-03-09 14:13:22 +00:00
Michael B. Gale
149fd14ac7
Add unknown property with string[] value
2026-03-09 13:12:37 +00:00
Michael B. Gale
5311ed41ea
Include type in error message
2026-03-09 13:09:34 +00:00
Michael B. Gale
58314dce95
Export types that weren't already
2026-03-09 13:03:47 +00:00
Michael B. Gale
58991590bd
Validate value types returned by API against expectations
2026-03-09 12:46:24 +00:00
Michael B. Gale
9c75a5f60c
Only validate property value type if we care about the property
2026-03-09 12:13:48 +00:00
Michael B. Gale
8e70ae21a1
Update GitHubRepositoryProperty to match schema
2026-03-09 12:03:34 +00:00
Sam Robson
9082319f5c
Merge branch 'main' into kaspersv/move-diff-range-absolute-path-conversion
2026-03-06 15:03:13 +00:00
Sam Robson
cdafc35ccb
refactor: pass checkoutPath as param to writeDiffRangeDataExtensionPack
2026-03-06 10:12:08 +00:00
Óscar San José
d1a65275e8
Merge pull request #3552 from github/mergeback/v4.32.6-to-main-0d579ffd
...
Mergeback v4.32.6 refs/heads/releases/v4 into main
2026-03-06 10:03:43 +00:00
Sam Robson
c10020e6a8
Merge remote-tracking branch 'origin/main' into kaspersv/move-diff-range-absolute-path-conversion
...
* origin/main: (32 commits)
Add changelog note
Update default bundle to codeql-bundle-v2.24.3
Bump tar from 7.5.7 to 7.5.10
Rebuild
Rebuild
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
Bump actions/download-artifact from 7 to 8 in /.github/workflows
Bump the npm-minor group with 2 updates
Fix some tests that should be serial
Update method naming and JSDoc
Rename to `EnabledOverlayConfig`
Address review comments
Use `Result`s for enablement return types
Add disabled by env var disablement reason
Rename to `usesDefaultQueriesOnly`
Update `NonDefaultQueries` documentation
Refactor `getOverlayDatabaseMode` and add new disablement reason
Address review comments
Add JSDoc
Sort `OverlayDisabledReason` enum
...
2026-03-06 09:10:13 +00:00
github-actions[bot]
0ccdcb8c0a
Rebuild
2026-03-05 19:44:36 +00:00
github-actions[bot]
05a48207b3
Update changelog and version after v4.32.6
2026-03-05 19:33:19 +00:00
Óscar San José
0d579ffd05
Merge pull request #3551 from github/update-v4.32.6-72d2d850d
...
Merge main into releases/v4
2026-03-05 20:29:07 +01:00
github-actions[bot]
d4c6be7cf1
Update changelog for v4.32.6
2026-03-05 18:58:14 +00:00
Sam Robson
b2de4934cf
refactor: pass checkoutPath as param and fix docs for relative path semantics
2026-03-05 18:09:06 +00:00
Michael B. Gale
0da2e79318
Remove installPython from checks which should no longer need it
2026-03-05 16:17:19 +00:00
Michael B. Gale
2a0060496c
Fix condition
2026-03-05 16:07:10 +00:00
Michael B. Gale
103db93efa
Make it more explicit that getSetupSteps just needs a JobSpecification
2026-03-05 16:06:03 +00:00
Óscar San José
72d2d850d1
Merge pull request #3548 from github/update-bundle/codeql-bundle-v2.24.3
...
Update default bundle to 2.24.3
2026-03-05 16:02:55 +00:00
Michael B. Gale
23f983ce00
Merge pull request #3544 from github/dependabot/github_actions/dot-github/workflows/actions/download-artifact-8
...
Bump actions/download-artifact from 7 to 8 in /.github/workflows
2026-03-05 15:54:50 +00:00
Michael B. Gale
79fdef791d
Fix generateValidationJobs typing
2026-03-05 15:54:33 +00:00
Michael B. Gale
3d478129f2
Add tsconfig.json for pr-checks
2026-03-05 15:54:17 +00:00
Michael B. Gale
832e97ccad
Merge pull request #3545 from github/dependabot/github_actions/dot-github/workflows/actions/upload-artifact-7
...
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
2026-03-05 15:52:06 +00:00
Michael B. Gale
5ef38c0b13
Merge pull request #3546 from github/dependabot/npm_and_yarn/tar-7.5.10
...
Bump tar from 7.5.7 to 7.5.10
2026-03-05 15:48:25 +00:00
Michael B. Gale
56ebdff8ae
Merge branch 'main' into mbg/pr-checks/validation-jobs
2026-03-05 15:39:28 +00:00
github-actions[bot]
80c9cda739
Add changelog note
2026-03-05 15:34:29 +00:00
github-actions[bot]
f2669dd916
Update default bundle to codeql-bundle-v2.24.3
2026-03-05 15:34:19 +00:00
Michael B. Gale
bd03c44cf4
Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/download-artifact-8
2026-03-05 15:32:00 +00:00
dependabot[bot]
102d7627b6
Bump tar from 7.5.7 to 7.5.10
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.5.7 to 7.5.10.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.7...v7.5.10 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.10
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-05 14:47:50 +00:00
Henry Mercer
0c0c5dc2f1
Merge pull request #3543 from github/dependabot/npm_and_yarn/npm-minor-af60a9b329
...
Bump the npm-minor group with 2 updates
2026-03-05 13:40:16 +00:00
github-actions[bot]
e96635d9ff
Rebuild
2026-03-05 13:19:38 +00:00
github-actions[bot]
77f9a86c60
Rebuild
2026-03-05 13:19:28 +00:00
github-actions[bot]
e681b9fb11
Merge remote-tracking branch 'origin/main' into dependabot/github_actions/dot-github/workflows/actions/upload-artifact-7
2026-03-05 13:18:44 +00:00
github-actions[bot]
bc4b00aadc
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_yarn/npm-minor-af60a9b329
2026-03-05 13:18:38 +00:00
Henry Mercer
05b6a6cfaa
Merge pull request #3538 from github/henrymercer/breakdown-overlay-disabled-reason
...
Break down overlay disabled reason
2026-03-05 13:13:13 +00:00
Michael B. Gale
b1b5550715
Merge pull request #3529 from github/mbg/ts/sync-back
...
Convert `sync_back.py` to TypeScript
2026-03-05 12:36:22 +00:00
Sam Robson
1443f5865e
chore: merge main into kaspersv/move-diff-range-absolute-path-conversion
2026-03-05 11:38:11 +00:00
dependabot[bot]
31d26f2397
Bump actions/upload-artifact from 6 to 7 in /.github/workflows
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 6 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 18:01:17 +00:00
dependabot[bot]
4d433615e7
Bump actions/download-artifact from 7 to 8 in /.github/workflows
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 7 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 18:00:15 +00:00
dependabot[bot]
545356f200
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ).
Updates `eslint-plugin-jsdoc` from 62.6.0 to 62.7.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.6.0...v62.7.1 )
Updates `typescript-eslint` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.7.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: typescript-eslint
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-04 17:53:15 +00:00
Henry Mercer
6d1c37ed8f
Fix some tests that should be serial
2026-03-04 18:02:17 +01:00
Henry Mercer
759b5db350
Merge branch 'main' into henrymercer/breakdown-overlay-disabled-reason
...
# Conflicts:
# src/config-utils.test.ts
2026-03-04 17:54:35 +01:00
Henry Mercer
60a0e2bf96
Update method naming and JSDoc
2026-03-04 17:50:30 +01:00
Henry Mercer
7449e3294d
Rename to EnabledOverlayConfig
2026-03-04 17:38:56 +01:00
Henry Mercer
4cd47adfe1
Address review comments
2026-03-04 17:38:24 +01:00
Henry Mercer
5fa8dad095
Use Results for enablement return types
2026-03-04 17:36:42 +01:00
Henry Mercer
6a77217a46
Add disabled by env var disablement reason
2026-03-04 17:27:44 +01:00
Henry Mercer
b6dfacb528
Merge pull request #3542 from github/henrymercer/parallel-unit-tests
...
Run some unit tests in parallel
2026-03-04 16:07:10 +00:00
Henry Mercer
6123416ead
Merge remote-tracking branch 'origin/main' into henrymercer/parallel-unit-tests
2026-03-04 15:12:33 +01:00
Henry Mercer
a6594f96a3
Merge pull request #3540 from github/henrymercer/stub-actions-vars
...
Testing: Provide default value for more environment variables in `setupActionsVars`
2026-03-04 13:27:40 +00:00
Henry Mercer
be20394012
Rename to usesDefaultQueriesOnly
2026-03-04 13:56:56 +01:00
Henry Mercer
d1c255c293
Update NonDefaultQueries documentation
2026-03-04 13:55:29 +01:00
Henry Mercer
b371ccd8ea
Refactor getOverlayDatabaseMode and add new disablement reason
2026-03-04 13:53:12 +01:00
Henry Mercer
71d7981285
Address review comments
2026-03-04 13:27:59 +01:00
Henry Mercer
e9e9733cb5
Merge branch 'main' into henrymercer/stub-actions-vars
2026-03-04 13:26:43 +01:00
Henry Mercer
8e17ec94b4
Merge branch 'main' into henrymercer/parallel-unit-tests
2026-03-04 13:25:01 +01:00
Henry Mercer
aae94187c1
Fix test name
2026-03-04 13:09:10 +01:00
Henry Mercer
36148cccb9
Run more actions util tests serially
2026-03-04 13:08:37 +01:00
Henry Mercer
a5b959e10d
Merge pull request #3537 from github/henrymercer/overlay-status-record-job
...
Record the job that published an overlay status
2026-03-04 11:49:52 +00:00
Michael B. Gale
d1ac77f26d
Merge pull request #3527 from github/mbg/start-proxy/remove-unused
...
Remove unused registry types from `LANGUAGE_TO_REGISTRY_TYPE`
2026-03-04 11:48:08 +00:00
Henry Mercer
675af55c60
Run some unit tests in parallel
2026-03-04 12:40:22 +01:00
Michael B. Gale
2b6077152e
Add support for additional, validation jobs
2026-03-04 11:37:17 +00:00
Michael B. Gale
95fc2f11fb
Move yq setup code into getSetupSteps
2026-03-04 11:37:17 +00:00
Michael B. Gale
92ab799fe0
Refactor job generation into generateJob
2026-03-04 11:37:17 +00:00
Michael B. Gale
369d73b98f
Refactor matrix generation into its own function
2026-03-04 11:37:16 +00:00
Michael B. Gale
97a3705788
Organise language-specific setup information
2026-03-04 11:37:16 +00:00
Henry Mercer
281b265245
Address review comments
2026-03-04 12:16:54 +01:00
Henry Mercer
335f08ccc6
Merge pull request #3539 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2026-03-04 11:01:18 +00:00
github-actions[bot]
4593dc2f8f
Update supported GitHub Enterprise Server versions
2026-03-04 00:23:29 +00:00
Henry Mercer
d4f1b14259
Use new setupActionsVars pattern
2026-03-03 19:24:18 +01:00
Henry Mercer
8a884bdb36
Extend setupActionsVars
2026-03-03 19:09:57 +01:00
Henry Mercer
129d771399
Add check run ID
2026-03-03 19:04:04 +01:00
Henry Mercer
776fd85f8c
Address review comments
2026-03-03 18:48:23 +01:00
Henry Mercer
f654d61146
Add JSDoc
2026-03-03 17:24:47 +01:00
Henry Mercer
eddf33655d
Sort OverlayDisabledReason enum
2026-03-03 17:22:36 +01:00
Henry Mercer
9f77ff18bb
Make "insufficient resources" reason more specific
2026-03-03 17:21:59 +01:00
Henry Mercer
0158d05946
Make "feature not enabled" reason more specific
2026-03-03 17:17:07 +01:00
Henry Mercer
a05f541a6e
Record the job that published an overlay status
...
This makes it easier to find the job that produced the status.
2026-03-03 16:56:18 +01:00
Michael B. Gale
5db3a9e947
Extract JobSpecification type from Specification
2026-03-03 14:15:45 +00:00
Michael B. Gale
40f0fa95c4
Merge pull request #3535 from github/mbg/ci/no-skip-overlay
...
Disable overlay status check for CS config test workflow
2026-03-03 12:26:50 +00:00
Michael B. Gale
9bf973324f
Merge pull request #3528 from github/mbg/refactor/sarif
...
Refactor SARIF-related types and functions into a separate module
2026-03-03 12:10:30 +00:00
Michael B. Gale
1175fd9b5d
Add some docs to some newer overlay Features
...
To make it easier to see what they do at a glance
2026-03-03 12:06:46 +00:00
Michael B. Gale
1faad73c9a
Disable resource checks as well
2026-03-03 12:06:46 +00:00
Michael B. Gale
6b246e4709
Disable overlay status check for CS config test workflow
2026-03-03 11:53:33 +00:00
Michael B. Gale
0a5b95cdcc
Update pr-checks README
2026-03-03 11:45:18 +00:00
Michael B. Gale
77fc89c78d
Remove python files from pr-checks
2026-03-03 11:42:49 +00:00
Michael B. Gale
bf9bf1c027
Remove python setup from rebuild workflow
2026-03-03 11:41:24 +00:00
Michael B. Gale
24fa947692
Update pr-checks to run new tests
2026-03-03 11:40:54 +00:00
Michael B. Gale
aaed7b75f9
Merge remote-tracking branch 'origin/main' into mbg/ts/sync-back
2026-03-03 11:36:59 +00:00
Michael B. Gale
2a2f4c30a1
Add docs for automationId
2026-03-03 11:35:43 +00:00
Michael B. Gale
6d060bbaa1
Return Partial<Log> from readSarifFile
...
Our previous definition had `tools` as a mandatory field, so this
also makes some changes to deal with the case where that may
be `undefined` by treating it as equivalent to `[]`.
2026-03-03 11:34:01 +00:00
Michael B. Gale
28b449d8c7
Improve version handling in combineSarifFiles
2026-03-03 11:18:47 +00:00
Michael B. Gale
1721ce7afd
Address minor review comments
2026-03-03 11:05:37 +00:00
Michael B. Gale
ff2daa0aba
Merge pull request #3526 from github/mbg/pr-checks/ts
...
Convert `sync.py` to TypeScript
2026-03-03 10:49:56 +00:00
Michael B. Gale
b43d146e37
Do not alias types
2026-03-02 20:47:19 +00:00
Michael B. Gale
66e08d2b3f
Make entries in new mapping mandatory
2026-03-02 18:08:53 +00:00
Michael B. Gale
9a31859f78
Use @types/sarif
2026-03-02 18:04:11 +00:00
Michael B. Gale
ae9cb02459
Add dependency on @types/sarif
2026-03-02 17:41:41 +00:00
Michael B. Gale
c0b22b827b
Replace filename in CONTRIBUTING.md
2026-03-02 15:40:32 +00:00
Michael B. Gale
d09af9d5b8
Type workflow input names
2026-03-02 15:39:46 +00:00
Michael B. Gale
e7ec96cee0
Remove isTruthy: consistently use booleans in templates
2026-03-02 15:34:11 +00:00
Michael B. Gale
41d5a06bfd
Address basic style comments
2026-03-02 15:32:30 +00:00
Michael B. Gale
4ca06280ba
Merge remote-tracking branch 'origin/main' into mbg/pr-checks/ts
2026-03-02 14:03:56 +00:00
Henry Mercer
b895512248
Merge pull request #3532 from github/mergeback/v4.32.5-to-main-c793b717
...
Mergeback v4.32.5 refs/heads/releases/v4 into main
2026-03-02 11:59:49 +00:00
github-actions[bot]
6059d3ceb5
Rebuild
2026-03-02 11:35:32 +00:00
github-actions[bot]
bab3951531
Merge remote-tracking branch 'origin/main' into mergeback/v4.32.5-to-main-c793b717
2026-03-02 11:34:42 +00:00
github-actions[bot]
93ec0f487d
Update changelog and version after v4.32.5
2026-03-02 11:13:35 +00:00
Henry Mercer
c793b717bc
Merge pull request #3523 from github/update-v4.32.5-ca42bf226
...
Merge main into releases/v4
2026-03-02 11:11:20 +00:00
Henry Mercer
06cd615ad8
Soften language re overlay failures
2026-03-02 11:48:45 +01:00
Henry Mercer
f5516c6630
Improve changelog
2026-03-02 11:45:27 +01:00
Henry Mercer
97519e197e
Update release date
2026-03-02 10:03:22 +00:00
Michael B. Gale
a6892dcba5
Use sync_back.ts in rebuild workflow
2026-03-01 16:04:35 +00:00
Michael B. Gale
8eb0202e9d
Port tests
2026-03-01 16:04:35 +00:00
Michael B. Gale
dd779fa7d3
Add updateTemplateFiles
2026-03-01 16:04:35 +00:00
Michael B. Gale
f05cfae018
Add updateSyncTs
2026-03-01 16:04:35 +00:00
Michael B. Gale
e1b83ccb74
Add scanGeneratedWorkflows
2026-03-01 16:04:35 +00:00
Michael B. Gale
6a6bd778b6
Add initial sync_back.ts script
2026-03-01 16:04:35 +00:00
Michael B. Gale
f0f92a1dc8
Remove sync.py
2026-03-01 16:03:47 +00:00
Michael B. Gale
e931a2475a
Replace remaining uses of sync.py
2026-03-01 16:03:35 +00:00
Michael B. Gale
8bfaf96434
Run npm ci in actions
2026-03-01 15:20:30 +00:00
Michael B. Gale
8a1cd7656d
Put change behind a FF
2026-03-01 15:07:47 +00:00
Michael B. Gale
3b16d31abc
Delete unused fixInvalidNotifications function
2026-03-01 14:26:41 +00:00
Michael B. Gale
40aec383a1
Move more SARIF helpers to sarif module
2026-03-01 14:22:49 +00:00
Michael B. Gale
2fce45b8e6
Add wrapper around JSON.parse to sarif module
2026-03-01 14:10:25 +00:00
Michael B. Gale
d7cfd19fb8
Move SARIF types out of util.ts
2026-03-01 13:42:46 +00:00
Michael B. Gale
68d73442fa
Remove unused registry types from LANGUAGE_TO_REGISTRY_TYPE
2026-02-28 23:24:41 +00:00
Michael B. Gale
f91cab1409
Adjust quotes and re-generate workflows
2026-02-28 18:13:05 +00:00
Michael B. Gale
5876a93a5f
Switch sync.sh script to only use sync.ts
2026-02-28 17:58:00 +00:00
Michael B. Gale
0ea8490473
Switch from js-yaml to yaml for better output formatting
2026-02-28 17:55:41 +00:00
Michael B. Gale
a85af80f34
Generate and write collections
2026-02-28 16:47:22 +00:00
Michael B. Gale
47671ab7aa
Track collections
2026-02-28 16:46:47 +00:00
Michael B. Gale
96e6b655c1
Add tool-specific setup steps
2026-02-28 16:32:32 +00:00
Michael B. Gale
57c7bc6885
Add analysisKinds
2026-02-28 16:32:32 +00:00
Michael B. Gale
d52917b510
Add useAllPlatformBundle
2026-02-28 16:32:32 +00:00
Michael B. Gale
b948e562f4
Add basic job steps
2026-02-28 16:32:31 +00:00
Michael B. Gale
c889588a2c
Add env, container, and services
2026-02-28 16:32:31 +00:00
Michael B. Gale
b77ebbe4d8
Add CODEQL_ACTION_TEST_MODE
2026-02-28 16:32:31 +00:00
Michael B. Gale
9a0fe9e006
Add permissions
2026-02-28 16:32:31 +00:00
Michael B. Gale
dd78add36d
Add matrix to job
2026-02-28 16:32:31 +00:00
Michael B. Gale
e62a268a73
Add job construction
2026-02-28 16:32:31 +00:00
Michael B. Gale
63b4776d64
Add matrix construction
2026-02-28 16:32:30 +00:00
Michael B. Gale
6932b1cda2
Add concurrency settings
2026-02-28 16:32:30 +00:00
Michael B. Gale
40aefb0faf
Add basic workflow construction
2026-02-28 16:32:30 +00:00
Michael B. Gale
efe64e03d9
Add isTruthy helper
2026-02-28 16:32:30 +00:00
Michael B. Gale
898d46e783
Strip trailing whitespace in output
2026-02-28 16:32:30 +00:00
Michael B. Gale
04c1e601ab
Add defaultTestVersions constant
2026-02-28 16:18:04 +00:00
Michael B. Gale
2f77cd04d4
Add specification types
2026-02-28 16:06:14 +00:00
Michael B. Gale
c7e378f003
Scaffold project for sync.ts script
2026-02-28 15:58:47 +00:00
Michael B. Gale
f3663cdc32
Fix typos in comments
2026-02-28 15:18:25 +00:00
Henry Mercer
0ec47d036c
Merge pull request #3524 from github/henrymercer/checks-use-setup-codeql
...
CI: Update CodeQL Action test to use `setup-codeql`
2026-02-27 17:02:44 +00:00
Henry Mercer
59245fd159
Add missing permissions to access feature flags
2026-02-27 17:39:20 +01:00
Henry Mercer
05259a1d08
Add more changelog notes
2026-02-27 17:24:17 +01:00
Henry Mercer
389c8322d5
CI: Update CodeQL Action test to use setup-codeql
2026-02-27 17:06:16 +01:00
Henry Mercer
01ee2f785a
Add changelog notes
2026-02-27 16:09:38 +01:00
github-actions[bot]
c72d9a4933
Update changelog for v4.32.5
2026-02-27 14:37:26 +00:00
Henry Mercer
ca42bf226a
Merge pull request #3522 from github/henrymercer/update-supported-versions-table
...
Update supported Action / Bundle / GHES version table
2026-02-27 13:57:17 +00:00
Henry Mercer
6704d80ac6
Merge pull request #3520 from github/dependabot/npm_and_yarn/fast-xml-parser-5.4.1
...
Bump fast-xml-parser from 5.3.6 to 5.4.1
2026-02-27 13:57:12 +00:00
Henry Mercer
76348c0f12
Merge pull request #3521 from github/dependabot/npm_and_yarn/minimatch-3.1.5
...
Bump minimatch from 3.1.3 to 3.1.5
2026-02-27 13:57:06 +00:00
Henry Mercer
3a42a998ef
Update supported Action / Bundle / GHES version table
2026-02-27 13:37:42 +00:00
Henry Mercer
8ab0431fc3
Merge pull request #3514 from github/dependabot/npm_and_yarn/globals-17.3.0
...
Bump globals from 16.5.0 to 17.3.0
2026-02-27 13:28:04 +00:00
Henry Mercer
2c92579346
Merge pull request #3513 from github/dependabot/npm_and_yarn/npm-minor-e1092f1102
...
Bump eslint-plugin-jsdoc from 62.5.0 to 62.6.0 in the npm-minor group
2026-02-27 13:27:19 +00:00
github-actions[bot]
2475286230
Rebuild
2026-02-27 13:23:45 +00:00
github-actions[bot]
236fbf7645
Rebuild
2026-02-27 13:23:30 +00:00
dependabot[bot]
29181f28d5
Bump minimatch from 3.1.3 to 3.1.5
...
Bumps [minimatch](https://github.com/isaacs/minimatch ) from 3.1.3 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.3...v3.1.5 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 3.1.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-27 13:21:47 +00:00
dependabot[bot]
a0735d7c2a
Bump fast-xml-parser from 5.3.6 to 5.4.1
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.6 to 5.4.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.6...v5.4.1 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.4.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-27 13:21:34 +00:00
Henry Mercer
b35e0349aa
Merge pull request #3518 from github/mbg/ci/merge-queue-codeql
...
Disable CodeQL upload for merge queue and exclude PR size workflow from required checks
2026-02-27 12:56:04 +00:00
Michael B. Gale
e995ba3522
Add more tests/assertions
2026-02-27 12:52:54 +00:00
Michael B. Gale
1e7e52a330
Add tests where upload should get skipped
2026-02-27 12:40:04 +00:00
Michael B. Gale
383b86ddcb
Refactor some test setup code into mockRiskAssessmentEnv
2026-02-27 12:27:32 +00:00
Michael B. Gale
4406eba03e
Skip uploads in merge queue
2026-02-27 12:14:56 +00:00
Henry Mercer
1b897f3911
Fix conditions in code scanning config checks
...
DIff-informed analysis isn't enabled in the merge queue.
2026-02-27 12:10:38 +00:00
Henry Mercer
adf58cf166
Merge pull request #3515 from github/henrymercer/drop-ram-limit
...
Skip overlay memory check for CodeQL 2.24.3 and later
2026-02-27 11:17:11 +00:00
Michael B. Gale
ca32b84657
Ensure correct failed SARIF file names for CSRA
2026-02-26 19:56:07 +00:00
Michael B. Gale
ce97dfe405
Sanitise artifact name
2026-02-26 19:47:55 +00:00
Michael B. Gale
003044eb84
Add test
2026-02-26 19:18:32 +00:00
Michael B. Gale
5b9d1f4fdf
Simplify prepareFailedSarif for risk assessments
2026-02-26 19:18:29 +00:00
Michael B. Gale
f265dd9392
Separate generateFailedSarif out of prepareFailedSarif
2026-02-26 18:44:50 +00:00
Michael B. Gale
44b66a8064
Upload failed SARIF as artifact for risk assessments
2026-02-26 18:40:00 +00:00
Michael B. Gale
b7d3fb98df
Exclude "Label PR with size" from required checks
2026-02-26 18:25:26 +00:00
Michael B. Gale
4e8e79431d
Run CodeQL with linked tools for merge queue
2026-02-26 18:25:26 +00:00
Michael B. Gale
60ca40ecd4
Refactor prepareFailedSarif out of maybeUploadFailedSarif
2026-02-26 18:07:00 +00:00
Michael B. Gale
56d1ccc87a
Change skipped reason message
2026-02-26 17:51:06 +00:00
Michael B. Gale
e9ce32d807
Change order of checks in tryUploadSarifIfRunFailed
2026-02-26 17:51:06 +00:00
Michael B. Gale
0f3e632580
Rename secondary run to uploadFailureInfo
2026-02-26 17:47:32 +00:00
github-actions[bot]
52c2a032f3
Rebuild
2026-02-26 17:22:24 +00:00
Henry Mercer
ba1288cb3c
Merge branch 'main' into dependabot/npm_and_yarn/globals-17.3.0
2026-02-26 17:20:10 +00:00
Henry Mercer
29765a3c71
Skip overlay memory check for CodeQL 2.24.3 and later
2026-02-26 16:53:26 +00:00
github-actions[bot]
068e80c14c
Rebuild
2026-02-26 16:42:43 +00:00
Michael B. Gale
154969e08b
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-e1092f1102
2026-02-26 16:40:19 +00:00
Michael B. Gale
b0ed4dedcb
Merge pull request #3511 from github/henrymercer/merge-queue
...
Add `merge_group` trigger to required checks to prepare for merge queue
2026-02-26 16:33:14 +00:00
Michael B. Gale
3c83f578ed
Merge pull request #3516 from github/mbg/start-proxy/reduce-connection-check-severity
2026-02-26 16:32:00 +00:00
Henry Mercer
20f148b36e
Merge pull request #3507 from github/henrymercer/overlay-repo-property
...
Add a repository property for disabling overlay
2026-02-26 16:21:03 +00:00
Henry Mercer
4068616de4
Merge branch 'main' into henrymercer/overlay-repo-property
2026-02-26 15:27:25 +00:00
Michael B. Gale
0d5f70631a
Merge branch 'main' into mbg/start-proxy/reduce-connection-check-severity
2026-02-26 15:16:23 +00:00
Michael B. Gale
ae14a1f513
Merge branch 'main' into henrymercer/merge-queue
2026-02-26 15:11:41 +00:00
Michael B. Gale
a577f702b9
Merge pull request #3512 from github/mbg/start-proxy/use-default-cli
...
Use `getDefaultCliVersion` for `start-proxy`
2026-02-26 15:11:18 +00:00
Michael B. Gale
bce0deb953
Fix log message / returned version
2026-02-26 13:55:47 +00:00
Michael B. Gale
db33d20bf4
Put change behind a FF
2026-02-26 13:10:52 +00:00
Michael B. Gale
3c911485ed
Address Copilot's review comments
2026-02-26 13:07:03 +00:00
Michael B. Gale
1ec5b701fc
Reduce log levels for registry connection checks
2026-02-26 11:53:26 +00:00
dependabot[bot]
9bdf640d99
Bump globals from 16.5.0 to 17.3.0
...
Bumps [globals](https://github.com/sindresorhus/globals ) from 16.5.0 to 17.3.0.
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v16.5.0...v17.3.0 )
---
updated-dependencies:
- dependency-name: globals
dependency-version: 17.3.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 17:53:31 +00:00
dependabot[bot]
b2beb85441
Bump eslint-plugin-jsdoc from 62.5.0 to 62.6.0 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `eslint-plugin-jsdoc` from 62.5.0 to 62.6.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.5.0...v62.6.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.6.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 17:53:10 +00:00
Michael B. Gale
f657c4e1eb
Use getDefaultCliVersion for start-proxy
2026-02-25 17:43:15 +00:00
Henry Mercer
f379c46d49
Address review comments
2026-02-25 15:26:48 +00:00
Henry Mercer
8105503f1a
Add merge_group trigger to required checks to prepare for merge queue
2026-02-25 15:12:37 +00:00
Henry Mercer
056b0912cf
Merge branch 'main' into henrymercer/overlay-repo-property
2026-02-25 14:43:34 +00:00
Henry Mercer
445a2a9bb2
Record overlay disablement reason
2026-02-25 14:36:03 +00:00
Henry Mercer
182427800c
Add disabled reason
2026-02-25 14:22:13 +00:00
Henry Mercer
c0fc915677
Merge pull request #3509 from github/dependabot/npm_and_yarn/multi-871638c4a1
...
Bump minimatch
2026-02-25 13:43:36 +00:00
Michael B. Gale
18898a6dd3
Merge pull request #3504 from github/mbg/ff/remove-ImprovedProxyCertificates
...
Remove FF gate for improved CA generation
2026-02-25 13:25:57 +00:00
Henry Mercer
70db156dcb
Add diagnostic when overlay disabled by repo property
2026-02-25 11:48:10 +00:00
Henry Mercer
9c61a2ddf4
Reorganize properties file
2026-02-25 11:35:34 +00:00
github-actions[bot]
123b3011fa
Rebuild
2026-02-25 00:19:51 +00:00
dependabot[bot]
0aafb58a10
Bump minimatch
...
Bumps and [minimatch](https://github.com/isaacs/minimatch ). These dependencies needed to be updated together.
Updates `minimatch` from 10.1.1 to 10.2.2
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 5.1.6 to 5.1.7
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 3.1.2 to 3.1.3
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
Updates `minimatch` from 9.0.5 to 9.0.6
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v10.1.1...v10.2.2 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 10.2.2
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 5.1.7
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 3.1.3
dependency-type: indirect
- dependency-name: minimatch
dependency-version: 9.0.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-25 00:17:44 +00:00
Henry Mercer
16adc4e672
Merge pull request #3506 from github/henrymercer/result-better-inference
...
Improve type inference of `Result<T, E>`
2026-02-24 20:05:34 +00:00
Henry Mercer
2808ca726e
Improve validation and address review comments
2026-02-24 19:56:43 +00:00
Henry Mercer
2a607fea25
Update JSDoc
...
Co-authored-by: Michael B. Gale <mbg@github.com >
2026-02-24 19:28:27 +00:00
Henry Mercer
ed39a1ea5c
Add repository property for disabling overlay
2026-02-24 18:58:08 +00:00
Henry Mercer
7ea93ee2e1
Add support for boolean repository properties
2026-02-24 18:48:32 +00:00
Henry Mercer
e51b6a9a52
Update names in tests
2026-02-24 17:55:29 +00:00
Henry Mercer
160d27baf0
Improve type inference of Result<T, E>
2026-02-24 17:41:30 +00:00
Michael B. Gale
28737ec792
Merge pull request #3503 from github/mbg/ff/make-connection-checks-default
...
Remove FF gate for connection checks
2026-02-24 17:26:42 +00:00
Henry Mercer
e5f9d3b55e
Merge pull request #3487 from github/henrymercer/overlay-status
...
Cache first failure building an overlay base DB to avoid repeated failures
2026-02-24 17:19:19 +00:00
Henry Mercer
dc00a6f08f
Improve error message
2026-02-24 16:47:42 +00:00
Henry Mercer
ab56c02e0c
Merge pull request #3497 from github/henrymercer/eslint-v9
...
Update eslint to v9
2026-02-24 14:38:34 +00:00
Michael B. Gale
83c236af2b
Remove FF gate for improved CA generation
2026-02-24 11:25:57 +00:00
Michael B. Gale
25bde03dfb
Remove FF gate for connection checks
2026-02-24 11:18:51 +00:00
Michael B. Gale
c4dca28336
Merge pull request #3502 from github/mbg/remove-ccr
...
Remove all CCR-specific code and tests
2026-02-24 10:58:49 +00:00
Michael B. Gale
1aad2787ec
Update PR template
2026-02-24 10:36:28 +00:00
Michael B. Gale
b6cf67a711
Remove CCR e2e check
2026-02-24 10:34:09 +00:00
Michael B. Gale
f59338d600
Remove isCCR
2026-02-24 10:33:23 +00:00
Henry Mercer
2a07b6e3c7
Merge branch 'main' into henrymercer/eslint-v9
2026-02-23 19:01:30 +00:00
Henry Mercer
fba33f686a
Enable tseslint strict rules
2026-02-23 19:00:06 +00:00
Henry Mercer
48094d2b6e
Explicitly include eslint recommended rules
2026-02-23 18:43:10 +00:00
Michael B. Gale
cb4e075f11
Merge pull request #3501 from github/mbg/ci/dont-label-merged
2026-02-23 15:41:07 +00:00
Henry Mercer
1847416575
Merge pull request #3498 from github/henrymercer/overlay-resource-checks-v2
...
Add feature flag for more lenient overlay resource checks
2026-02-23 15:22:02 +00:00
Michael B. Gale
11dd746d70
Don't run label-pr-size once a PR has been merged
2026-02-23 15:09:13 +00:00
Michael B. Gale
a754a57c21
Merge pull request #3500 from github/mbg/fixup/version-pinning
...
Minor improvements to "Keeping the CodeQL Action up to date" section
2026-02-23 14:19:30 +00:00
Michael B. Gale
466da5ec2d
Slight wording change
2026-02-23 12:00:58 +00:00
Michael B. Gale
0a9b98b511
Highlight that this for advanced setups
2026-02-23 11:59:08 +00:00
Michael B. Gale
bce7dc4616
v3 => v4
2026-02-23 11:58:25 +00:00
Michael B. Gale
b13ab62bc0
Remove extra blank line
2026-02-23 11:57:23 +00:00
Sam Robson
4ea06e96f5
Merge pull request #3499 from github/sam-robson/document-version-pinning-risk
...
docs: guidance on keeping the CodeQL Action up to date
2026-02-23 10:34:02 +00:00
Sam Robson
c9223eb0a0
Merge branch 'main' into sam-robson/document-version-pinning-risk
2026-02-23 10:05:57 +00:00
Sam Robson
f0767c48a1
docs: risks of pinning
2026-02-20 20:15:14 +00:00
Henry Mercer
4e71011f44
Add feature flag for more lenient overlay resource checks
2026-02-20 18:26:14 +00:00
Henry Mercer
710e294578
Merge pull request #3489 from github/dependabot/npm_and_yarn/npm-minor-37a5b5ae66
...
Bump the npm-minor group with 6 updates
2026-02-20 17:12:00 +00:00
Henry Mercer
b948539dd4
Use import-x/no-cycle
2026-02-20 16:34:03 +00:00
Henry Mercer
c54531587d
Update eslint to v9
2026-02-20 15:57:26 +00:00
Michael B. Gale
559d85d1fa
Merge pull request #3477 from github/mbg/features/offline-features
2026-02-20 15:36:07 +00:00
Michael B. Gale
8e010557a9
Merge pull request #3495 from github/mergeback/v4.32.4-to-main-89a39a4e
2026-02-20 15:02:14 +00:00
github-actions[bot]
37d6d1ca27
Rebuild
2026-02-20 14:32:21 +00:00
github-actions[bot]
68b53dc641
Update changelog and version after v4.32.4
2026-02-20 14:17:35 +00:00
Michael B. Gale
89a39a4e59
Merge pull request #3494 from github/update-v4.32.4-39ba80c47
2026-02-20 14:15:31 +00:00
Michael B. Gale
e5d84c885c
Apply remaining review suggestions
2026-02-20 13:54:55 +00:00
Michael B. Gale
0c202097b5
Apply suggestions from code review
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-20 13:51:55 +00:00
Michael B. Gale
314172e5a1
Fix typo
2026-02-20 13:11:54 +00:00
Michael B. Gale
cdda72d36b
Add changelog entries
2026-02-20 13:07:14 +00:00
github-actions[bot]
cfda84cc55
Update changelog for v4.32.4
2026-02-20 12:42:43 +00:00
Michael B. Gale
39ba80c475
Merge pull request #3493 from github/update-bundle/codeql-bundle-v2.24.2
...
Update default bundle to 2.24.2
2026-02-20 11:01:00 +00:00
github-actions[bot]
00150dad95
Add changelog note
2026-02-20 10:44:41 +00:00
github-actions[bot]
d97dce6561
Update default bundle to codeql-bundle-v2.24.2
2026-02-20 10:44:31 +00:00
Michael B. Gale
50fdbb9ec8
Merge pull request #3492 from github/henrymercer/new-repository-properties-ff
...
Use new feature flag for repository properties
2026-02-20 10:43:26 +00:00
Henry Mercer
f7905e8415
Use new feature flag for repository properties
2026-02-19 18:30:50 +00:00
Henry Mercer
4191f52110
Address review comments
2026-02-19 17:57:08 +00:00
github-actions[bot]
79a913656c
Rebuild
2026-02-18 17:55:38 +00:00
dependabot[bot]
167b47e60c
Bump the npm-minor group with 6 updates
...
Bumps the npm-minor group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [semver](https://github.com/npm/node-semver ) | `7.7.3` | `7.7.4` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.54.0` | `8.55.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.54.0` | `8.56.0` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.2` | `0.27.3` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.5.0` | `62.5.4` |
| [nock](https://github.com/nock/nock ) | `14.0.10` | `14.0.11` |
Updates `semver` from 7.7.3 to 7.7.4
- [Release notes](https://github.com/npm/node-semver/releases )
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md )
- [Commits](https://github.com/npm/node-semver/compare/v7.7.3...v7.7.4 )
Updates `@typescript-eslint/eslint-plugin` from 8.54.0 to 8.55.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.55.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/parser )
Updates `esbuild` from 0.27.2 to 0.27.3
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.2...v0.27.3 )
Updates `eslint-plugin-jsdoc` from 62.5.0 to 62.5.4
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.5.0...v62.5.4 )
Updates `nock` from 14.0.10 to 14.0.11
- [Release notes](https://github.com/nock/nock/releases )
- [Changelog](https://github.com/nock/nock/blob/main/CHANGELOG.md )
- [Commits](https://github.com/nock/nock/compare/v14.0.10...v14.0.11 )
---
updated-dependencies:
- dependency-name: semver
dependency-version: 7.7.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.55.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.56.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.5.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: nock
dependency-version: 14.0.11
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 17:53:34 +00:00
Óscar San José
5e7a52feb2
Merge pull request #3488 from github/dependabot/npm_and_yarn/fast-xml-parser-5.3.6
...
Bump fast-xml-parser from 5.3.4 to 5.3.6
2026-02-18 15:41:31 +01:00
github-actions[bot]
76cf404c99
Rebuild
2026-02-18 05:01:36 +00:00
dependabot[bot]
7407d38386
Bump fast-xml-parser from 5.3.4 to 5.3.6
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.4 to 5.3.6.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.4...v5.3.6 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 04:59:37 +00:00
Michael B. Gale
015d8c7cbc
Merge pull request #3486 from github/mbg/start-proxy/java-env-checks
...
Log information about the runner which may affect the private registry proxy
2026-02-17 20:48:41 +00:00
Michael B. Gale
09bd46dda5
Fix typos in comments
2026-02-17 17:18:09 +00:00
Michael B. Gale
b927a69f96
Merge remote-tracking branch 'origin/main' into mbg/features/offline-features
2026-02-17 17:14:08 +00:00
Michael B. Gale
61f7dd3d0d
Fix checkExpectedLogMessages not asserting anything on success
2026-02-17 16:49:01 +00:00
Michael B. Gale
64300e453b
Merge branch 'main' into mbg/start-proxy/java-env-checks
2026-02-17 16:49:01 +00:00
Michael B. Gale
906dd890a5
Run java to show computed settings
2026-02-17 16:49:00 +00:00
Henry Mercer
898ae16413
Improve log message
2026-02-17 15:55:15 +00:00
Henry Mercer
fa56ea8dc0
Extract status file path helper
2026-02-17 15:55:13 +00:00
Henry Mercer
657f337cd1
Add tests for shouldSkipOverlayAnalysis
2026-02-17 15:55:05 +00:00
Henry Mercer
05d4e25296
Avoid mutating languages array in overlay status functions
...
Use [...languages].sort() instead of languages.sort() to avoid
mutating the caller's array as a side effect.
2026-02-17 15:55:05 +00:00
Henry Mercer
5c583bbb19
Include diagnostics in bundle
2026-02-17 15:55:02 +00:00
Henry Mercer
554b93127b
More error message improvements
2026-02-17 15:55:01 +00:00
Henry Mercer
3dd1275368
Improve error messages
2026-02-17 15:55:01 +00:00
Henry Mercer
d24014a749
Tweak diagnostic message
2026-02-17 15:55:00 +00:00
Henry Mercer
cc0dce044b
Improve diagnostic message wording
2026-02-17 15:55:00 +00:00
Henry Mercer
ef58c00dfe
Only store overlay status if analysis failed
2026-02-17 15:54:59 +00:00
Henry Mercer
7b7a951e08
Add status page diagnostic when overlay skipped
2026-02-17 15:54:58 +00:00
Henry Mercer
0c47ae1c18
Sort doc URLs
2026-02-17 15:54:58 +00:00
Henry Mercer
6c405c2562
Be more explicit about attempt to build overlay DB
2026-02-17 15:54:57 +00:00
Henry Mercer
827bba691f
Introduce feature flags for saving and checking status
2026-02-17 15:54:57 +00:00
Henry Mercer
96961e0ee3
Save overlay status to Actions cache
2026-02-17 15:54:53 +00:00
Henry Mercer
ebad062f08
Skip overlay analysis based on cached status
2026-02-17 15:54:31 +00:00
Henry Mercer
e275d63e1d
Generalise status to multiple languages
2026-02-17 15:54:06 +00:00
Henry Mercer
69c2819972
Add save and restore methods
2026-02-17 15:54:06 +00:00
Henry Mercer
d28d9967fe
Compute cache key for overlay language status
2026-02-17 15:54:06 +00:00
Henry Mercer
d1bdc0ea05
Create separate directory for overlay source code
2026-02-17 15:54:03 +00:00
Michael B. Gale
b1b1e44da9
Merge pull request #3474 from github/mbg/risk-assessment-analysis
...
Add `csra` analysis kind
2026-02-17 15:39:05 +00:00
Michael B. Gale
46473e05b7
Add more interesting Java properties
2026-02-17 15:23:21 +00:00
Michael B. Gale
32ab108bfd
Move interesting JRE properties out of checkJdkSettings
2026-02-17 15:22:43 +00:00
Michael B. Gale
971592501c
Consistently use "\n" to split lines, then trim extra characters if needed
2026-02-17 14:58:40 +00:00
Michael B. Gale
2abec3f0c3
Replace most occurrences of CSRA
2026-02-17 14:55:31 +00:00
Michael B. Gale
6d55dfff02
Reword error message
2026-02-17 14:49:34 +00:00
Michael B. Gale
5c96b6e3db
Add JSDoc comments to upload-lib types
2026-02-17 14:40:16 +00:00
Michael B. Gale
44a4bea367
Fixup: add missing .env
2026-02-17 13:54:22 +00:00
Michael B. Gale
11c6c18818
Only run when debugging or test mode is enabled
2026-02-17 13:44:18 +00:00
Michael B. Gale
99fcc7b2a1
Check whether value is a URL in checkEnvVar and clear credentials
...
Note also that we run this after `getCredentials` which already instructs Actions to mask credentials that we know about in logs
2026-02-17 13:42:51 +00:00
Michael B. Gale
c1d6ee5477
Fix typos
2026-02-17 13:31:01 +00:00
Michael B. Gale
ef9cfd91a8
Clear GHA JAVA_HOME_* env vars for discoverActionsJdks test
2026-02-17 13:28:56 +00:00
Michael B. Gale
4250b466b2
Wrap checkProxyEnvironment call in try/catch for good measure
2026-02-17 13:17:49 +00:00
Michael B. Gale
a3d7d36aa6
Find likely JDK locations and check configurations
2026-02-17 13:17:48 +00:00
Michael B. Gale
33e2dff082
Log information about proxy-related environment variables
2026-02-17 12:38:30 +00:00
Michael B. Gale
bff89dcba4
Add enum for Java-related env var names
2026-02-17 11:37:25 +00:00
Michael B. Gale
d6ea6709b9
Remove unnecessary check
2026-02-17 10:56:29 +00:00
Michael B. Gale
f315d82bd7
Rename csra to risk-assessment
2026-02-17 10:52:04 +00:00
Michael B. Gale
ebce69a4b7
Merge pull request #3485 from github/mbg/java/network-debugging
...
Add feature to enable Java network debugging
2026-02-17 10:19:54 +00:00
Michael B. Gale
ab2580041c
Merge remote-tracking branch 'origin/main' into mbg/features/offline-features
2026-02-17 09:54:34 +00:00
Michael B. Gale
d1689c9307
Use all
2026-02-17 09:53:49 +00:00
Michael B. Gale
147d1495e4
Merge pull request #3484 from github/mbg/cli/force-nightly
...
Add feature for forcing the `nightly` bundle in `dynamic` workflows
2026-02-16 22:37:31 +00:00
Michael B. Gale
3e37216660
Merge branch 'main' into mbg/java/network-debugging
2026-02-16 22:02:36 +00:00
Michael B. Gale
ad5a6c0147
Merge pull request #3482 from github/mbg/release/author-or-merger
...
Release notes: Use author if they are GitHub staff
2026-02-16 18:21:44 +00:00
Michael B. Gale
aee29a19d7
Merge pull request #3473 from github/mbg/start-proxy/cert-gen
...
Improve proxy certificate generation
2026-02-16 17:19:30 +00:00
Michael B. Gale
ac74c2835a
Use init in new check workflow
2026-02-16 17:15:11 +00:00
Michael B. Gale
f8c75d3f32
Change diagnostic level to note
2026-02-16 17:12:12 +00:00
Michael B. Gale
e315c6fd3b
Add diagnostic when a nightly release is forced
2026-02-16 09:29:32 +00:00
Michael B. Gale
e6a312a771
Allow addNoLanguageDiagnostic to be used without a Config
2026-02-16 09:13:06 +00:00
Michael B. Gale
73f5a29960
Complete JSDoc
2026-02-16 09:07:02 +00:00
Michael B. Gale
8b734d3bc2
Improve variable names and comments
...
Also set default `GITHUB_EVENT_NAME` in `setupActionsVars`
2026-02-16 08:54:19 +00:00
Michael B. Gale
e21e4ca93f
Add debugging options to JAVA_TOOL_OPTIONS when FF is enabled
2026-02-15 18:12:51 +00:00
Michael B. Gale
595ce2dc3e
Add JavaNetworkDebugging feature
2026-02-15 18:04:48 +00:00
Michael B. Gale
a61e3cb9f2
Add integration test
2026-02-15 17:49:10 +00:00
Michael B. Gale
d5f0374a1f
Force nightly bundle when FF is enabled
2026-02-15 17:22:20 +00:00
Michael B. Gale
466a4f00eb
Add unit test for tools: nightly
2026-02-15 17:19:12 +00:00
Michael B. Gale
817d568ca0
Improve docs in setup-codeql
2026-02-15 16:21:03 +00:00
Michael B. Gale
34d43db4c6
Add ForceNightly feature
2026-02-15 16:10:53 +00:00
Michael B. Gale
db834c9e1d
Use OfflineFeatures when !supportsFeatureFlags as well
2026-02-15 16:03:48 +00:00
Michael B. Gale
7af50a43c1
Restore test improvements from previous PR
2026-02-15 15:57:02 +00:00
Michael B. Gale
60dee3dbd3
Log when using OfflineFeatures for CCR
2026-02-15 15:55:03 +00:00
Michael B. Gale
0874cf9f8b
Change FFs not supported log message
2026-02-15 15:51:06 +00:00
Michael B. Gale
bc76ceafaf
Add test to check that OfflineFeatures doesn't use the API client
2026-02-15 15:40:23 +00:00
Michael B. Gale
377300bcda
Add mockCCR helper to testing-utils
2026-02-15 15:40:23 +00:00
Michael B. Gale
ee8360df59
Move FF test utils out of main file
2026-02-15 15:40:23 +00:00
Michael B. Gale
9dcfdf2c9c
Return OfflineFeatures for CCR
2026-02-15 15:40:22 +00:00
Michael B. Gale
2c9bc45d46
Abstract over FeatureEnablement implementations with initFeatures
2026-02-15 15:40:21 +00:00
Michael B. Gale
368f322a09
Add OfflineFeatures class
2026-02-15 15:40:20 +00:00
Michael B. Gale
5283c3ba5a
Move getDefaultCliVersion out of GitHubFeatureFlags
...
It doesn't need to be in there since it doesn't depend on the API itself and call `getDefaultCliVersionFromFlags` directly
2026-02-15 15:40:19 +00:00
Michael B. Gale
ea1a400e13
Revert "Merge pull request #3476 from github/henrymercer/retry-auth-errors"
...
This reverts commit 9658e23e5b , reversing
changes made to 2d6b98c7cf .
2026-02-15 15:39:04 +00:00
Michael B. Gale
248d7971c2
Remove superfluous try/catch
2026-02-15 15:23:38 +00:00
Michael B. Gale
64940fad4a
Use author if they are GitHub staff
2026-02-13 15:10:39 +00:00
Henry Mercer
ef618feace
Merge pull request #3480 from github/mergeback/v4.32.3-to-main-9e907b5e
...
Mergeback v4.32.3 refs/heads/releases/v4 into main
2026-02-13 12:21:19 +00:00
github-actions[bot]
6bddc7956d
Rebuild
2026-02-13 12:01:09 +00:00
github-actions[bot]
01fcdceb89
Update changelog and version after v4.32.3
2026-02-13 11:52:49 +00:00
Henry Mercer
9e907b5e64
Merge pull request #3479 from github/update-v4.32.3-4bf6fa4e2
...
Merge main into releases/v4
2026-02-13 11:50:53 +00:00
github-actions[bot]
1814c9fbfd
Update changelog for v4.32.3
2026-02-13 11:17:52 +00:00
Henry Mercer
4bf6fa4e2d
Merge pull request #3478 from github/mbg/changelog/add-connection-test-entry
...
Add changelog entry for #3466
2026-02-13 11:12:32 +00:00
Henry Mercer
9658e23e5b
Merge pull request #3476 from github/henrymercer/retry-auth-errors
...
Avoid requesting features in CCR
2026-02-13 11:11:50 +00:00
Michael B. Gale
e1933c66bd
Find all missing messages in checkExpectedLogMessages
2026-02-12 23:22:33 +00:00
Michael B. Gale
edf36092cf
Add RecordingLogger that keeps track of groups
2026-02-12 23:21:58 +00:00
Michael B. Gale
15a3d32df0
Extend uploadPayload tests to all analysis kinds
2026-02-12 22:28:27 +00:00
Michael B. Gale
9835994414
CSRA category does not need to be adjusted
2026-02-12 20:16:22 +00:00
Michael B. Gale
0ce6420f8e
Validate CODEQL_ACTION_CSRA_ASSESSMENT_ID value
2026-02-12 20:15:18 +00:00
Michael B. Gale
be75dd92ea
Add changelog entry for #3466
2026-02-12 19:40:23 +00:00
Henry Mercer
05bca54402
Apply suggestion from @Copilot
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-12 17:37:10 +00:00
Michael B. Gale
2d6b98c7cf
Merge pull request #3475 from github/henrymercer/retry-auth-errors
...
Retry API authentication errors since these can be transient
2026-02-12 17:04:05 +00:00
Henry Mercer
876cecb383
Avoid requesting features in CCR
2026-02-12 16:53:19 +00:00
Henry Mercer
43b46a19be
Retry API authentication errors since these can be transient
2026-02-12 16:19:04 +00:00
Michael B. Gale
8ad4b6ec58
Merge pull request #3472 from github/dependabot/github_actions/dot-github/workflows/actions-minor-299c02fd34
...
Bump ruby/setup-ruby from 1.286.0 to 1.288.0 in /.github/workflows in the actions-minor group across 1 directory
2026-02-12 14:00:07 +00:00
Michael B. Gale
4edc7d2e82
Merge pull request #3467 from github/dependabot/npm_and_yarn/npm-minor-5707d09364
...
Bump the npm-minor group with 2 updates
2026-02-12 13:33:11 +00:00
Michael B. Gale
2adcb6464e
Add BasePayload type and derive AssessmentPayload from it
2026-02-12 00:13:22 +00:00
Michael B. Gale
da67096c6f
Change assessment_id to be a number
2026-02-12 00:10:42 +00:00
Michael B. Gale
c48cd247df
Add assessment_id to CSRA payload
2026-02-11 23:56:52 +00:00
Michael B. Gale
0cfcceb4b8
Add transformPayload to AnalysisConfig
2026-02-11 23:56:51 +00:00
Michael B. Gale
cbb92e7ff6
Type the upload payload object
2026-02-11 23:56:51 +00:00
Michael B. Gale
db9346285d
Add csra case to addSarifExtension test
2026-02-11 23:28:38 +00:00
Michael B. Gale
2de76b6faa
Update PR check for csra
2026-02-11 22:46:24 +00:00
Michael B. Gale
6a17f4e258
Update getPrimaryAnalysis* and add test
2026-02-11 22:46:24 +00:00
Michael B. Gale
8cc4d2539b
Remove redundant analysis kind check
2026-02-11 22:14:39 +00:00
Michael B. Gale
406bbfcef1
Update upload-lib tests for CSRA
2026-02-11 22:11:17 +00:00
Michael B. Gale
5132eb53f2
Fix CodeScanning config's sarifPredicate and add test
2026-02-11 22:10:55 +00:00
Michael B. Gale
5b3261bcbf
Enforce that only compatible kinds can be enabled concurrently
2026-02-11 20:14:37 +00:00
Michael B. Gale
9267d8d51e
Add csra analysis kind
2026-02-11 19:48:06 +00:00
Michael B. Gale
bc1164e014
Fix typo in test
2026-02-11 19:35:29 +00:00
Michael B. Gale
7801eda177
Add some basic unit tests
2026-02-11 19:23:35 +00:00
Michael B. Gale
b1d963ed8f
Gate updated cert gen behind FF
2026-02-11 19:23:10 +00:00
Michael B. Gale
d636fb3f63
Move certificate code to its own file
2026-02-11 19:23:09 +00:00
Michael B. Gale
d155ebf27f
Set more extensions
2026-02-11 19:23:09 +00:00
Michael B. Gale
e8f0116911
Explicitly sign certificate with SHA256
2026-02-11 19:23:09 +00:00
Michael B. Gale
713a293090
Set keyUsage
2026-02-11 19:23:08 +00:00
Michael B. Gale
ff33514494
Merge pull request #3466 from github/mbg/start-proxy/test-connections
...
Test connections to private registries in `start-proxy`
2026-02-11 19:19:02 +00:00
Michael B. Gale
efb92e2714
Skip checks for non-URLs for now
2026-02-11 18:02:24 +00:00
github-actions[bot]
d73644591f
Rebuild
2026-02-11 18:01:35 +00:00
dependabot[bot]
41d2cc39b6
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.286.0 to 1.288.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/90be1154f987f4dc0fe0dd0feedac9e473aa4ba8...09a7688d3b55cf0e976497ff046b70949eeaccfd )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.288.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-11 17:59:56 +00:00
github-actions[bot]
be578c7735
Rebuild
2026-02-11 17:54:50 +00:00
dependabot[bot]
fa6e24cf12
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@eslint/compat` from 2.0.1 to 2.0.2
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.2/packages/compat )
Updates `eslint-plugin-jsdoc` from 62.4.1 to 62.5.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.4.1...v62.5.0 )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-11 17:53:12 +00:00
Michael B. Gale
2b5b614c85
Add timeout event handler
2026-02-11 17:50:44 +00:00
Michael B. Gale
555ee17b0b
Remove unused logger in NetworkReachabilityBackend
2026-02-11 17:46:33 +00:00
Michael B. Gale
e114998dda
Add test for missing type
2026-02-11 17:15:45 +00:00
Michael B. Gale
bd36637537
Require validated Credential for credentialToStr
2026-02-11 17:13:01 +00:00
Michael B. Gale
4d0bec12bf
Rename types
2026-02-11 17:10:39 +00:00
Michael B. Gale
0387f55b70
Fix outdated comment
2026-02-11 16:49:07 +00:00
Michael B. Gale
27b3b6586d
Remove unnecessary test assertions
2026-02-11 16:47:57 +00:00
Michael B. Gale
c4b0f60beb
Remove superfluous error handling details
2026-02-10 17:15:03 +00:00
Michael B. Gale
51357000d2
Add a 5s timeout to requests
2026-02-10 17:09:49 +00:00
Michael B. Gale
4d44b570d2
Type that registries must have either an url or a host
2026-02-10 17:05:44 +00:00
Michael B. Gale
700fc11b44
Add missing else
2026-02-10 16:21:07 +00:00
Michael B. Gale
9f2f6d0d2e
Remove superflous log message
2026-02-10 16:13:23 +00:00
Michael B. Gale
01ee641f14
Test connections to registries, if FF is enabled
2026-02-10 15:37:45 +00:00
Michael B. Gale
c7eff3f0b1
Add StartProxyConnectionChecks feature
2026-02-10 14:57:16 +00:00
Michael B. Gale
c4717c9c74
Add ProxyInfo type and return from startProxy
2026-02-10 14:56:24 +00:00
Michael B. Gale
b030333651
Add explicit dependency on https-proxy-agent
2026-02-10 14:53:56 +00:00
Michael B. Gale
70eae154c6
Break up Credential type into two interfaces
2026-02-09 17:36:08 +00:00
Michael B. Gale
93302bc63a
Move Credential type
2026-02-09 17:32:48 +00:00
Michael B. Gale
310177a1fb
Merge branch 'main' into mbg/start-proxy/test-connections
2026-02-09 17:27:05 +00:00
Henry Mercer
b13d724d35
Merge pull request #3462 from github/mergeback/v4.32.2-to-main-45cbd0c6
...
Mergeback v4.32.2 refs/heads/releases/v4 into main
2026-02-06 11:33:23 +00:00
github-actions[bot]
4b8e16f54f
Rebuild
2026-02-06 11:00:39 +00:00
github-actions[bot]
481be99883
Merge remote-tracking branch 'origin/main' into mergeback/v4.32.2-to-main-45cbd0c6
2026-02-06 10:59:51 +00:00
Michael B. Gale
9b3a0d2c26
Merge pull request #3464 from github/mbg/disable-ts-unused-checks
...
Disable TypeScript `noUnusedLocals` and `noUnusedParameters` options, already covered by eslint
2026-02-06 10:59:44 +00:00
Michael B. Gale
d2901f5537
Make FFs available in start-proxy action
2026-02-06 10:43:36 +00:00
Michael B. Gale
46c411a7f4
Disable noUnusedLocals and noUnusedParameters
2026-02-06 00:14:12 +00:00
github-actions[bot]
5a82333186
Update changelog and version after v4.32.2
2026-02-05 17:09:49 +00:00
Henry Mercer
45cbd0c69e
Merge pull request #3461 from github/update-v4.32.2-7aee93297
...
Merge main into releases/v4
2026-02-05 17:07:58 +00:00
github-actions[bot]
cb528be87e
Update changelog for v4.32.2
2026-02-05 16:29:51 +00:00
Henry Mercer
7aee932974
Merge pull request #3460 from github/update-bundle/codeql-bundle-v2.24.1
...
Update default bundle to 2.24.1
2026-02-05 15:52:29 +00:00
Henry Mercer
b5f028a984
Merge pull request #3457 from github/dependabot/npm_and_yarn/npm-minor-4c1fc3d0aa
...
Bump the npm-minor group across 1 directory with 4 updates
2026-02-05 15:47:13 +00:00
Henry Mercer
9702c27ab9
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-4c1fc3d0aa
2026-02-05 15:18:18 +00:00
github-actions[bot]
c36c94846f
Add changelog note
2026-02-05 15:16:32 +00:00
github-actions[bot]
3d0331896c
Update default bundle to codeql-bundle-v2.24.1
2026-02-05 15:16:22 +00:00
Henry Mercer
77591e2c4a
Merge pull request #3459 from github/copilot/fix-github-actions-workflow-again
...
Fix `git merge --continue` missing --no-edit in Rebuild workflow
2026-02-05 15:00:59 +00:00
copilot-swe-agent[bot]
7a44a9db3f
Fix Rebuild Action workflow by adding --no-edit flag to git merge --continue
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2026-02-04 21:50:17 +00:00
copilot-swe-agent[bot]
e2ac371513
Initial plan
2026-02-04 21:48:30 +00:00
Michael B. Gale
7deb0a15d3
Merge pull request #3444 from github/mbg/start-proxy/error-types
...
Report some types of errors in `start-proxy` status reports
2026-02-04 19:12:25 +00:00
github-actions[bot]
4f6ea84c21
Rebuild
2026-02-04 18:53:07 +00:00
dependabot[bot]
73dbc8364d
Bump the npm-minor group across 1 directory with 4 updates
...
Bumps the npm-minor group with 3 updates in the / directory: [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@actions/github` from 8.0.0 to 8.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
Updates `@typescript-eslint/eslint-plugin` from 8.53.1 to 8.54.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.54.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.53.1 to 8.54.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.54.0/packages/parser )
Updates `eslint-plugin-jsdoc` from 62.3.0 to 62.4.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.3.0...v62.4.1 )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 8.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.54.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.54.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.4.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-04 18:51:26 +00:00
Michael B. Gale
f959778b39
Merge pull request #3451 from github/dependabot/npm_and_yarn/isaacs/brace-expansion-5.0.1
...
Bump @isaacs/brace-expansion from 5.0.0 to 5.0.1
2026-02-04 10:07:23 +00:00
github-actions[bot]
d38ad56358
Rebuild
2026-02-03 19:49:21 +00:00
dependabot[bot]
bc9796e2e0
Bump @isaacs/brace-expansion from 5.0.0 to 5.0.1
...
Bumps @isaacs/brace-expansion from 5.0.0 to 5.0.1.
---
updated-dependencies:
- dependency-name: "@isaacs/brace-expansion"
dependency-version: 5.0.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-03 19:47:47 +00:00
Henry Mercer
ab5b0e3aab
Merge pull request #3450 from github/henrymercer/add-requires-auth
...
Add "Requires authentication" to `wrapApiConfigurationError`
2026-02-02 10:22:51 -08:00
Michael B. Gale
57a47f44df
Improve credentialToStr tests
2026-02-02 18:13:23 +00:00
Michael B. Gale
076d055bee
Improve sendFailedStatusReport tests
2026-02-02 18:09:44 +00:00
Henry Mercer
6d4cd5d744
Add "Requires authentication" to wrapApiConfigurationError
2026-02-02 18:02:11 +00:00
Michael B. Gale
42fb267c1c
Don't store error message in StartProxyError errors
2026-02-02 17:26:37 +00:00
Michael B. Gale
832a783bd4
Address minor review comments
2026-02-02 17:13:43 +00:00
Michael B. Gale
160e695297
Merge branch 'main' into mbg/start-proxy/error-types
2026-02-02 16:34:35 +00:00
Henry Mercer
8aac4e47ac
Merge pull request #3448 from github/mergeback/v4.32.1-to-main-6bc82e05
...
Mergeback v4.32.1 refs/heads/releases/v4 into main
2026-02-02 07:46:51 -08:00
github-actions[bot]
e8d7df4f04
Rebuild
2026-02-02 15:21:41 +00:00
github-actions[bot]
c1bba77db0
Update changelog and version after v4.32.1
2026-02-02 15:11:38 +00:00
Henry Mercer
6bc82e05fd
Merge pull request #3447 from github/update-v4.32.1-f52cbc830
...
Merge main into releases/v4
2026-02-02 07:09:16 -08:00
Michael B. Gale
42f00f2d33
Add a couple of change notes
2026-02-02 14:32:28 +00:00
github-actions[bot]
cedee6de9f
Update changelog for v4.32.1
2026-02-02 12:13:48 +00:00
Henry Mercer
f52cbc8309
Merge pull request #3445 from github/dependabot/npm_and_yarn/fast-xml-parser-5.3.4
...
Bump fast-xml-parser from 5.3.3 to 5.3.4
2026-02-02 03:49:48 -08:00
Michael B. Gale
c5aaca4bb9
Merge pull request #3446 from github/mbg/ci/pin-node-packages
2026-02-02 10:51:35 +00:00
Michael B. Gale
3e58739c65
Pin @actions/tool-cache@3 in workflows to avoid failures with github-script
2026-02-02 08:18:36 +00:00
github-actions[bot]
a6ccefb47c
Rebuild
2026-01-30 23:00:12 +00:00
dependabot[bot]
0e64858573
Bump fast-xml-parser from 5.3.3 to 5.3.4
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) from 5.3.3 to 5.3.4.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.3...v5.3.4 )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-30 22:58:35 +00:00
Michael B. Gale
beb9f533db
Add and use getProxyFilename
2026-01-29 15:19:36 +00:00
Michael B. Gale
a1c70789a3
Use getSafeErrorMessage for unhandled error message
2026-01-29 15:09:21 +00:00
Michael B. Gale
d94d88d717
Add tests for getProxyBinaryPath
2026-01-29 15:06:20 +00:00
Michael B. Gale
a6d296a341
Move getProxyBinaryPath to start-proxy module
2026-01-29 14:20:16 +00:00
Michael B. Gale
28f6d316c0
Handle toolcache errors with StartProxyError
2026-01-29 14:16:36 +00:00
Michael B. Gale
1d0f911837
Handle extraction errors with StartProxyError
2026-01-29 13:45:46 +00:00
Michael B. Gale
05bd050f34
Add and use withRecordingLoggerAsync
2026-01-29 13:44:10 +00:00
Michael B. Gale
325a3a2ae3
Add wrapFailureTest test macro
2026-01-29 13:34:19 +00:00
Michael B. Gale
6394750070
Add test for sendFailedStatusReport
2026-01-29 13:19:37 +00:00
Michael B. Gale
f1588cde0c
Add StartProxyError for status-report-safe errors, and use for proxy download
2026-01-29 12:38:04 +00:00
Henry Mercer
f985be5b50
Merge pull request #3443 from github/dependabot/npm_and_yarn/tar-7.5.7
...
Bump tar from 7.5.6 to 7.5.7
2026-01-29 03:00:35 -08:00
Michael B. Gale
4dcc8a9cdc
Move failed status report code into sendFailedStatusReport
2026-01-29 10:28:55 +00:00
Michael B. Gale
fbe3ae9de8
Move sendSuccessStatusReport to start-proxy module
2026-01-29 10:20:59 +00:00
Michael B. Gale
2a384c1c14
Move credentialToStr and add tests
2026-01-29 10:07:51 +00:00
dependabot[bot]
0c8e06dfb2
Bump tar from 7.5.6 to 7.5.7
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.5.6 to 7.5.7.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.6...v7.5.7 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-28 19:01:18 +00:00
Henry Mercer
b2ff80ddac
Merge pull request #3440 from github/dependabot/npm_and_yarn/npm-minor-6271c457c1
...
Bump the npm-minor group with 7 updates
2026-01-28 10:59:57 -08:00
github-actions[bot]
48f3548141
Rebuild
2026-01-28 17:55:06 +00:00
dependabot[bot]
800dfbe5e1
Bump the npm-minor group with 7 updates
...
Bumps the npm-minor group with 7 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact ) | `5.0.2` | `5.0.3` |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `5.0.3` | `5.0.5` |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core ) | `2.0.2` | `2.0.3` |
| [@actions/glob](https://github.com/actions/toolkit/tree/HEAD/packages/glob ) | `0.5.0` | `0.5.1` |
| [@actions/http-client](https://github.com/actions/toolkit/tree/HEAD/packages/http-client ) | `3.0.1` | `3.0.2` |
| [@actions/tool-cache](https://github.com/actions/toolkit/tree/HEAD/packages/tool-cache ) | `3.0.0` | `3.0.1` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `62.2.0` | `62.3.0` |
Updates `@actions/artifact` from 5.0.2 to 5.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/artifact )
Updates `@actions/cache` from 5.0.3 to 5.0.5
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@actions/core` from 2.0.2 to 2.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core )
Updates `@actions/glob` from 0.5.0 to 0.5.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/glob/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/glob )
Updates `@actions/http-client` from 3.0.1 to 3.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/http-client/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/http-client )
Updates `@actions/tool-cache` from 3.0.0 to 3.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/tool-cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/tool-cache )
Updates `eslint-plugin-jsdoc` from 62.2.0 to 62.3.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.2.0...v62.3.0 )
---
updated-dependencies:
- dependency-name: "@actions/artifact"
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/cache"
dependency-version: 5.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/core"
dependency-version: 2.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/glob"
dependency-version: 0.5.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/http-client"
dependency-version: 3.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/tool-cache"
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.3.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-28 17:53:24 +00:00
Michael B. Gale
1314d3d17e
Merge pull request #3439 from github/mbg/fix-proxy-test
...
Remove `gh` setup from global proxy test
2026-01-28 13:58:28 +00:00
Michael B. Gale
f7f9d3f341
Remove gh setup from global proxy test
2026-01-28 13:35:59 +00:00
Henry Mercer
eb5bd2d0b9
Merge pull request #3421 from github/henrymercer/only-request-properties-for-orgs
...
Tolerate errors loading repository properties
2026-01-28 04:00:31 -08:00
Henry Mercer
9aa0515f67
Update comments
2026-01-28 11:33:06 +00:00
Henry Mercer
0720e13f0b
Log repository owner type explicitly
2026-01-28 11:30:35 +00:00
Henry Mercer
38ba96d2aa
Merge branch 'main' into henrymercer/only-request-properties-for-orgs
2026-01-27 18:28:33 +00:00
Henry Mercer
679da45cc3
Add basic unit tests for Result class
2026-01-27 15:19:17 +00:00
Henry Mercer
d5dd165f8b
Ensure default value is assignable if we have a Failure
2026-01-27 15:18:50 +00:00
Henry Mercer
fbf75ebd7b
Merge branch 'main' into henrymercer/only-request-properties-for-orgs
2026-01-27 15:17:20 +00:00
Henry Mercer
6a50972d16
Introduce addNoLanguageDiagnostic
2026-01-27 15:14:32 +00:00
Henry Mercer
5cb12c41c2
Include "Result" in name
2026-01-27 15:11:48 +00:00
Henry Mercer
e8f487178f
Add some doc for loadRepositoryProperties
2026-01-27 15:11:01 +00:00
Henry Mercer
a0671be58e
Add doc for Result
2026-01-27 15:07:46 +00:00
Henry Mercer
9ea34c5169
Result: Make use of type hint
2026-01-27 15:05:03 +00:00
Henry Mercer
9fda641d8d
Prefer accessing context via @actions/github
2026-01-27 15:00:52 +00:00
Henry Mercer
b126facd4e
Merge pull request #3434 from github/mbg/dependabot/cooldown
...
Add `cooldown` settings for Dependabot
2026-01-27 06:57:30 -08:00
Henry Mercer
835dadecbf
Merge pull request #3420 from github/henrymercer/compute-job-status-if-no-config
...
Simplify computation of job status
2026-01-27 06:51:55 -08:00
Henry Mercer
a02edfe319
Merge pull request #3424 from github/henrymercer/feature-skip-file-coverage-info-prs
...
Add feature flag to skip computing baseline file coverage information on PRs
2026-01-27 06:49:29 -08:00
Michael B. Gale
173919c9d5
Merge pull request #3436 from github/mbg/rebuild-js-es2022
...
Update JS for ES2022
2026-01-27 14:46:54 +00:00
Henry Mercer
6095dc4d51
Merge branch 'main' into henrymercer/compute-job-status-if-no-config
2026-01-27 14:31:51 +00:00
Henry Mercer
b333fc6f5b
Split up getFinalJobStatus
2026-01-27 14:30:42 +00:00
Henry Mercer
60b658ed10
Update comment
2026-01-27 14:26:31 +00:00
Michael B. Gale
e4e324705e
Update JS
2026-01-27 14:13:28 +00:00
github-actions[bot]
faf7a50b01
Rebuild
2026-01-27 14:13:05 +00:00
Michael B. Gale
2591c2031f
Add cooldown settings for Dependabot
2026-01-27 14:08:27 +00:00
Michael B. Gale
34cae51104
Merge pull request #3422 from github/mbg/start-proxy/warn-if-pat-without-username
...
Warn if a private registry configuration uses a PAT, but has no username
2026-01-27 14:07:06 +00:00
Henry Mercer
9308bcd6bb
Add unit tests for file coverage enablement
2026-01-27 13:55:22 +00:00
Michael B. Gale
fa9b76ac37
Merge pull request #3432 from github/dependabot/npm_and_yarn/actions/github-8.0.0
...
Bump @actions/github from 7.0.0 to 8.0.0
2026-01-27 13:49:13 +00:00
Michael B. Gale
6059a66dec
Remove @octokit/plugin-retry from Dependabot ignore list
2026-01-27 13:22:57 +00:00
Michael B. Gale
cb4fc9e8db
Update @octokit/plugin-retry
2026-01-27 13:10:33 +00:00
Michael B. Gale
be82188a2a
Bump ES version, required by newer @octokit/request-error
2026-01-27 13:09:39 +00:00
Michael B. Gale
c656a11252
Use .match in isAuthToken and add repeated call to test
2026-01-27 11:45:03 +00:00
Michael B. Gale
bd9f639752
Merge pull request #3433 from github/dependabot/github_actions/dot-github/workflows/actions-minor-69d791f5c9
...
Bump ruby/setup-ruby from 1.284.0 to 1.286.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-27 11:31:46 +00:00
Michael B. Gale
0a0c3a2e09
Merge branch 'main' into mbg/start-proxy/warn-if-pat-without-username
2026-01-27 11:27:31 +00:00
github-actions[bot]
46a8de52fc
Rebuild
2026-01-26 19:47:52 +00:00
dependabot[bot]
f8cea24201
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.284.0 to 1.286.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/80740b3b13bf9857e28854481ca95a84e78a2bdf...90be1154f987f4dc0fe0dd0feedac9e473aa4ba8 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.286.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-26 19:46:17 +00:00
dependabot[bot]
b1993d9139
Bump @actions/github from 7.0.0 to 8.0.0
...
Bumps [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ) from 7.0.0 to 8.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 8.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-26 19:40:04 +00:00
Henry Mercer
ee1e1399e2
Merge pull request #3429 from github/mergeback/v4.32.0-to-main-b20883b0
...
Mergeback v4.32.0 refs/heads/releases/v4 into main
2026-01-26 11:18:48 -08:00
github-actions[bot]
e7d3af2e1e
Rebuild
2026-01-26 18:54:35 +00:00
github-actions[bot]
13a6d8be95
Update changelog and version after v4.32.0
2026-01-26 18:39:39 +00:00
Henry Mercer
b20883b0cd
Merge pull request #3428 from github/update-v4.32.0-e3b8227a2
...
Merge main into releases/v4
2026-01-26 10:38:00 -08:00
Henry Mercer
bf20b3e07b
Exclude PR check from feature flag
2026-01-26 18:04:37 +00:00
Henry Mercer
f1aa4f497a
Explain why we ignore extra baseline files options
2026-01-26 18:02:58 +00:00
Henry Mercer
9a55d5bc5f
Improve log message
2026-01-26 18:00:34 +00:00
Henry Mercer
17cd475099
Move to separate function
2026-01-26 17:55:17 +00:00
github-actions[bot]
c9aa45dd0f
Update changelog for v4.32.0
2026-01-26 17:52:31 +00:00
Henry Mercer
e3b8227a28
Merge pull request #3427 from github/henrymercer/bump-for-new-minor-series
...
Bump the Action minor version number on new CodeQL minor version series
2026-01-26 09:12:23 -08:00
Henry Mercer
8a01181ce2
Compare minor version number
...
This deals with the case that we skip `x.y.0` and go straight to `x.y.1`.
2026-01-26 16:50:11 +00:00
Henry Mercer
80e142568f
Bump minor version for CLI v2.24.0
2026-01-26 15:46:05 +00:00
Henry Mercer
b748848f27
Bump the Action minor version number on new CodeQL minor version series
2026-01-26 15:45:24 +00:00
Nick Rolfe
5e767eff5a
Merge pull request #3425 from github/update-bundle/codeql-bundle-v2.24.0
...
Update default bundle to 2.24.0
2026-01-26 04:40:17 -08:00
github-actions[bot]
9752869470
Add changelog note
2026-01-26 12:16:22 +00:00
github-actions[bot]
c62c214723
Update default bundle to codeql-bundle-v2.24.0
2026-01-26 12:16:14 +00:00
Henry Mercer
18c2cfc765
Indulge caniuse-lite to avoid build warnings
2026-01-26 11:42:13 +00:00
Henry Mercer
1996ca9f5d
Log when file coverage info is disabled
2026-01-26 11:42:13 +00:00
Henry Mercer
12c4c7d0e9
Don't log empty summaries
2026-01-26 11:42:13 +00:00
Michael B. Gale
25a224b808
Merge pull request #3423 from github/mbg/ci/yq-windows
...
Add `installYq` option to `sync.py` and install `yq` directly from GitHub release
2026-01-26 11:23:44 +00:00
Henry Mercer
919e8aaa40
Mention caveat in feature JSDoc
2026-01-26 11:00:04 +00:00
Henry Mercer
4918026b93
Use FF to disable baseline file coverage
2026-01-26 11:00:04 +00:00
Henry Mercer
e8c164b902
Remove unused database print-baseline
2026-01-26 11:00:03 +00:00
Michael B. Gale
3657da1eac
Move yq version into env var and add comment
2026-01-26 10:59:43 +00:00
Michael B. Gale
605d404db0
Install yq directly from GitHub release
2026-01-24 14:09:33 +00:00
Michael B. Gale
efea9cca02
Add installYq option to sync.py and cache downloads
2026-01-24 13:43:15 +00:00
Michael B. Gale
9fccf271ff
Warn if a private registry configuration uses a PAT, but has no username
2026-01-24 13:02:41 +00:00
Michael B. Gale
c12cf8d49a
Move makeTestToken to testing-utils
2026-01-24 12:55:32 +00:00
Michael B. Gale
0fcbec3eec
Add isAuthToken function, with tests
2026-01-24 12:38:14 +00:00
Michael B. Gale
0ae8b05d08
Extend unit tests to cover all token types
2026-01-24 12:25:40 +00:00
Michael B. Gale
49cdf744d9
Use enum for token types
2026-01-24 11:58:10 +00:00
Michael B. Gale
aac4202424
Add fine-grained tokens to GITHUB_TOKEN_PATTERNS
2026-01-24 11:52:53 +00:00
Henry Mercer
e7ece62b96
Add feature flag to skip file coverage information on PRs
2026-01-23 18:41:24 +00:00
Henry Mercer
d9e374ef85
Tolerate failures loading repository properties
2026-01-23 17:51:41 +00:00
Henry Mercer
f4b47e7013
Add result type
2026-01-23 17:51:02 +00:00
Henry Mercer
4e14537b54
Improve logging when no known repository properties found
2026-01-23 17:29:15 +00:00
Henry Mercer
e142eee9b4
Only load repository properties for repos owned by orgs
2026-01-23 17:20:30 +00:00
Henry Mercer
dcd1b12beb
Simplify computation of job status
...
- Move it out of the failed SARIF reporting so we compute the job status
whether or not we have a CodeQL config.
- Add comments to clarify what happens in the case that the CodeQL
config is absent.
2026-01-23 17:07:21 +00:00
Michael B. Gale
55252c7a3a
Merge pull request #3418 from github/mergeback/v4.31.11-to-main-19b2f06d
...
Mergeback v4.31.11 refs/heads/releases/v4 into main
2026-01-23 15:26:56 +00:00
github-actions[bot]
7381f9750d
Rebuild
2026-01-23 14:48:27 +00:00
github-actions[bot]
6e162a0930
Update changelog and version after v4.31.11
2026-01-23 13:53:17 +00:00
Michael B. Gale
19b2f06db2
Merge pull request #3417 from github/update-v4.31.11-1601acf88
...
Merge main into releases/v4
2026-01-23 13:51:38 +00:00
Michael B. Gale
03afde035d
Add noteworthy changes to changelog
2026-01-23 13:24:31 +00:00
github-actions[bot]
9469107033
Update changelog for v4.31.11
2026-01-23 12:58:42 +00:00
Henry Mercer
1601acf88b
Merge pull request #3415 from github/henrymercer/address-telemetry-gap
...
Address missing telemetry at the start of Actions
2026-01-23 04:51:05 -08:00
Henry Mercer
fba78720ca
Address review comments
2026-01-23 12:22:31 +00:00
Henry Mercer
a8dd5ab7a4
Merge pull request #3414 from github/dependabot/npm_and_yarn/lodash-4.17.23
...
Bump lodash from 4.17.21 to 4.17.23
2026-01-23 02:55:45 -08:00
Henry Mercer
28bfb7b7b5
Omit error from start-proxy Action
2026-01-23 10:42:42 +00:00
Henry Mercer
91f3460006
Throw if in test mode
2026-01-23 10:40:51 +00:00
Henry Mercer
edebb7861e
Differentiate unhandled errors in telemetry
2026-01-23 10:39:51 +00:00
Henry Mercer
529c266223
Use getErrorMessage in more places
2026-01-23 10:36:25 +00:00
Henry Mercer
6bd84b6a82
Rename to "unhandled"
2026-01-23 10:34:45 +00:00
Henry Mercer
5e98e18a17
Merge pull request #3410 from github/dependabot/npm_and_yarn/tar-7.5.6
...
Bump tar from 7.4.3 to 7.5.6
2026-01-22 05:15:39 -08:00
Henry Mercer
229e0cd749
Add catch-all error reporting for errors that slip through run
2026-01-22 13:14:53 +00:00
Henry Mercer
14bd76753f
Add reminder to minimise code outside try/catch
2026-01-22 11:31:17 +00:00
Henry Mercer
b715292b74
Move config saving within try-catch
2026-01-22 11:27:46 +00:00
Henry Mercer
7c72e12ecb
Expand try-catch to cover more of Actions
2026-01-22 10:46:05 +00:00
dependabot[bot]
b5bb69ad4b
Bump lodash from 4.17.21 to 4.17.23
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-22 00:26:32 +00:00
Michael B. Gale
1c4c0b36be
Merge pull request #3318 from github/mbg/ignore-generated
2026-01-21 14:43:55 +00:00
Michael B. Gale
bc75091173
Add empty lines to test cases
2026-01-21 13:29:15 +00:00
Michael B. Gale
dc2428c879
Trim whitespace/remove empty lines
2026-01-21 13:27:47 +00:00
Michael B. Gale
cb2dd2ed29
Add telemetry diagnostic
2026-01-21 13:22:01 +00:00
Michael B. Gale
9e2fa7419d
Use joinAtMost for log message
2026-01-21 13:12:28 +00:00
Michael B. Gale
6a02be43ee
Add joinAtMost utility function
2026-01-21 13:10:50 +00:00
dependabot[bot]
e19f95e73f
Bump tar from 7.4.3 to 7.5.6
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.4.3 to 7.5.6.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.4.3...v7.5.6 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-21 12:56:03 +00:00
Michael B. Gale
4325937dc6
Merge pull request #3405 from github/mbg/ci/fix-concurrency-ignores-inputs
...
Improve `concurrency` settings for PR checks
2026-01-21 12:54:48 +00:00
Michael B. Gale
d5b3d42fd4
Inline EnvVar.ANALYSIS_KEY in getAnalysisKey
2026-01-21 12:52:24 +00:00
Michael B. Gale
417a8c2176
Merge branch 'main' into mbg/ignore-generated
2026-01-21 12:44:35 +00:00
Michael B. Gale
fa03060d60
Update new CCR workflow
2026-01-21 12:33:08 +00:00
Michael B. Gale
f58cb3d53e
Improve comment for concurrency settings
2026-01-21 12:33:02 +00:00
Michael B. Gale
51975ff7b7
Merge branch 'main' into mbg/ci/fix-concurrency-ignores-inputs
2026-01-21 12:28:09 +00:00
Henry Mercer
32d41f36fe
Merge pull request #3403 from github/henrymercer/abridge-release-notes
...
Abridge release notes
2026-01-20 06:26:19 -08:00
Michael B. Gale
d60bbdfd70
Merge pull request #3409 from github/mbg/start-proxy/make-unique-artifact
...
Ensure that proxy log artifacts have unique names
2026-01-20 14:24:28 +00:00
Henry Mercer
93a99bf571
Merge pull request #3404 from github/henrymercer/include-oids-in-bundle
...
Include base database OIDs when bundling database
2026-01-20 06:13:13 -08:00
Michael B. Gale
dce83e1c1e
Merge pull request #3408 from github/mbg/add-ccr-check
...
Add basic PR check with CCR-like environment
2026-01-20 14:04:13 +00:00
Henry Mercer
ec4eda1b42
Just link the release notes
2026-01-20 14:00:21 +00:00
Michael B. Gale
1df1c9f85d
Include expected suffixes in test
2026-01-20 13:55:25 +00:00
Michael B. Gale
9483bd5a7f
Check that matrixObject is an object
2026-01-20 13:51:59 +00:00
Henry Mercer
b880a1a7bd
Improve comment
2026-01-20 13:45:41 +00:00
Henry Mercer
5ac04769eb
Rename argument
2026-01-20 13:39:43 +00:00
Michael B. Gale
1ac62705ed
Change log message to warning
2026-01-20 13:25:25 +00:00
Michael B. Gale
9a57e78a04
Improving sorting of matrix keys
2026-01-20 13:21:16 +00:00
Michael B. Gale
7e96d45489
Use uploadArtifacts for start-proxy post action
2026-01-20 12:52:35 +00:00
Michael B. Gale
13eb1818b9
Refactor generic part of uploadDebugArtifacts into uploadArtifacts
2026-01-20 12:49:19 +00:00
Michael B. Gale
f950f7f442
Add unit tests for getArtifactSuffix
2026-01-20 12:41:35 +00:00
Michael B. Gale
69173ea009
Refactor artifact suffix computation into getArtifactSuffix
2026-01-20 12:41:22 +00:00
Michael B. Gale
a886c30690
Add basic PR check with CCR-like environment
2026-01-20 12:19:29 +00:00
Michael B. Gale
044ff10e29
Merge pull request #3406 from github/dependabot/npm_and_yarn/npm-minor-e76a272df4
...
Bump the npm-minor group with 4 updates
2026-01-20 11:18:45 +00:00
Michael B. Gale
84edfc05fa
Merge pull request #3407 from github/dependabot/github_actions/dot-github/workflows/actions-minor-ec7bddb364
...
Bump ruby/setup-ruby from 1.281.0 to 1.284.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-20 11:16:49 +00:00
github-actions[bot]
df0cc0ca39
Rebuild
2026-01-19 19:40:50 +00:00
dependabot[bot]
24f1cbdafb
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.281.0 to 1.284.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/675dd7ba1b06c8786a1480d89c384f5620a42647...80740b3b13bf9857e28854481ca95a84e78a2bdf )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.284.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 19:39:18 +00:00
github-actions[bot]
8881a4160f
Rebuild
2026-01-19 19:34:41 +00:00
dependabot[bot]
1191c09db6
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@actions/cache` from 5.0.2 to 5.0.3
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@typescript-eslint/eslint-plugin` from 8.53.0 to 8.53.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.53.0 to 8.53.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.1/packages/parser )
Updates `eslint-plugin-jsdoc` from 62.0.0 to 62.2.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.0.0...v62.2.0 )
---
updated-dependencies:
- dependency-name: "@actions/cache"
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.53.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.53.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.2.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 19:33:09 +00:00
Michael B. Gale
90f4ffcc7e
Include input values in concurrency groups
2026-01-19 18:53:51 +00:00
Michael B. Gale
03e3f60d99
Explicitly set cancel-in-progress to false
2026-01-19 18:51:44 +00:00
Michael B. Gale
778f83ff16
Use hard-coded concurrency group names instead of github.workflow
...
Since `github.workflow` will be the caller's name for `workflow_call` events
2026-01-19 18:43:17 +00:00
Henry Mercer
75716abfa3
Merge branch 'main' into henrymercer/include-oids-in-bundle
2026-01-19 18:11:11 +00:00
Henry Mercer
ebffc48bf5
Include /tag in bundle release URL
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-19 18:00:34 +00:00
Henry Mercer
d51b375a03
Drop unneeded version tag argument
2026-01-19 17:59:04 +00:00
Henry Mercer
3a7caafd73
Update comment
2026-01-19 17:57:59 +00:00
Henry Mercer
4d4ae1fbe8
Abridge release notes for Action GH release
2026-01-19 17:55:06 +00:00
Henry Mercer
064fafeb49
Link CLI/language pack notes from new bundle changelog
2026-01-19 17:51:27 +00:00
Henry Mercer
a7783c507b
Make bundle changelog script executable
...
For local testing
2026-01-19 17:49:14 +00:00
Henry Mercer
0d94aab48f
Make prepare changelog script executable
...
For local testing
2026-01-19 17:43:45 +00:00
Michael B. Gale
1ec7dd2bc4
Merge pull request #3398 from github/dependabot/npm_and_yarn/actions/github-7.0.0
...
Bump @actions/github from 6.0.1 to 7.0.0
2026-01-19 14:47:09 +00:00
github-actions[bot]
1b4c62b79d
Rebuild
2026-01-19 14:20:47 +00:00
Michael B. Gale
4bd7556a48
Log when there are no generated files
2026-01-19 14:12:57 +00:00
Michael B. Gale
7beb64218a
Move after Git version check
2026-01-19 14:12:04 +00:00
Michael B. Gale
546ea07303
Use linebreaks
2026-01-19 14:11:11 +00:00
Michael B. Gale
9c3f69d7a3
Add some logging
2026-01-19 14:04:41 +00:00
Michael B. Gale
5f5c095469
Add docs comments for listFiles and getGeneratedFiles
2026-01-19 13:49:42 +00:00
Michael B. Gale
c7d0b92094
Drop isDynamic check from isCCR
...
The analysis key already tells us this under normal conditions
2026-01-19 13:47:50 +00:00
Michael B. Gale
055e6b6f36
Add EnvVar constant for analysis key
2026-01-19 13:41:38 +00:00
Michael B. Gale
644e2b9bd7
Restore condition for enablement
2026-01-19 13:19:48 +00:00
Michael B. Gale
02b2c55c51
Use stdin for files to query attributes of
2026-01-19 13:18:48 +00:00
Michael B. Gale
1782089bde
Merge branch 'main' into mbg/ignore-generated
2026-01-19 13:09:15 +00:00
dependabot[bot]
6c5e0ea335
Bump @actions/github from 6.0.1 to 7.0.0
...
Bumps [@actions/github](https://github.com/actions/toolkit/tree/HEAD/packages/github ) from 6.0.1 to 7.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/github/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/github )
---
updated-dependencies:
- dependency-name: "@actions/github"
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-19 13:05:53 +00:00
Michael B. Gale
c99e493099
Merge pull request #3399 from github/dependabot/npm_and_yarn/eslint-plugin-jsdoc-62.0.0
...
Bump eslint-plugin-jsdoc from 61.5.0 to 62.0.0
2026-01-19 13:04:30 +00:00
Michael B. Gale
f687ebf1c9
Merge pull request #3397 from github/dependabot/npm_and_yarn/npm-minor-70139cb906
...
Bump the npm-minor group with 7 updates
2026-01-19 11:46:30 +00:00
Michael B. Gale
070e2a5f21
Merge pull request #3400 from github/dependabot/npm_and_yarn/actions/tool-cache-3.0.0
...
Bump @actions/tool-cache from 2.0.2 to 3.0.0
2026-01-19 10:49:50 +00:00
Michael B. Gale
fb650c22f9
Merge pull request #3401 from github/dependabot/github_actions/dot-github/workflows/actions-minor-c79fd65a81
...
Bump ruby/setup-ruby from 1.278.0 to 1.281.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-16 18:03:34 +00:00
github-actions[bot]
21c5dc0f33
Rebuild
2026-01-12 22:02:32 +00:00
dependabot[bot]
bdabb8f1bc
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.278.0 to 1.281.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/4c24fa5ec04b2e79eb40571b1cee2a0d2b705771...675dd7ba1b06c8786a1480d89c384f5620a42647 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.281.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:59:39 +00:00
github-actions[bot]
39105f35da
Rebuild
2026-01-12 21:55:29 +00:00
github-actions[bot]
dc7e2ff87d
Rebuild
2026-01-12 21:55:24 +00:00
github-actions[bot]
642eca368e
Rebuild
2026-01-12 21:54:58 +00:00
dependabot[bot]
e20d24fb28
Bump @actions/tool-cache from 2.0.2 to 3.0.0
...
Bumps [@actions/tool-cache](https://github.com/actions/toolkit/tree/HEAD/packages/tool-cache ) from 2.0.2 to 3.0.0.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/tool-cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/tool-cache )
---
updated-dependencies:
- dependency-name: "@actions/tool-cache"
dependency-version: 3.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:57 +00:00
dependabot[bot]
f301585a01
Bump eslint-plugin-jsdoc from 61.5.0 to 62.0.0
...
Bumps [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) from 61.5.0 to 62.0.0.
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.5.0...v62.0.0 )
---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
dependency-version: 62.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:52 +00:00
dependabot[bot]
c8914af920
Bump the npm-minor group with 7 updates
...
Bumps the npm-minor group with 7 updates:
| Package | From | To |
| --- | --- | --- |
| [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact ) | `5.0.1` | `5.0.2` |
| [@actions/cache](https://github.com/actions/toolkit/tree/HEAD/packages/cache ) | `5.0.1` | `5.0.2` |
| [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core ) | `2.0.1` | `2.0.2` |
| [@actions/http-client](https://github.com/actions/toolkit/tree/HEAD/packages/http-client ) | `3.0.0` | `3.0.1` |
| [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) | `2.0.0` | `2.0.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.52.0` | `8.53.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.52.0` | `8.53.0` |
Updates `@actions/artifact` from 5.0.1 to 5.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/artifact )
Updates `@actions/cache` from 5.0.1 to 5.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/cache/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/cache )
Updates `@actions/core` from 2.0.1 to 2.0.2
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core )
Updates `@actions/http-client` from 3.0.0 to 3.0.1
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/http-client/RELEASES.md )
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/http-client )
Updates `@eslint/compat` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.1/packages/compat )
Updates `@typescript-eslint/eslint-plugin` from 8.52.0 to 8.53.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.52.0 to 8.53.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.53.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@actions/artifact"
dependency-version: 5.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/cache"
dependency-version: 5.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/core"
dependency-version: 2.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@actions/http-client"
dependency-version: 3.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@eslint/compat"
dependency-version: 2.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.53.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.53.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-12 21:53:28 +00:00
Ian Lynagh
a2d9de63c2
Merge pull request #3395 from github/mergeback/v4.31.10-to-main-cdefb33c
...
Mergeback v4.31.10 refs/heads/releases/v4 into main
2026-01-12 15:23:02 +00:00
github-actions[bot]
4672d7807f
Rebuild
2026-01-12 14:39:48 +00:00
github-actions[bot]
be6e3c4480
Update changelog and version after v4.31.10
2026-01-12 14:34:39 +00:00
Ian Lynagh
cdefb33c0f
Merge pull request #3394 from github/update-v4.31.10-0fa411efd
...
Merge main into releases/v4
2026-01-12 14:32:55 +00:00
github-actions[bot]
cfa77c6b13
Update changelog for v4.31.10
2026-01-12 12:24:26 +00:00
Henry Mercer
79939d8ca5
Copy OIDs from DB cluster to individual DBs
2026-01-09 19:08:36 +00:00
Henry Mercer
d32cd4ddde
Include base database OIDs when bundling database
2026-01-09 18:58:32 +00:00
Henry Mercer
d6efb85cdf
Add tools feature for codeql database bundle --include
2026-01-09 18:50:12 +00:00
Ian Lynagh
0fa411efd0
Merge pull request #3393 from github/update-bundle/codeql-bundle-v2.23.9
...
Update default bundle to 2.23.9
2026-01-09 17:24:49 +00:00
github-actions[bot]
c284324212
Add changelog note
2026-01-09 16:41:42 +00:00
github-actions[bot]
83e7d0046c
Update default bundle to codeql-bundle-v2.23.9
2026-01-09 16:41:33 +00:00
Henry Mercer
f6a16bef8e
Merge pull request #3391 from github/dependabot/npm_and_yarn/npm-minor-f1cdf520b2
...
Bump the npm-minor group with 2 updates
2026-01-08 15:36:24 +00:00
github-actions[bot]
c1f5f1a8b5
Rebuild
2026-01-07 16:07:35 +00:00
dependabot[bot]
1805d8d0a4
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@typescript-eslint/eslint-plugin` from 8.51.0 to 8.52.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.52.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.51.0 to 8.52.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.52.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.52.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.52.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-07 16:05:56 +00:00
Henry Mercer
b2951d2a1e
Merge pull request #3353 from github/kaspersv/bump-min-cli-v-for-overlay
...
Overlay: Bump minimum CLI version for overlay
2026-01-06 16:44:27 +00:00
Henry Mercer
41448d92b9
Merge pull request #3287 from github/henrymercer/generate-mergeback-last
...
Open mergeback PR last
2026-01-06 12:16:00 +00:00
Michael B. Gale
a7fe4ffe40
Merge pull request #3387 from github/dependabot/npm_and_yarn/npm-minor-59ea988ea1
...
Bump the npm-minor group with 2 updates
2026-01-06 11:29:09 +00:00
Michael B. Gale
fd448f79eb
Merge pull request #3388 from github/dependabot/github_actions/dot-github/workflows/actions-minor-a0e46cd791
...
Bump ruby/setup-ruby from 1.275.0 to 1.278.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-05 21:28:14 +00:00
github-actions[bot]
079ca18961
Rebuild
2026-01-05 17:16:59 +00:00
github-actions[bot]
80dbba139d
Merge remote-tracking branch 'origin/main' into dependabot/github_actions/dot-github/workflows/actions-minor-a0e46cd791
2026-01-05 17:16:09 +00:00
dependabot[bot]
7edf2bd491
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.275.0 to 1.278.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/d354de180d0c9e813cfddfcbdc079945d4be589b...4c24fa5ec04b2e79eb40571b1cee2a0d2b705771 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.278.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-05 17:15:28 +00:00
Henry Mercer
db726913e9
Merge pull request #3386 from github/henrymercer/codeql-ff-improve-safety
...
Introduce a type-level check that CodeQL is passed during feature flag lookup if it is needed
2026-01-05 17:13:26 +00:00
github-actions[bot]
c327260b2b
Rebuild
2026-01-05 17:03:30 +00:00
dependabot[bot]
ce7b1f8663
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@typescript-eslint/eslint-plugin` from 8.50.0 to 8.51.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.51.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.50.0 to 8.51.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.51.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.51.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.51.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-01-05 17:01:55 +00:00
Henry Mercer
855c0888b6
Improve test for throwing when no CodeQL provided
2026-01-05 16:38:04 +00:00
Henry Mercer
ec1705eb43
Rebuild now type error fixed in main
2026-01-05 16:23:16 +00:00
Henry Mercer
29ee0e040d
Merge branch 'main' into henrymercer/codeql-ff-improve-safety
2026-01-05 16:22:46 +00:00
Henry Mercer
35d39dfdb3
Introduce type error when CodeQL is needed
2026-01-05 16:22:40 +00:00
Henry Mercer
66bcc86d07
Merge pull request #3385 from github/henrymercer/fix-ff-lookup
...
Fix feature flag lookup when uploading DB
2026-01-05 14:28:10 +00:00
Henry Mercer
44e589b637
Fix feature flag lookup when uploading DB
2026-01-05 14:07:03 +00:00
Henry Mercer
0d648eb4d1
Merge pull request #3380 from github/dependabot/github_actions/dot-github/workflows/actions-minor-b4688f1603
...
Bump ruby/setup-ruby from 1.270.0 to 1.275.0 in /.github/workflows in the actions-minor group across 1 directory
2026-01-05 13:44:11 +00:00
Henry Mercer
3fd7db80f0
Merge pull request #3379 from github/dependabot/npm_and_yarn/npm-minor-1607f6c1cd
...
Bump the npm-minor group with 4 updates
2026-01-05 13:41:32 +00:00
github-actions[bot]
6b11018e07
Rebuild
2025-12-22 17:18:17 +00:00
dependabot[bot]
d0d445f91c
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.270.0 to 1.275.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/ac793fdd38cc468a4dd57246fa9d0e868aba9085...d354de180d0c9e813cfddfcbdc079945d4be589b )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.275.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 17:16:43 +00:00
github-actions[bot]
60b2ba310b
Rebuild
2025-12-22 17:03:28 +00:00
dependabot[bot]
709d6de5f3
Bump the npm-minor group with 4 updates
...
Bumps the npm-minor group with 4 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ), [esbuild](https://github.com/evanw/esbuild ) and [sinon](https://github.com/sinonjs/sinon ).
Updates `@typescript-eslint/eslint-plugin` from 8.49.0 to 8.50.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.50.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.49.0 to 8.50.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.50.0/packages/parser )
Updates `esbuild` from 0.27.1 to 0.27.2
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.1...v0.27.2 )
Updates `sinon` from 21.0.0 to 21.0.1
- [Release notes](https://github.com/sinonjs/sinon/releases )
- [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md )
- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.0...v21.0.1 )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.50.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.50.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: sinon
dependency-version: 21.0.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 17:01:51 +00:00
Kasper Svendsen
efbc56d117
Overlay: Bump minimum CLI version for overlay
2025-12-19 11:25:46 +01:00
Henry Mercer
f67ec12472
Merge pull request #3370 from github/copilot/update-overlay-git-version-check
...
Add git version check for overlay analysis enablement
2025-12-18 15:47:40 +00:00
Henry Mercer
3b6fef64d5
Fix import order
2025-12-18 14:39:01 +00:00
Henry Mercer
8b428c0d4c
Use EnvVar
2025-12-18 14:34:50 +00:00
Henry Mercer
034401b281
Merge branch 'main' into copilot/update-overlay-git-version-check
2025-12-18 14:06:01 +00:00
Henry Mercer
95246ce019
Prefer explicit env var to binary accessibility check
2025-12-18 14:05:12 +00:00
Henry Mercer
525b64847a
Merge pull request #3374 from github/henrymercer/scan-debug-artifacts
...
CI: Perform a best-effort scan of the debug artifacts during release validation
2025-12-18 14:00:25 +00:00
Henry Mercer
a7e88a44f8
Only enable overlay for the code scanning suite
2025-12-18 13:06:44 +00:00
Henry Mercer
ff84c6f23c
Improve comment
2025-12-18 13:03:52 +00:00
Henry Mercer
948c7fbf11
Test mode: Tolerate missing git binary
2025-12-18 13:01:00 +00:00
Henry Mercer
cec3cc5782
Trim git version output
2025-12-18 12:52:30 +00:00
Henry Mercer
358a55e232
Throw in test mode if can't compute git version
2025-12-18 12:52:13 +00:00
Henry Mercer
eb823a7a97
Merge pull request #3375 from github/henrymercer/overlay-upload-tools-feature
...
Require tools feature for uploading overlay DBs
2025-12-18 12:43:26 +00:00
Henry Mercer
003ddaeef5
Avoid non-determinism in PR checks due to overlay FFs
2025-12-18 12:35:06 +00:00
Henry Mercer
a2c3c8e3e2
Bump log level for failing to parse git version
2025-12-17 17:28:13 +00:00
Henry Mercer
a13b404670
Record both truncated and full git versions
2025-12-17 17:27:14 +00:00
Henry Mercer
a2917b0733
Check !== undefined rather than truthiness
2025-12-17 16:27:36 +00:00
Henry Mercer
67e683bd1b
Report bundled DB size in error if known
2025-12-17 16:02:55 +00:00
Henry Mercer
cb26a026e5
Require tools feature for uploading overlay DBs
2025-12-17 16:02:26 +00:00
Henry Mercer
ac6c41b910
Extract zstd files too
2025-12-17 15:34:12 +00:00
Henry Mercer
056581e05b
Update makeTelemetryDiagnostic doc
2025-12-17 12:15:37 +00:00
Henry Mercer
9c5588d006
Remove unnecessary stub restores
2025-12-17 12:12:04 +00:00
Henry Mercer
3765106c90
Move git version logging to config utils
2025-12-17 12:06:41 +00:00
Henry Mercer
e052dbd57d
Remove caching mechanism
2025-12-17 11:56:23 +00:00
Henry Mercer
7673a2de65
Run testing Action using Node 24
2025-12-17 11:51:34 +00:00
Henry Mercer
32795b3c52
Merge branch 'main' into copilot/update-overlay-git-version-check
2025-12-17 11:49:32 +00:00
Henry Mercer
6b5763e5ee
Skip slow test on Windows
2025-12-17 11:47:39 +00:00
Henry Mercer
3322491022
Bump timeout on Windows
2025-12-17 11:41:55 +00:00
Henry Mercer
6bc6217487
Merge branch 'main' into henrymercer/scan-debug-artifacts
2025-12-17 11:36:38 +00:00
Henry Mercer
faf6d35e7b
Verify using post step
2025-12-17 11:35:26 +00:00
Henry Mercer
3b94cfeb15
Avoid logging each extract call
2025-12-17 11:35:26 +00:00
Henry Mercer
b88acb2f6c
Merge pull request #3359 from github/dependabot/npm_and_yarn/npm-minor-b2e0062778
...
Bump the npm-minor group with 3 updates
2025-12-17 11:04:55 +00:00
Henry Mercer
241948c698
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-b2e0062778
2025-12-17 10:38:55 +00:00
Henry Mercer
da77f9f638
Suppress debug logs for artifact scanner test
2025-12-17 10:25:48 +00:00
Henry Mercer
de172624a1
Slim down test debug artifacts
2025-12-17 10:25:48 +00:00
Henry Mercer
488c1f1959
Add regression test for artifact scanner
2025-12-17 10:25:48 +00:00
Henry Mercer
f2ccf3b4f1
Ensure .gz files are extracted too
2025-12-17 10:25:47 +00:00
Henry Mercer
f28848a66a
Use artifact scanner in debug artifacts PR checks
2025-12-17 10:25:47 +00:00
Henry Mercer
5459b98ca0
Add simple artifact scanner for tests only
2025-12-17 10:25:46 +00:00
Henry Mercer
0c8bfeaf84
Add artifact scanner
2025-12-17 10:25:46 +00:00
Henry Mercer
1fe89fe9cb
Merge pull request #3368 from github/copilot/bump-actions-npm-packages
...
Bump @actions/* npm packages to latest versions
2025-12-17 09:59:27 +00:00
Henry Mercer
6dba00881c
Merge pull request #3372 from github/mergeback/v4.31.9-to-main-5d4e8d1a
...
Mergeback v4.31.9 refs/heads/releases/v4 into main
2025-12-16 19:33:12 +00:00
github-actions[bot]
d4d47c0d3d
Rebuild
2025-12-16 18:56:12 +00:00
github-actions[bot]
6c6e810910
Update changelog and version after v4.31.9
2025-12-16 18:32:18 +00:00
Henry Mercer
5d4e8d1aca
Merge pull request #3371 from github/update-v4.31.9-998798e34
...
Merge main into releases/v4
2025-12-16 18:30:42 +00:00
github-actions[bot]
1dc115f17a
Update changelog for v4.31.9
2025-12-16 17:45:14 +00:00
Nick Rolfe
998798e34d
Merge pull request #3352 from github/nickrolfe/jar-min-ff-cleanup
...
Clean up `JavaMinimizeDependencyJars` feature flag
2025-12-16 17:25:23 +00:00
copilot-swe-agent[bot]
393c074965
Refactor existing telemetry diagnostics to use makeTelemetryDiagnostic
...
Refactored bundle-download-telemetry and zstd-availability diagnostics
in init-action.ts to use the new makeTelemetryDiagnostic helper function.
Also added guard for empty languages array in logGitVersionTelemetry.
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 17:24:57 +00:00
copilot-swe-agent[bot]
c3dc529aef
Address feedback: cache git version, improve error handling, add telemetry
...
- Cache the git version to avoid recomputing on repeated calls
- Refactor getGitVersion to getGitVersionOrThrow with detailed errors
- Add getGitVersion that logs errors and handles caching
- Add makeTelemetryDiagnostic helper to diagnostics.ts
- Add logGitVersionTelemetry function to log git version telemetry
- Call logGitVersionTelemetry in init-action.ts
- Add resetCachedGitVersion for testing
- Update tests to work with new function signatures and caching
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 17:19:46 +00:00
copilot-swe-agent[bot]
fc2bbb041e
Address code review feedback
...
- Add test for Windows-style git version format
- Add comment clarifying regex extracts major.minor.patch
- Replace dynamic import with static import for semver
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 16:27:41 +00:00
copilot-swe-agent[bot]
89753aa84b
Add git version check for overlay analysis enablement
...
Overlay analysis depends on `getFileOidsUnderPath`, which uses
`git ls-files --format` option that requires Git 2.38.0+. This
change adds a check for the git version before enabling overlay
analysis.
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 16:22:23 +00:00
Henry Mercer
5eb751966f
Merge pull request #3358 from github/henrymercer/database-upload-telemetry
...
Add status report for uploading databases to API
2025-12-16 16:18:52 +00:00
Nick Rolfe
d29eddb39b
Extract version number to constant
2025-12-16 16:17:52 +00:00
copilot-swe-agent[bot]
aff7998c4a
Initial plan
2025-12-16 16:09:09 +00:00
Henry Mercer
e9626872ef
Merge branch 'main' into henrymercer/database-upload-telemetry
2025-12-16 15:53:31 +00:00
Henry Mercer
19c7f96922
Rename isOverlayBase
2025-12-16 15:41:50 +00:00
Henry Mercer
ae5de9a20d
Use getErrorMessage in log too
2025-12-16 15:41:04 +00:00
Henry Mercer
0cb86337c5
Prefer performance.now()
2025-12-16 15:38:29 +00:00
Henry Mercer
c07cc0d3a9
Merge pull request #3351 from github/henrymercer/ghec-dr-determine-tools-version-from-ffs
...
Determine CodeQL version from feature flags on GHEC-DR
2025-12-16 13:42:01 +00:00
Henry Mercer
7a5748cf0d
Remove changelog note
2025-12-16 13:41:13 +00:00
copilot-swe-agent[bot]
db75d46248
Bump @actions/* npm packages to latest versions
...
Co-authored-by: henrymercer <14129055+henrymercer@users.noreply.github.com >
2025-12-16 13:34:51 +00:00
copilot-swe-agent[bot]
a0fc644617
Initial plan
2025-12-16 13:29:18 +00:00
Henry Mercer
a2ee53c0d3
Use full names for GitHub variants
2025-12-16 13:23:24 +00:00
Michael B. Gale
b5e1a28b8a
Merge pull request #3365 from github/dependabot/github_actions/dot-github/workflows/actions/download-artifact-7
...
Bump actions/download-artifact from 6 to 7 in /.github/workflows
2025-12-16 12:17:14 +00:00
Michael B. Gale
c2d4383e64
Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/download-artifact-7
2025-12-15 22:00:03 +00:00
Michael B. Gale
d0ad1da72a
Merge pull request #3364 from github/dependabot/github_actions/dot-github/workflows/actions-minor-8751820eb1
...
Bump ruby/setup-ruby from 1.269.0 to 1.270.0 in /.github/workflows in the actions-minor group across 1 directory
2025-12-15 21:08:40 +00:00
Michael B. Gale
07cd437640
Merge pull request #3366 from github/dependabot/github_actions/dot-github/workflows/actions/upload-artifact-6
...
Bump actions/upload-artifact from 5 to 6 in /.github/workflows
2025-12-15 18:18:05 +00:00
Michael B. Gale
a682bbe410
Merge pull request #3309 from github/mbg/ff/make-new-upload-default
...
Remove `AnalyzeUseNewUpload` FF and make its behaviour the default
2025-12-15 17:24:57 +00:00
github-actions[bot]
7fd7db3f26
Rebuild
2025-12-15 17:20:17 +00:00
github-actions[bot]
d6c1a791b7
Rebuild
2025-12-15 17:20:02 +00:00
dependabot[bot]
034374eb3f
Bump actions/upload-artifact from 5 to 6 in /.github/workflows
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:40 +00:00
dependabot[bot]
6dbc22c93f
Bump actions/download-artifact from 6 to 7 in /.github/workflows
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 6 to 7.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:32 +00:00
dependabot[bot]
a539068a61
Bump ruby/setup-ruby
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ).
Updates `ruby/setup-ruby` from 1.269.0 to 1.270.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/d697be2f83c6234b20877c3b5eac7a7f342f0d0c...ac793fdd38cc468a4dd57246fa9d0e868aba9085 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.270.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:18:28 +00:00
github-actions[bot]
e1058e4d74
Rebuild
2025-12-15 17:03:33 +00:00
dependabot[bot]
d4f39b0766
Bump the npm-minor group with 3 updates
...
Bumps the npm-minor group with 3 updates: [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js ), [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) and [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ).
Updates `@eslint/js` from 9.39.1 to 9.39.2
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/commits/v9.39.2/packages/js )
Updates `@typescript-eslint/eslint-plugin` from 8.48.1 to 8.49.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.49.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.48.1 to 8.49.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.49.0/packages/parser )
---
updated-dependencies:
- dependency-name: "@eslint/js"
dependency-version: 9.39.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.49.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.49.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-15 17:01:55 +00:00
Michael B. Gale
b30cb9ae2a
Merge branch 'main' into mbg/ff/make-new-upload-default
2025-12-15 16:28:30 +00:00
Michael B. Gale
009fe6b0c1
Remove AnalyzeUseNewUpload FF
2025-12-15 16:27:29 +00:00
Michael B. Gale
b1dea65f65
Make postProcessAndUploadSarif the default
2025-12-15 16:27:19 +00:00
Henry Mercer
7e0b77e3a8
Merge pull request #3349 from github/dependabot/github_actions/dot-github/workflows/actions-minor-dc476f2f5b
...
Bump the actions-minor group across 1 directory with 2 updates
2025-12-15 15:38:25 +00:00
Henry Mercer
0264b51610
Merge pull request #3348 from github/dependabot/npm_and_yarn/npm-minor-38a2a793c5
...
Bump the npm-minor group with 5 updates
2025-12-15 15:37:54 +00:00
Henry Mercer
2ac846d41e
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-38a2a793c5
2025-12-15 14:12:45 +00:00
Henry Mercer
5d063dd3af
Populate database upload results telemetry
2025-12-15 12:55:12 +00:00
Henry Mercer
8e921c3145
Return status report from cleanupAndUploadDatabases
2025-12-15 12:55:12 +00:00
Óscar San José
4b675e451b
Merge pull request #3356 from github/mergeback/v4.31.8-to-main-1b168cd3
...
Mergeback v4.31.8 refs/heads/releases/v4 into main
2025-12-12 10:48:29 +01:00
github-actions[bot]
65bad627f3
Rebuild
2025-12-12 08:52:54 +00:00
github-actions[bot]
4564f5e482
Update changelog and version after v4.31.8
2025-12-12 08:44:31 +00:00
Óscar San José
1b168cd394
Merge pull request #3355 from github/update-v4.31.8-1b0b941e1
...
Merge main into releases/v4
2025-12-12 09:43:00 +01:00
github-actions[bot]
120f277b16
Update changelog for v4.31.8
2025-12-11 17:23:34 +00:00
Óscar San José
1b0b941e1f
Merge pull request #3354 from github/update-bundle/codeql-bundle-v2.23.8
...
Update default bundle to 2.23.8
2025-12-11 17:25:18 +01:00
github-actions[bot]
db812c1ae6
Add changelog note
2025-12-11 15:46:24 +00:00
github-actions[bot]
2930dba17a
Update default bundle to codeql-bundle-v2.23.8
2025-12-11 15:46:14 +00:00
Nick Rolfe
805b7e1790
Clean up JavaMinimizeDependencyJars feature flag
2025-12-11 10:46:56 +00:00
Henry Mercer
da501245d4
Update PR template to include GHEC-DR
2025-12-10 17:41:20 +00:00
Henry Mercer
1fc7d3785d
Rename GHE_DOTCOM to GHEC_DR
...
This more closely reflects the published naming https://docs.github.com/en/enterprise-cloud@latest/admin/data-residency/about-github-enterprise-cloud-with-data-residency
2025-12-10 17:41:19 +00:00
Henry Mercer
7a55ffeaf1
Determine CodeQL version from feature flags on GHEC-DR
2025-12-10 17:35:27 +00:00
Kasper Svendsen
c43362b91a
Merge pull request #3340 from github/kaspersv/check-for-overlayBaseSpecifier
...
Overlay: Check database metadata for overlayBaseSpecifier
2025-12-09 11:37:30 +01:00
Kasper Svendsen
002a7f25fd
Overlay: log overlayBaseSpecifier at debug log-level
2025-12-09 09:44:56 +01:00
Kasper Svendsen
5b7e7fcc9c
Update src/codeql.ts
...
Co-authored-by: Henry Mercer <henrymercer@github.com >
2025-12-09 09:41:33 +01:00
github-actions[bot]
cd48547da5
Rebuild
2025-12-08 17:18:17 +00:00
dependabot[bot]
44570be32d
Bump the actions-minor group across 1 directory with 2 updates
...
Bumps the actions-minor group with 2 updates in the /.github/workflows directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) and [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `ruby/setup-ruby` from 1.268.0 to 1.269.0
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/8aeb6ff8030dd539317f8e1769a044873b56ea71...d697be2f83c6234b20877c3b5eac7a7f342f0d0c )
Updates `actions/create-github-app-token` from 2.2.0 to 2.2.1
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.2.0...v2.2.1 )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.269.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
- dependency-name: actions/create-github-app-token
dependency-version: 2.2.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-08 17:16:45 +00:00
github-actions[bot]
b73d396b48
Rebuild
2025-12-08 17:03:51 +00:00
dependabot[bot]
0ffebf72b2
Bump the npm-minor group with 5 updates
...
Bumps the npm-minor group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [node-forge](https://github.com/digitalbazaar/forge ) | `1.3.2` | `1.3.3` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.48.0` | `8.48.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.48.0` | `8.48.1` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.27.0` | `0.27.1` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ) | `61.4.1` | `61.5.0` |
Updates `node-forge` from 1.3.2 to 1.3.3
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.2...v1.3.3 )
Updates `@typescript-eslint/eslint-plugin` from 8.48.0 to 8.48.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.48.0 to 8.48.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.1/packages/parser )
Updates `esbuild` from 0.27.0 to 0.27.1
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.0...v0.27.1 )
Updates `eslint-plugin-jsdoc` from 61.4.1 to 61.5.0
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.4.1...v61.5.0 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.3.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.48.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.48.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: esbuild
dependency-version: 0.27.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-08 17:02:12 +00:00
Óscar San José
149d184a51
Merge pull request #3345 from github/mergeback/v4.31.7-to-main-cf1bb45a
...
Mergeback v4.31.7 refs/heads/releases/v4 into main
2025-12-05 21:43:41 +01:00
github-actions[bot]
97c2630b10
Rebuild
2025-12-05 17:21:46 +00:00
github-actions[bot]
b93926dc35
Update changelog and version after v4.31.7
2025-12-05 17:19:09 +00:00
Óscar San José
cf1bb45a27
Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
...
Merge main into releases/v4
2025-12-05 18:17:21 +01:00
github-actions[bot]
f4ebe95061
Update changelog for v4.31.7
2025-12-05 15:18:53 +00:00
Óscar San José
f5c63fadd5
Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
...
Update default bundle to 2.23.7
2025-12-05 15:06:47 +01:00
github-actions[bot]
a2c01e776e
Add changelog note
2025-12-05 13:39:53 +00:00
github-actions[bot]
ac34c13834
Update default bundle to codeql-bundle-v2.23.7
2025-12-05 13:39:45 +00:00
Michael B. Gale
267c4672a5
Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d26487b0
...
Bump @eslint/eslintrc from 3.3.1 to 3.3.3 in the npm-minor group
2025-12-03 14:27:03 +00:00
Michael B. Gale
aeabef7b69
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
2025-12-03 12:43:12 +00:00
Kasper Svendsen
c4efbda299
Overlay: Check database metadata for overlayBaseSpecifier
2025-12-03 13:40:24 +01:00
Kasper Svendsen
dd8914320f
CodeQL: Add resolveDatabase method
2025-12-03 13:40:24 +01:00
Michael B. Gale
78357d3fc9
Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
...
Update CLI config test to account for overlay db changes on PRs
2025-12-03 12:39:49 +00:00
Michael B. Gale
d61a6fa793
Update CLI config test to account for overlay db changes on PRs
2025-12-03 12:11:11 +00:00
github-actions[bot]
ce27e95f79
Rebuild
2025-12-01 18:32:19 +00:00
dependabot[bot]
43224eb34e
Bump @eslint/eslintrc from 3.3.1 to 3.3.3 in the npm-minor group
...
Bumps the npm-minor group with 1 update: [@eslint/eslintrc](https://github.com/eslint/eslintrc ).
Updates `@eslint/eslintrc` from 3.3.1 to 3.3.3
- [Release notes](https://github.com/eslint/eslintrc/releases )
- [Changelog](https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md )
- [Commits](https://github.com/eslint/eslintrc/compare/v3.3.1...eslintrc-v3.3.3 )
---
updated-dependencies:
- dependency-name: "@eslint/eslintrc"
dependency-version: 3.3.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-01 18:30:33 +00:00
Michael B. Gale
f0ac9bfbe3
Merge pull request #3337 from github/mergeback/v4.31.6-to-main-fe4161a2
...
Mergeback v4.31.6 refs/heads/releases/v4 into main
2025-12-01 10:18:06 +00:00
github-actions[bot]
c1ca379fc0
Rebuild
2025-12-01 09:55:25 +00:00
github-actions[bot]
c3455c55c1
Update changelog and version after v4.31.6
2025-12-01 09:50:22 +00:00
Michael B. Gale
fe4161a26a
Merge pull request #3336 from github/update-v4.31.6-ecec1f887
...
Merge main into releases/v4
2025-12-01 09:48:24 +00:00
github-actions[bot]
88c2ab5eee
Update changelog for v4.31.6
2025-12-01 09:26:09 +00:00
Michael B. Gale
ecec1f8876
Merge pull request #3335 from github/mbg/ci/run-codeql-on-all-prs
...
Remove branch filter for PR event in CodeQL workflow
2025-11-28 12:19:33 +00:00
Kasper Svendsen
23da732778
Merge pull request #3334 from github/kaspersv/overlay-minor-comments
...
Overlay: Small code improvements
2025-11-28 10:26:32 +01:00
Michael B. Gale
f7abc748a3
Remove branch filter for PR event in CodeQL workflow
2025-11-28 09:13:23 +00:00
Kasper Svendsen
32ada5e061
Merge branch 'main' into kaspersv/overlay-minor-comments
2025-11-28 10:02:55 +01:00
Kasper Svendsen
75b2f49aea
Merge pull request #3333 from github/kaspersv/overlay-no-resource-checks-option
...
Overlay: Add feature flag to skip resource checks
2025-11-28 10:01:21 +01:00
Kasper Svendsen
f036b1cb78
Merge branch 'main' into kaspersv/overlay-no-resource-checks-option
2025-11-28 09:44:11 +01:00
Kasper Svendsen
58c5954801
Add comment to runnerSupportsOverlayAnalysis
2025-11-27 15:56:29 +01:00
Kasper Svendsen
b02fa13292
Order feature flags alphabetically
2025-11-27 15:56:29 +01:00
Kasper Svendsen
8d91fa189d
Rename getMemoryFlagValue
2025-11-27 15:56:29 +01:00
Kasper Svendsen
2f3bbce9a6
Overlay: Introduce overlay memory limit constant
2025-11-27 15:33:57 +01:00
Kasper Svendsen
c178e03ec8
Merge pull request #3332 from github/kaspersv/overlay-memory-limit
...
Overlay: Fall back to full analysis if memory flag is low
2025-11-27 15:26:02 +01:00
Henry Mercer
d29b97960c
Merge pull request #3331 from github/dependabot/npm_and_yarn/node-forge-1.3.2
...
Bump node-forge from 1.3.1 to 1.3.2
2025-11-27 11:44:32 +00:00
Kasper Svendsen
1ffb7dd0c8
Overlay: Add feature flag to skip resource checks
2025-11-27 12:30:23 +01:00
Kasper Svendsen
bd8d26b618
Overlay: Fall back to full analysis if memory flag is low
2025-11-27 09:16:35 +01:00
Kasper Svendsen
bd30e753a6
Simplify getOverlayDatabaseMode
2025-11-27 08:34:43 +01:00
github-actions[bot]
4822f934e3
Rebuild
2025-11-26 22:34:54 +00:00
dependabot[bot]
0c204fc557
Bump node-forge from 1.3.1 to 1.3.2
...
Bumps [node-forge](https://github.com/digitalbazaar/forge ) from 1.3.1 to 1.3.2.
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md )
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.1...v1.3.2 )
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: 1.3.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-26 22:33:20 +00:00
Michael B. Gale
59ce4c1340
Merge pull request #3286 from github/mbg/csharp/more-cache-locations
...
C#: Cache temporary dependency directory for BMN
2025-11-26 14:36:58 +00:00
Henry Mercer
3e939667ec
Merge branch 'main' into mbg/csharp/more-cache-locations
2025-11-26 14:12:07 +00:00
Michael B. Gale
7850b1c983
Merge pull request #3330 from github/mbg/ci/remove-push-from-groups
...
Remove `push` triggers from workflow collections
2025-11-26 10:52:53 +00:00
Henry Mercer
c370017ae8
Merge pull request #3325 from github/dependabot/npm_and_yarn/npm-minor-45ea8d913b
...
Bump the npm-minor group with 3 updates
2025-11-26 10:34:47 +00:00
Michael B. Gale
a6909455e4
Remove push triggers from workflow collections
2025-11-26 10:27:48 +00:00
github-actions[bot]
510d25ff7f
Rebuild
2025-11-26 10:15:27 +00:00
github-actions[bot]
85fd3e57b5
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_yarn/npm-minor-45ea8d913b
2025-11-26 10:14:31 +00:00
Henry Mercer
d8e497a759
Update version in package.json too
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-11-26 10:13:41 +00:00
Henry Mercer
99d80b4ea7
Merge pull request #3328 from github/update-supported-enterprise-server-versions
...
Update supported GitHub Enterprise Server versions
2025-11-26 10:12:59 +00:00
Michael B. Gale
0155561719
Merge branch 'main' into mbg/csharp/more-cache-locations
2025-11-26 10:01:51 +00:00
github-actions[bot]
6b7e963cf1
Update supported GitHub Enterprise Server versions
2025-11-26 00:18:14 +00:00
Michael B. Gale
0e52774aee
Merge pull request #3326 from github/dependabot/github_actions/dot-github/workflows/actions-minor-8ee81fe642
...
Bump actions/create-github-app-token from 2.1.4 to 2.2.0 in /.github/workflows in the actions-minor group across 1 directory
2025-11-25 11:45:44 +00:00
Michael B. Gale
62e90525a0
Merge pull request #3327 from github/dependabot/github_actions/dot-github/workflows/actions/checkout-6
...
Bump actions/checkout from 5 to 6 in /.github/workflows
2025-11-25 11:20:57 +00:00
github-actions[bot]
8484f54a0a
Rebuild
2025-11-24 18:02:41 +00:00
dependabot[bot]
5bd8069afb
Bump actions/checkout from 5 to 6 in /.github/workflows
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 18:01:10 +00:00
dependabot[bot]
6feac2b36a
Bump actions/create-github-app-token
...
Bumps the actions-minor group with 1 update in the /.github/workflows directory: [actions/create-github-app-token](https://github.com/actions/create-github-app-token ).
Updates `actions/create-github-app-token` from 2.1.4 to 2.2.0
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Commits](https://github.com/actions/create-github-app-token/compare/v2.1.4...v2.2.0 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 2.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 17:59:04 +00:00
github-actions[bot]
514279113a
Rebuild
2025-11-24 17:38:19 +00:00
dependabot[bot]
e2a623d7cf
Bump the npm-minor group with 3 updates
...
Bumps the npm-minor group with 3 updates: [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ), [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@typescript-eslint/eslint-plugin` from 8.46.4 to 8.48.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.46.4 to 8.48.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.48.0/packages/parser )
Updates `eslint-plugin-jsdoc` from 61.2.1 to 61.4.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Changelog](https://github.com/gajus/eslint-plugin-jsdoc/blob/main/.releaserc )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.2.1...v61.4.1 )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.48.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.48.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.4.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-24 17:36:24 +00:00
Paolo Tranquilli
52f930e50a
Merge pull request #3323 from github/mergeback/v4.31.5-to-main-fdbfb4d2
...
Mergeback v4.31.5 refs/heads/releases/v4 into main
2025-11-24 12:18:45 +01:00
github-actions[bot]
478350182f
Rebuild
2025-11-24 10:55:14 +00:00
github-actions[bot]
29e11fdce1
Update changelog and version after v4.31.5
2025-11-24 09:31:18 +00:00
Paolo Tranquilli
fdbfb4d275
Merge pull request #3322 from github/update-v4.31.5-ec2ee575c
...
Merge main into releases/v4
2025-11-24 10:29:19 +01:00
github-actions[bot]
81f6d649ae
Update changelog for v4.31.5
2025-11-24 09:03:58 +00:00
Paolo Tranquilli
ec2ee575c0
Merge pull request #3321 from github/update-bundle/codeql-bundle-v2.23.6
...
Update default bundle to 2.23.6
2025-11-24 09:14:29 +01:00
github-actions[bot]
ecc87875ee
Add changelog note
2025-11-24 07:51:53 +00:00
github-actions[bot]
1d2a238d7d
Update default bundle to codeql-bundle-v2.23.6
2025-11-24 07:51:46 +00:00
Michael B. Gale
b4db38273c
Add generated files to paths-ignore, if FF is enabled
2025-11-19 19:42:18 +00:00
Michael B. Gale
846f8590dc
Add IgnoreGeneratedFiles FF
2025-11-19 19:10:42 +00:00
Michael B. Gale
3eaf00092b
Add isCCR helper, and update isDefaultSetup
2025-11-19 19:07:21 +00:00
Michael B. Gale
1512f400b3
Add function to query git for all generated files
2025-11-19 15:35:46 +00:00
Henry Mercer
ce729e4d35
Merge pull request #3315 from github/henrymercer/dead-code-elimination
...
Delete unused exports
2025-11-19 15:24:22 +00:00
Henry Mercer
ac359aad20
Add return type
2025-11-19 14:59:16 +00:00
Henry Mercer
112cd075bd
Merge branch 'main' into henrymercer/dead-code-elimination
2025-11-19 14:56:28 +00:00
Michael B. Gale
0b4317954f
Merge pull request #3306 from github/dependabot/npm_and_yarn/types/sinon-21.0.0
...
Bump @types/sinon from 17.0.4 to 21.0.0
2025-11-19 14:13:16 +00:00
Michael B. Gale
e818008b54
Merge pull request #3305 from github/dependabot/npm_and_yarn/eslint/compat-2.0.0
...
Bump @eslint/compat from 1.4.1 to 2.0.0
2025-11-19 13:41:43 +00:00
Michael B. Gale
90871e185b
Merge pull request #3304 from github/dependabot/npm_and_yarn/npm-minor-7439af33e4
...
Bump the npm-minor group with 2 updates
2025-11-19 13:18:38 +00:00
Kasper Svendsen
a102014397
Merge pull request #3317 from github/kaspersv/bump-minimum-overlay-version
...
Overlay: Increase minimum CLI version required for overlay analysis
2025-11-19 14:18:24 +01:00
Kasper Svendsen
de74d762a3
Overlay: Increase minimum CLI version
2025-11-19 13:04:23 +01:00
Kasper Svendsen
ce07e7d196
Merge pull request #3310 from github/kaspersv/overlay-disk-available-limit
...
Overlay: Fall back to full analysis if runner disk space is low
2025-11-19 12:57:53 +01:00
Henry Mercer
86d2aa55c0
Merge pull request #3316 from github/henrymercer/upload-overlay-to-api
...
Upload overlay base DBs to GitHub API behind FF
2025-11-19 10:29:28 +00:00
Kasper Svendsen
4eccb3798e
Overlay: Round available disk space in MB
2025-11-19 08:40:56 +01:00
Kasper Svendsen
ed80d6e5e9
Overlay: Reorder available disk space check
2025-11-19 07:54:05 +01:00
Henry Mercer
378219ced2
Merge pull request #3313 from github/mergeback/v4.31.4-to-main-e12f0178
...
Mergeback v4.31.4 refs/heads/releases/v4 into main
2025-11-18 18:46:24 +00:00
Henry Mercer
c649c5993d
Upload overlay base DB to API behind FF
2025-11-18 18:43:19 +00:00
Henry Mercer
31042e9879
Rename function calls to make destructive operation clearer
2025-11-18 18:42:15 +00:00
Henry Mercer
5da2098551
Add feature flag for uploading overlay DBs to API
2025-11-18 18:40:51 +00:00
Henry Mercer
cac5926de5
Delete unused exports
2025-11-18 18:16:54 +00:00
Henry Mercer
e24190a70c
Remove unused dependencies
2025-11-18 18:14:49 +00:00
github-actions[bot]
ce9b526448
Rebuild
2025-11-18 16:17:35 +00:00
github-actions[bot]
28f4a61417
Merge remote-tracking branch 'origin/main' into mergeback/v4.31.4-to-main-e12f0178
2025-11-18 16:16:46 +00:00
github-actions[bot]
fea250010c
Update changelog and version after v4.31.4
2025-11-18 16:14:11 +00:00
Michael B. Gale
249458aab2
Merge pull request #3296 from github/mbg/dependency-caching/skip-uploads-for-exact-matches
...
Skip uploading dependency caches if we know they exist
2025-11-18 15:44:06 +00:00
Henry Mercer
7bb4bfc7c2
Merge branch 'main' into henrymercer/generate-mergeback-last
2025-11-18 15:03:11 +00:00
Kasper Svendsen
726a2a01b8
Overlay: Increase disk storage threshold to 20GB
2025-11-18 15:37:27 +01:00
Kasper Svendsen
4f746e4a60
Overlay: Fall back to full analysis if runner disk space is low
2025-11-18 08:19:13 +01:00
github-actions[bot]
b595847fa5
Rebuild
2025-11-17 17:04:50 +00:00
github-actions[bot]
4f39cef4c6
Rebuild
2025-11-17 17:03:39 +00:00
github-actions[bot]
d4a7ccd1f0
Rebuild
2025-11-17 17:03:22 +00:00
dependabot[bot]
cd808e1260
Bump @types/sinon from 17.0.4 to 21.0.0
...
Bumps [@types/sinon](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sinon ) from 17.0.4 to 21.0.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sinon )
---
updated-dependencies:
- dependency-name: "@types/sinon"
dependency-version: 21.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:02:13 +00:00
dependabot[bot]
01577d4797
Bump @eslint/compat from 1.4.1 to 2.0.0
...
Bumps [@eslint/compat](https://github.com/eslint/rewrite/tree/HEAD/packages/compat ) from 1.4.1 to 2.0.0.
- [Release notes](https://github.com/eslint/rewrite/releases )
- [Changelog](https://github.com/eslint/rewrite/blob/main/packages/compat/CHANGELOG.md )
- [Commits](https://github.com/eslint/rewrite/commits/compat-v2.0.0/packages/compat )
---
updated-dependencies:
- dependency-name: "@eslint/compat"
dependency-version: 2.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:01:53 +00:00
dependabot[bot]
3b635815d6
Bump the npm-minor group with 2 updates
...
Bumps the npm-minor group with 2 updates: [@octokit/request-error](https://github.com/octokit/request-error.js ) and [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc ).
Updates `@octokit/request-error` from 7.0.2 to 7.1.0
- [Release notes](https://github.com/octokit/request-error.js/releases )
- [Commits](https://github.com/octokit/request-error.js/compare/v7.0.2...v7.1.0 )
Updates `eslint-plugin-jsdoc` from 61.1.12 to 61.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases )
- [Changelog](https://github.com/gajus/eslint-plugin-jsdoc/blob/main/.releaserc )
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v61.1.12...v61.2.1 )
---
updated-dependencies:
- dependency-name: "@octokit/request-error"
dependency-version: 7.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: npm-minor
- dependency-name: eslint-plugin-jsdoc
dependency-version: 61.2.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-11-17 17:01:47 +00:00
Michael B. Gale
1ed85b4501
Add test coverage for uploadDependencyCaches
2025-11-14 14:30:54 +00:00
Michael B. Gale
51c9af3a3b
Don't try to upload cache if we have restored a cache with the same key
2025-11-14 14:30:54 +00:00
Michael B. Gale
594c0cc369
Store restored keys in action state
2025-11-14 14:30:54 +00:00
Michael B. Gale
11889c27fd
Return keys of restored caches from downloadDependencyCaches
2025-11-14 14:30:54 +00:00
Henry Mercer
6678cee8aa
Merge branch 'main' into henrymercer/generate-mergeback-last
2025-11-13 21:06:03 +00:00
Henry Mercer
79e9b8a130
Open mergeback PR last
...
This reduces the likelihood of publishing a tag but not a release.
2025-11-13 17:23:45 +00:00
Michael B. Gale
f5f9571d61
Configure temp dependency dir for C# extractor when FF is enabled
...
And also clean it up.
2025-11-13 14:03:44 +00:00
Michael B. Gale
ecaa6db95a
Include getCsharpTempDependencyDir in C# caches if FF is enabled
2025-11-13 13:40:58 +00:00
Michael B. Gale
a47d04cf9b
Add FF for extra C# cache contents
2025-11-13 13:40:57 +00:00
Michael B. Gale
d854ba6ec0
Pass FeatureEnablement to getDependencyPaths
2025-11-13 13:40:57 +00:00
Michael B. Gale
cf8b7a6e14
Refactor C# cache content paths into a function
2025-11-13 13:40:56 +00:00
Kasper Svendsen
4eb247591f
Move conversion of PR diff-range paths to absolute paths
2025-11-12 08:10:40 +01:00
Kasper Svendsen
df4e1992c0
Add unit test for diffRangeExtensionPackContents
2025-11-12 08:10:40 +01:00
Kasper Svendsen
d18f3acf74
Move diff-range extension pack generation into testable function
2025-11-12 08:10:39 +01:00
Kasper Svendsen
035c1179af
upload-lib: Unit test filterAlertsByDiffRange
2025-11-12 08:10:39 +01:00