Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump github/codeql-action from 2 to 3 #2283

Merged
merged 1 commit into from
Mar 26, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 26, 2024

Bumps github/codeql-action from 2 to 3.

Release notes

Sourced from github/codeql-action's releases.

CodeQL Bundle v2.16.6

Bundles CodeQL CLI v2.16.6

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.16.6:

CodeQL Bundle v2.16.5

Bundles CodeQL CLI v2.16.5

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.16.5:

CodeQL Bundle v2.16.4

Bundles CodeQL CLI v2.16.4

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.16.4:

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

3.24.9 - 22 Mar 2024

  • Update default CodeQL bundle version to 2.16.5. #2203

3.24.8 - 18 Mar 2024

  • Improve the ease of debugging extraction issues by increasing the verbosity of the extractor logs when running in debug mode. #2195

3.24.7 - 12 Mar 2024

  • Update default CodeQL bundle version to 2.16.4. #2185

3.24.6 - 29 Feb 2024

No user facing changes.

3.24.5 - 23 Feb 2024

  • Update default CodeQL bundle version to 2.16.3. #2156

3.24.4 - 21 Feb 2024

  • Fix an issue where an existing, but empty, /sys/fs/cgroup/cpuset.cpus file always resulted in a single-threaded run. #2151

3.24.3 - 15 Feb 2024

  • Fix an issue where the CodeQL Action would fail to load a configuration specified by the config input to the init Action. #2147

3.24.2 - 15 Feb 2024

  • Enable improved multi-threaded performance on larger runners for GitHub Enterprise Server users. This feature is already available to GitHub.com users. #2141

3.24.1 - 13 Feb 2024

  • Update default CodeQL bundle version to 2.16.2. #2124
  • The CodeQL action no longer fails if it can't write to the telemetry api endpoint. #2121

3.24.0 - 02 Feb 2024

  • CodeQL Python analysis will no longer install dependencies on GitHub Enterprise Server, as is already the case for GitHub.com. See release notes for 3.23.0 for more details. #2106

3.23.2 - 26 Jan 2024

  • On Linux, the maximum possible value for the --threads option now respects the CPU count as specified in cgroup files to more accurately reflect the number of available cores when running in containers. #2083
  • Update default CodeQL bundle version to 2.16.1. #2096

3.23.1 - 17 Jan 2024

  • Update default CodeQL bundle version to 2.16.0. #2073
  • Change the retention period for uploaded debug artifacts to 7 days. Previously, this was whatever the repository default was. #2079

... (truncated)

Commits
  • 4b2a786 Update changelog and version after v3.24.8
  • 05963f4 Merge pull request #2200 from github/update-v3.24.8-1ecc2779e
  • 2b9b521 Update changelog for v3.24.8
  • 1ecc277 Merge pull request #2198 from github/henrymercer/improve-tracking-autobuild-e...
  • e28ae3a Add config error for Swift build failures
  • bddfc7c Add config error for Gradle build failures
  • 3edd1bf Truncate autobuild errors to 10 lines
  • 88a0b7a Mark Maven build failures as configuration errors
  • 88b28eb Surface autobuild errors from stderr stream
  • f055b5e Merge pull request #2197 from github/henrymercer/log-job-status
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2 to 3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v2...v3)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Mar 26, 2024
@tekton-robot
Copy link
Contributor

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a tektoncd member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@tekton-robot tekton-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 26, 2024
@piyush-garg
Copy link
Contributor

/approve
/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Mar 26, 2024
@tekton-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: piyush-garg

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 26, 2024
@piyush-garg
Copy link
Contributor

/test pull-tekton-cli-integration-tests

@tekton-robot tekton-robot merged commit e519a8a into main Mar 26, 2024
8 checks passed
@dependabot dependabot bot deleted the dependabot/github_actions/github/codeql-action-3 branch March 26, 2024 10:42
piyush-garg added a commit that referenced this pull request May 13, 2024
#2281 | [Piyush Garg] Add 0.35.2 in LTS doc | 2024/03/26-00:24
#2282 | [Piyush Garg] Enable dependabot on github actions | 2024/03/26-09:04
#2284 | [dependabot[bot]] Bump actions/checkout from 2 to 4 | 2024/03/26-09:32
#2283 | [dependabot[bot]] Bump github/codeql-action from 2 to 3 | 2024/03/26-10:42
#2285 | [Piyush Garg] Fix codeql github action | 2024/03/27-15:42
#2286 | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.57.1 to 1.57.2 in /tools | 2024/03/31-20:40
#2288 | [dependabot[bot]] Bump golang.org/x/term from 0.18.0 to 0.19.0 | 2024/04/06-04:01
#2289 | [dependabot[bot]] Bump github.com/docker/docker | 2024/04/15-12:57
#2290 | [dependabot[bot]] Bump github.com/docker/cli | 2024/04/15-14:39
#2291 | [Piyush Garg] Bump sigstore to v1.8.3 | 2024/04/16-04:49
null | [dependabot[bot]] Bump github.com/sigstore/cosign/v2 from 2.2.2 to 2.2.4 | 2024/04/16-12:41
null | [dependabot[bot]] Bump github.com/docker/docker | 2024/04/19-19:19
null | [dependabot[bot]] Bump github.com/docker/cli | 2024/04/19-20:01
null | [dependabot[bot]] Bump golang.org/x/net from 0.22.0 to 0.23.0 | 2024/04/22-07:23
null | [dependabot[bot]] Bump github.com/docker/cli | 2024/04/25-05:15
null | [dependabot[bot]] Bump github.com/docker/docker | 2024/04/25-09:47
null | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.58.0 to 0.59.0 | 2024/04/29-03:47
null | [dependabot[bot]] Bump github.com/tektoncd/triggers from 0.26.1 to 0.26.2 | 2024/04/30-19:55
null | [dependabot[bot]] Bump github.com/docker/cli | 2024/05/01-21:15
null | [dependabot[bot]] Bump github.com/docker/docker | 2024/05/01-21:53
null | [Chmouel Boudjnah] Add -E flag to exit with the pr sate on unix shell | 2024/05/06-16:30
null | [dependabot[bot]] Bump golang.org/x/term from 0.19.0 to 0.20.0 | 2024/05/07-04:38
null | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.57.2 to 1.58.0 in /tools | 2024/05/07-07:08
null | [Piyush Garg] Bump k8s.io deps to match with tektoncd/pipeline | 2024/05/08-02:00
null | [Piyush Garg] Bump golangci-lint to v0.58.0 | 2024/05/08-06:34
null | [Piyush Garg] Group docker dep updates | 2024/05/08-08:16
null | [dependabot[bot]] Bump k8s.io/cli-runtime from 0.28.5 to 0.28.9 | 2024/05/08-09:08
null | [Piyush Garg] Bump k8s.io/apimachinery to v0.28.9 | 2024/05/08-11:16
null | [Piyush Garg] Group all k8s dep together | 2024/05/08-11:16
null | [Piyush Garg] Bump go version to 1.22 | 2024/05/08-17:36
null | [Piyush Garg] Bump goreleaser for latest v1.25.1 | 2024/05/08-17:36
null | [dependabot[bot]] Bump github.com/tektoncd/hub from 1.16.0 to 1.17.0 | 2024/05/08-20:12
null | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.58.0 to 1.58.1 in /tools | 2024/05/09-05:58
null | [dependabot[bot]] Bump the go-docker-dependencies group with 2 updates | 2024/05/09-12:38
null | [dependabot[bot]] Bump github.com/tektoncd/triggers from 0.26.2 to 0.27.0 | 2024/05/10-19:00

Signed-off-by: Piyush Garg <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants