Skip to content

Releases: github/codeql-action

v4.36.1

02 Jun 10:09
Immutable release. Only release title and notes can be modified.
87557b9

Choose a tag to compare

No user facing changes.

v3.36.1

02 Jun 10:37
Immutable release. Only release title and notes can be modified.
d77b13a

Choose a tag to compare

No user facing changes.

v4.36.0

22 May 11:07
Immutable release. Only release title and notes can be modified.
7211b7c

Choose a tag to compare

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893
  • Update default CodeQL bundle version to 2.25.5. #3926

v3.36.0

22 May 11:28
Immutable release. Only release title and notes can be modified.
03e4368

Choose a tag to compare

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
  • Add support for SHA-256 Git object IDs. #3893
  • Update default CodeQL bundle version to 2.25.5. #3926

CodeQL Bundle v2.25.5

22 May 10:16
Immutable release. Only release title and notes can be modified.
8449852

Choose a tag to compare

Bundles CodeQL CLI v2.25.5

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.25.5:

v4.35.5

15 May 11:24
Immutable release. Only release title and notes can be modified.
9e0d7b8

Choose a tag to compare

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880

v3.35.5

15 May 12:42
Immutable release. Only release title and notes can be modified.
458d36d

Choose a tag to compare

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880

v3.35.4

08 May 06:21
Immutable release. Only release title and notes can be modified.
7fd177f

Choose a tag to compare

  • Update default CodeQL bundle version to 2.25.4. #3881

v4.35.4

07 May 15:54
Immutable release. Only release title and notes can be modified.
68bde55

Choose a tag to compare

  • Update default CodeQL bundle version to 2.25.4. #3881

CodeQL Bundle v2.25.4

07 May 12:47
Immutable release. Only release title and notes can be modified.
bc0b696

Choose a tag to compare

Bundles CodeQL CLI v2.25.4

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.25.4: