Sourced from github/codeql-action's releases.
v4.30.9
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.30.9 - 17 Oct 2025
- Update default CodeQL bundle version to 2.23.3. #3205
- Experimental: A new
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204See the full CHANGELOG.md for more information.
v4.30.8
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.30.8 - 10 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v4.30.7
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.30.7 - 06 Oct 2025
- [v4+ only] The CodeQL Action now runs on Node.js v24. #3169
See the full CHANGELOG.md for more information.
v3.30.9
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.9 - 17 Oct 2025
- Update default CodeQL bundle version to 2.23.3. #3205
- Experimental: A new
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204See the full CHANGELOG.md for more information.
v3.30.8
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
... (truncated)
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.30.9 - 17 Oct 2025
- Update default CodeQL bundle version to 2.23.3. #3205
- Experimental: A new
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #32044.30.8 - 10 Oct 2025
No user facing changes.
4.30.7 - 06 Oct 2025
- [v4+ only] The CodeQL Action now runs on Node.js v24. #3169
3.30.6 - 02 Oct 2025
- Update default CodeQL bundle version to 2.23.2. #3168
3.30.5 - 26 Sep 2025
- We fixed a bug that was introduced in
3.30.4withupload-sarifwhich resulted in files without a.sarifextension not getting uploaded. #31603.30.4 - 25 Sep 2025
- We have improved the CodeQL Action's ability to validate that the workflow it is used in does not use different versions of the CodeQL Action for different workflow steps. Mixing different versions of the CodeQL Action in the same workflow is unsupported and can lead to unpredictable results. A warning will now be emitted from the
codeql-action/initstep if different versions of the CodeQL Action are detected in the workflow file. Additionally, an error will now be thrown by the other CodeQL Action steps if they load a configuration file that was generated by a different version of thecodeql-action/initstep. #3099 and #3100- We added support for reducing the size of dependency caches for Java analyses, which will reduce cache usage and speed up workflows. This will be enabled automatically at a later time. #3107
- You can now run the latest CodeQL nightly bundle by passing
tools: nightlyto theinitaction. In general, the nightly bundle is unstable and we only recommend running it when directed by GitHub staff. #3130- Update default CodeQL bundle version to 2.23.1. #3118
3.30.3 - 10 Sep 2025
No user facing changes.
3.30.2 - 09 Sep 2025
- Fixed a bug which could cause language autodetection to fail. #3084
- Experimental: The
quality-queriesinput that was added in3.29.2as part of an internal experiment is now deprecated and will be removed in an upcoming version of the CodeQL Action. It has been superseded by a newanalysis-kindsinput, which is part of the same internal experiment. Do not use this in production as it is subject to change at any time. #30643.30.1 - 05 Sep 2025
- Update default CodeQL bundle version to 2.23.0. #3077
3.30.0 - 01 Sep 2025
... (truncated)
16140ae
Merge pull request #3213
from github/update-v4.30.9-70205d3d130db5fe
Update changelog for v4.30.970205d3
Merge pull request #3211
from github/mbg/init/starting-partial-config697c209
Merge remote-tracking branch 'origin/main' into
mbg/init/starting-partial-config1bd53ba
Merge pull request #3205
from github/update-bundle/codeql-bundle-v2.23.3cac4df0
Rebuild77e5c0d
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.397a4f75
Merge pull request #3204
from github/mbg/setup-codeql2d5512b
Merge remote-tracking branch 'origin/main' into
mbg/init/starting-partial-configfa7bdf0
Call getAnalysisKinds a second time, and ignore exceptions
thrown during th...Sourced from sigstore/cosign-installer's releases.
v4.0.0
What's Changed?
Note: You must upgrade to cosign-installer v4 if you want to install Cosign v3+. You may still install Cosign v2.x with cosign-installer v4.
In version v3+, using
cosign sign-blobrequires adding the--bundleflag which may require you to update your signing command.
- Add support for Cosign v3 releases (#201)
v3.10.1
What's Changed?
Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.
Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.
- Bump default Cosign to v2.6.1 (#203)
faadad0
add support for cosign v3 releases (#201)Sourced from actions/setup-node's releases.
v6.0.0
What's Changed
Breaking Changes
- Limit automatic caching to npm, update workflows and documentation by
@priyagupta108in actions/setup-node#1374Dependency Upgrades
- Upgrade ts-jest from 29.1.2 to 29.4.1 and document breaking changes in v5 by
@dependabot[bot] in #1336- Upgrade prettier from 2.8.8 to 3.6.2 by
@dependabot[bot] in #1334- Upgrade actions/publish-action from 0.3.0 to 0.4.0 by
@dependabot[bot] in #1362Full Changelog: https://github.com/actions/setup-node/compare/v5...v6.0.0
Sourced from com.github.junrar:junrar's releases.
Release v7.5.7
Changelog
🛠 Build
- fix failing version (beccd50)
- fix failing version (4ccf1d2)
- use bump when computing snapshot version (20e9105)
- use java 21 (ae8bff6)
- remove java toolchains and use release flag instead (0d99993), closes #218
📝 Documentation
- update maven snapshot badge (04481cf)
Contributors
We'd like to thank the following people for their contributions: Gauthier Roebroeck
Release v7.5.6
Changelog
🐛 Fixes
🧪 Tests
- replace deprecation (ae8870d)
🛠 Build
deps
- bump com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.19.0 to 2.20.0 (a1143e2)
- bump ch.qos.logback:logback-classic from 1.5.18 to 1.5.19 (06ba358)
- bump org.mockito:mockito-core from 5.17.0 to 5.20.0 (9880cc4)
- bump com.fasterxml.jackson.core:jackson-databind (9912de1)
- bump commons-io:commons-io from 2.19.0 to 2.20.0 (716b0fc)
- bump org.assertj:assertj-core from 3.27.4 to 3.27.6 (23ba3d7)
- bump peter-evans/create-or-update-comment from 4 to 5 (932af2e)
- bump gradle/actions from 4 to 5 (d3b4237)
- bump org.assertj:assertj-core from 3.27.3 to 3.27.4 (a7b88da)
- bump com.github.gotson.bestbefore:bestbefore-processor-java (acf11b2)
- bump org.jreleaser from 1.18.0 to 1.20.0 (694c46c)
- bump actions/setup-java from 4 to 5 (c6c2cb9)
- bump actions/checkout from 4 to 5 (f55f514)
- bump archunit to 1.4.1 (4942838)
- bump junit-pioneer to 2.3.0 (75bd572)
- bump slf4j-api from 2.0.9 to 2.0.17 (cd598e6)
- bump ch.qos.logback:logback-classic from 1.4.11 to 1.5.18 (666e572)
... (truncated)
Sourced from com.github.junrar:junrar's changelog.
7.5.7 (2025-10-17)
🛠 Build
- fix failing version (beccd50)
- fix failing version (4ccf1d2)
- use bump when computing snapshot version (20e9105)
- use java 21 (ae8bff6)
- remove java toolchains and use release flag instead (0d99993), closes #218
📝 Documentation
- update maven snapshot badge (04481cf)
7.5.6 (2025-10-16)
🐛 Fixes
🧪 Tests
- replace deprecation (ae8870d)
🛠 Build
deps
- bump com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.19.0 to 2.20.0 (a1143e2)
- bump ch.qos.logback:logback-classic from 1.5.18 to 1.5.19 (06ba358)
- bump org.mockito:mockito-core from 5.17.0 to 5.20.0 (9880cc4)
- bump com.fasterxml.jackson.core:jackson-databind (9912de1)
- bump commons-io:commons-io from 2.19.0 to 2.20.0 (716b0fc)
- bump org.assertj:assertj-core from 3.27.4 to 3.27.6 (23ba3d7)
- bump peter-evans/create-or-update-comment from 4 to 5 (932af2e)
- bump gradle/actions from 4 to 5 (d3b4237)
- bump org.assertj:assertj-core from 3.27.3 to 3.27.4 (a7b88da)
- bump com.github.gotson.bestbefore:bestbefore-processor-java (acf11b2)
- bump org.jreleaser from 1.18.0 to 1.20.0 (694c46c)
- bump actions/setup-java from 4 to 5 (c6c2cb9)
- bump actions/checkout from 4 to 5 (f55f514)
- bump archunit to 1.4.1 (4942838)
- bump junit-pioneer to 2.3.0 (75bd572)
- bump slf4j-api from 2.0.9 to 2.0.17 (cd598e6)
- bump ch.qos.logback:logback-classic from 1.4.11 to 1.5.18 (666e572)
- bump com.fasterxml.jackson.core:jackson-databind (9258830)
- bump org.mockito:mockito-core from 5.6.0 to 5.17.0 (c2eeadc)
- bump io.github.gradle-nexus.publish-plugin (777d966)
- bump org.assertj:assertj-core from 3.24.2 to 3.27.3 (76c8474)
- bump com.github.ben-manes.versions from 0.50.0 to 0.52.0 (b6fa2a8)
- bump codecov/codecov-action from 3 to 5 (9c37e01)
- bump com.fasterxml.jackson.datatype:jackson-datatype-jsr310 (ea99789)
- bump commons-io:commons-io from 2.15.0 to 2.19.0 (2c02c73)
- bump org.jreleaser from 1.9.0 to 1.18.0 (d588832)
... (truncated)
04481cf
docs: update maven snapshot badgebeccd50
ci: fix failing version4ccf1d2
ci: fix failing version20e9105
ci: use bump when computing snapshot versionae8bff6
ci: use java 210d99993
build: remove java toolchains and use release flag instead9550e75
chore(release): 7.5.6 [skip ci]a1143e2
build(deps): bump com.fasterxml.jackson.datatype:jackson-datatype-jsr310
from...06ba358
build(deps): bump ch.qos.logback:logback-classic from 1.5.18 to
1.5.199880cc4
build(deps): bump org.mockito:mockito-core from 5.17.0 to 5.20.0