dependabot[bot] opened a new pull request, #74111: URL: https://github.com/apache/airflow/pull/74111
Bumps the github-actions-updates group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [apache/infrastructure-actions/stash/restore](https://github.com/apache/infrastructure-actions) | `ec1b354a0455b41001d77473236d02a0ee0adba4` | `73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7` | | [apache/infrastructure-actions/stash/save](https://github.com/apache/infrastructure-actions) | `ec1b354a0455b41001d77473236d02a0ee0adba4` | `73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.1.0` | `10.2.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` | | [gradle/actions/dependency-submission](https://github.com/gradle/actions) | `6.3.0` | `6.4.0` | Updates `apache/infrastructure-actions/stash/restore` from ec1b354a0455b41001d77473236d02a0ee0adba4 to 73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/apache/infrastructure-actions/commit/73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7"><code>73dfeb8</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/d545588139850a104de28a3a203555f719e0393a"><code>d545588</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/4ce8ecd7195b3a7c42f385079e03e5f9b796ff72"><code>4ce8ecd</code></a> Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in /.github/workflows (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1333">#1333</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/512c434eebc71d4687af57aea058974a4f29a4c4"><code>512c434</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/bb4db89f21d5ce20319f37e2b2f4c45ae32826ba"><code>bb4db89</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/79442b87f41b86b70efd99ed54346b30fa402637"><code>79442b8</code></a> Sync actions.yml, composite action, and approved_patterns.yml</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/177c4ba4c5fb19ce485c8dd7743569c7266972b6"><code>177c4ba</code></a> allowlist: re-add CodSpeedHQ/action v5.2.1 (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1327">#1327</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/c3bc1b88ced65d2cf79fab272b14ce38fa180e19"><code>c3bc1b8</code></a> fix(pelican): Upgrade Debian to trixie and Python to 3.11 (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1328">#1328</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/cc6fa4541420bb0587057909eba413d7d57fe96a"><code>cc6fa45</code></a> Sync actions.yml, composite action, and approved_patterns.yml</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/472f9d4ba216c565e04c03c4780c010069b4156e"><code>472f9d4</code></a> action-allowlist-review: bump uraimo/run-on-arch-action (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1329">#1329</a>)</li> <li>Additional commits viewable in <a href="https://github.com/apache/infrastructure-actions/compare/ec1b354a0455b41001d77473236d02a0ee0adba4...73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7">compare view</a></li> </ul> </details> <br /> Updates `apache/infrastructure-actions/stash/save` from ec1b354a0455b41001d77473236d02a0ee0adba4 to 73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/apache/infrastructure-actions/commit/73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7"><code>73dfeb8</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/d545588139850a104de28a3a203555f719e0393a"><code>d545588</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/4ce8ecd7195b3a7c42f385079e03e5f9b796ff72"><code>4ce8ecd</code></a> Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in /.github/workflows (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1333">#1333</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/512c434eebc71d4687af57aea058974a4f29a4c4"><code>512c434</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/bb4db89f21d5ce20319f37e2b2f4c45ae32826ba"><code>bb4db89</code></a> Remove Expired Refs</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/79442b87f41b86b70efd99ed54346b30fa402637"><code>79442b8</code></a> Sync actions.yml, composite action, and approved_patterns.yml</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/177c4ba4c5fb19ce485c8dd7743569c7266972b6"><code>177c4ba</code></a> allowlist: re-add CodSpeedHQ/action v5.2.1 (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1327">#1327</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/c3bc1b88ced65d2cf79fab272b14ce38fa180e19"><code>c3bc1b8</code></a> fix(pelican): Upgrade Debian to trixie and Python to 3.11 (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1328">#1328</a>)</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/cc6fa4541420bb0587057909eba413d7d57fe96a"><code>cc6fa45</code></a> Sync actions.yml, composite action, and approved_patterns.yml</li> <li><a href="https://github.com/apache/infrastructure-actions/commit/472f9d4ba216c565e04c03c4780c010069b4156e"><code>472f9d4</code></a> action-allowlist-review: bump uraimo/run-on-arch-action (<a href="https://redirect.github.com/apache/infrastructure-actions/issues/1329">#1329</a>)</li> <li>Additional commits viewable in <a href="https://github.com/apache/infrastructure-actions/compare/ec1b354a0455b41001d77473236d02a0ee0adba4...73dfeb8821416f3a31ddcd1e6eec95dc15b14ea7">compare view</a></li> </ul> </details> <br /> Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's releases</a>.</em></p> <blockquote> <h2>v10.2.0 🌈 Disable automatic cache saves for merge queues</h2> <h2>Changes</h2> <p>This release contains the known-checksum of the most recent uv releases and also disabled the uploading(saving) of the cache when in a merge queue since theses caches would almost never be used.</p> <h2>🚀 Enhancements</h2> <ul> <li>Disable automatic cache saves for merge queues <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1056">#1056</a>)</li> </ul> <h2>🧰 Maintenance</h2> <ul> <li>chore: update known checksums for 0.12.17 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1058">#1058</a>)</li> <li>chore: update known checksums for 0.12.16 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1057">#1057</a>)</li> <li>chore: update known checksums for 0.12.15 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1054">#1054</a>)</li> <li>chore: update known checksums for 0.12.14 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1053">#1053</a>)</li> <li>chore: update known checksums for 0.12.13 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1045">#1045</a>)</li> </ul> <h2>📚 Documentation</h2> <ul> <li>docs: update version references to v10.1.0 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1044">#1044</a>)</li> </ul> <h2>⬆️ Dependency updates</h2> <ul> <li>chore(deps): roll up Dependabot updates <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1059">#1059</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/setup-uv/commit/c18668ad3cf93ea998bef934396af7bb5c839dc7"><code>c18668a</code></a> chore(deps): roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1059">#1059</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/ffe14763056ca34ecd158146a9fc7e144c8a2753"><code>ffe1476</code></a> chore: update known checksums for 0.12.17 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1058">#1058</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/f5548c55522a1db0af3c84f2af3d058bc9bc2de2"><code>f5548c5</code></a> chore: update known checksums for 0.12.16 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1057">#1057</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/a761a4e9afd7b2f353ae020bd6d3a3af34c6c4d5"><code>a761a4e</code></a> Disable automatic cache saves for merge queues (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1056">#1056</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/3377a30666f438759955882b3eba6a92b2b29b12"><code>3377a30</code></a> chore: update known checksums for 0.12.15 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1054">#1054</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/dfb5f386776afcea37f271f3b656318d9949b9f1"><code>dfb5f38</code></a> chore: update known checksums for 0.12.14 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1053">#1053</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/45c121f982720f3bdf236c2ac06f126ca211949c"><code>45c121f</code></a> chore: update known checksums for 0.12.13 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1045">#1045</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/8073452fd4b566e886f04f731bcdbd8332b0b779"><code>8073452</code></a> docs: update version references to v10.1.0 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1044">#1044</a>)</li> <li>See full diff in <a href="https://github.com/astral-sh/setup-uv/compare/bec219d24cd3e171d82865faccec33120bb574f4...c18668ad3cf93ea998bef934396af7bb5c839dc7">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/init` from 4.38.0 to 4.38.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/init's releases</a>.</em></p> <blockquote> <h2>v4.38.2</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with < code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a> from github/update-v4.38.2-a6ef2c96f</li> <li><a href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a> Trigger workflows</li> <li><a href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a> Update changelog for v4.38.2</li> <li><a href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a> from github/mario-campos/fix-validate-cmd</li> <li><a href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a> from github/dependabot/github_actions/dot-github/wor...</li> <li><a href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a> from github/mbg/fix-getCommitOid-stubs</li> <li><a href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a> from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li> <li><a href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a> Bump ruby/setup-ruby</li> <li><a href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's releases</a>.</em></p> <blockquote> <h2>v4.38.2</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with < code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a> from github/update-v4.38.2-a6ef2c96f</li> <li><a href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a> Trigger workflows</li> <li><a href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a> Update changelog for v4.38.2</li> <li><a href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a> from github/mario-campos/fix-validate-cmd</li> <li><a href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a> from github/dependabot/github_actions/dot-github/wor...</li> <li><a href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a> from github/mbg/fix-getCommitOid-stubs</li> <li><a href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a> from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li> <li><a href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a> Bump ruby/setup-ruby</li> <li><a href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's releases</a>.</em></p> <blockquote> <h2>v4.38.2</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with < code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a> from github/update-v4.38.2-a6ef2c96f</li> <li><a href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a> Trigger workflows</li> <li><a href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a> Update changelog for v4.38.2</li> <li><a href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a> from github/mario-campos/fix-validate-cmd</li> <li><a href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a> from github/dependabot/github_actions/dot-github/wor...</li> <li><a href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a> from github/mbg/fix-getCommitOid-stubs</li> <li><a href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a> from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li> <li><a href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a> Bump ruby/setup-ruby</li> <li><a href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare view</a></li> </ul> </details> <br /> Updates `gradle/actions/dependency-submission` from 6.3.0 to 6.4.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/gradle/actions/releases">gradle/actions/dependency-submission's releases</a>.</em></p> <blockquote> <h2>v6.4.0</h2> <h2>Highlights</h2> <h3>Gradle version support status in the Job Summary</h3> <p>The actions now report the support status of every Gradle version used in a workflow, as job annotations and in the Job Summary (<a href="https://redirect.github.com/gradle/actions/issues/1057">#1057</a>). Thanks to <a href="https://github.com/ov7a"><code>@ov7a</code></a> for the contribution.</p> <table> <thead> <tr> <th>version kind</th> <th>job annotation</th> <th>version table</th> <th>below the table</th> </tr> </thead> <tbody> <tr> <td><strong>End-of-life</strong> — two or more major versions behind the latest release</td> <td>warning</td> <td>:warning:</td> <td>expandable section naming the affected release lines, pointing at the <a href="https://gradle.org/security-subscription/">Gradle Security Subscription</a></td> </tr> <tr> <td><strong>Out of date</strong> — one major behind, or more than two minors behind on the current major</td> <td>notice</td> <td>:information_source:</td> <td>one-line legend pointing at the <a href="https://docs.gradle.org/current/userguide/feature_lifecycle.html#eol_support">Gradle release lifecycle</a> docs</td> </tr> <tr> <td><strong>Current</strong></td> <td>none</td> <td>—</td> <td>—</td> </tr> </tbody> </table> <p>Deliberately <em>not</em> reported: patch releases (being on <code>9.7.0</code> when <code>9.7.1</code> exists is not flagged) and pre-releases (release candidates, milestones and snapshots never produce annotations). The latest Gradle release is determined from the wrapper checksum data already bundled with the action, so no network access is required.</p> <p>Note that these annotations are emitted independently of the <code>add-job-summary</code> setting: setting <code>add-job-summary: 'never'</code> suppresses the Job Summary itself, but the warning and notice annotations remain.</p> <h3>Gradle itself is now reported in the dependency graph</h3> <p>The <code>dependency-submission</code> action now applies <strong>v1.5.0</strong> of the <a href="https://github.com/gradle/github-dependency-graph-gradle-plugin">GitHub Dependency Graph Gradle Plugin</a> (up from v1.4.2) (<a href="https://redirect.github.com/gradle/actions/issues/1069">#1069</a>).</p> <p>The headline change is that the Gradle Build Tool running the build is now reported as an <code>org.gradle:gradle-core</code> dependency, so that <strong>GitHub can surface known vulnerabilities in the version of Gradle used to run your build</strong>. These are the coordinates that GitHub advisories for the Gradle Build Tool are published against.</p> <p>Details worth knowing:</p> <ul> <li>The entry is always reported as a <strong>direct</strong> dependency with <strong>development</strong> scope.</li> <li>It is <strong>not</strong> affected by the project, configuration or scope filters, so it appears even in graphs that filter aggressively.</li> <li>Expect dependency graphs to gain this one new entry the first time a build runs after upgrading.</li> </ul> <h3>A new Gradle signing key, if you use dependency verification</h3> <blockquote> <p>[!IMPORTANT] If your build has <a href="https://docs.gradle.org/current/userguide/dependency_verification.html#sec:signature-verification">dependency verification</a> enabled, you must add a <strong>second</strong> trusted key before upgrading, or Dependency Graph generation will fail signature verification.</p> </blockquote> <p><code>github-dependency-graph-gradle-plugin</code> <code>1.5.0</code> is signed with a new Gradle signing subkey, and the key previously documented in our setup guide has been revoked upstream:</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/gradle/actions/commit/3f5f9adaf7d9fecd50b5935e54106014257a94e6"><code>3f5f9ad</code></a> Document the new Gradle signing key for dependency verification (<a href="https://redirect.github.com/gradle/actions/issues/1071">#1071</a>)</li> <li><a href="https://github.com/gradle/actions/commit/b031f6d1a92a4611986643414591f8f649182940"><code>b031f6d</code></a> [bot] Update dist directory</li> <li><a href="https://github.com/gradle/actions/commit/5bc4175609b5adc59007637c78e2eb52125bea3d"><code>5bc4175</code></a> Bump dependency-graph-gradle-plugin to 1.5.0 (<a href="https://redirect.github.com/gradle/actions/issues/1069">#1069</a>)</li> <li><a href="https://github.com/gradle/actions/commit/f3ff59b4e4151fd189d67647ccb7b78ddde26db9"><code>f3ff59b</code></a> Combined automated updates: wrapper checksums, npm dependencies, setup-java (...</li> <li><a href="https://github.com/gradle/actions/commit/7927085475f60c9d4b43880590e265597c31d8b4"><code>7927085</code></a> Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 (<a href="https://redirect.github.com/gradle/actions/issues/1068">#1068</a>)</li> <li><a href="https://github.com/gradle/actions/commit/c3897a4e73a8f23b849f1980944785e7ae34c471"><code>c3897a4</code></a> [bot] Update dist directory</li> <li><a href="https://github.com/gradle/actions/commit/6b92be19055d28f8f52e00bd24bb215841656af4"><code>6b92be1</code></a> Update dependencies (<a href="https://redirect.github.com/gradle/actions/issues/1065">#1065</a>)</li> <li><a href="https://github.com/gradle/actions/commit/0d208da0581aab8a4c6c02b69957a02c7806bca8"><code>0d208da</code></a> [bot] Update dist directory</li> <li><a href="https://github.com/gradle/actions/commit/e49d0a36a8651e7efb23918f4532fe1d4f46de77"><code>e49d0a3</code></a> Report EOL and maintenance status for Gradle versions (<a href="https://redirect.github.com/gradle/actions/issues/1057">#1057</a>)</li> <li><a href="https://github.com/gradle/actions/commit/575435b1ea5344b0885c3387acd4752bca7a57b7"><code>575435b</code></a> Use the root-qualified <code>:wrapper</code> task (<a href="https://redirect.github.com/gradle/actions/issues/1064">#1064</a>)</li> <li>Additional commits viewable in <a href="https://github.com/gradle/actions/compare/9c971963bec38e04b3d30dcc455b5382be2fdbfb...3f5f9adaf7d9fecd50b5935e54106014257a94e6">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
