dependabot[bot] opened a new pull request, #2877:
URL: https://github.com/apache/shiro/pull/2877

   Bumps the github-actions-dependencies group with 6 updates:
   
   | Package | From | To |
   | --- | --- | --- |
   | 
[apache/infrastructure-actions/allowlist-check](https://github.com/apache/infrastructure-actions)
 | `4e9c961f587f72b170874b6f5cd4ac15f7f26eb8` | 
`ce952724eb5210790bd5d466d70d5d60ac3e6c21` |
   | [github/codeql-action/init](https://github.com/github/codeql-action) | 
`4.37.3` | `4.37.9` |
   | [github/codeql-action/analyze](https://github.com/github/codeql-action) | 
`4.37.3` | `4.37.9` |
   | [actions/setup-java](https://github.com/actions/setup-java) | `5.6.0` | 
`6.0.0` |
   | [j178/prek-action](https://github.com/j178/prek-action) | `2.0.6` | 
`3.0.0` |
   | 
[github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | 
`4.37.3` | `4.37.9` |
   
   Updates `apache/infrastructure-actions/allowlist-check` from 
4e9c961f587f72b170874b6f5cd4ac15f7f26eb8 to 
ce952724eb5210790bd5d466d70d5d60ac3e6c21
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/ce952724eb5210790bd5d466d70d5d60ac3e6c21";><code>ce95272</code></a>
 Merge pull request <a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1207";>#1207</a>
 from potiuk/skill-triage-precedents-aug</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/e2ca50464f7a1a26205237fcdc8257f4c09c149f";><code>e2ca504</code></a>
 Merge pull request <a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1206";>#1206</a>
 from potiuk/verify-intree-rebuild-credit</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/888400277b284722ca153bc16e5dbb32d55c058d";><code>8884002</code></a>
 Merge pull request <a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1205";>#1205</a>
 from potiuk/verify-diff-shell-sources</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/a6fc3c73cec8c0c0849ca99c07aba91e3c1cd92e";><code>a6fc3c7</code></a>
 Merge pull request <a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1175";>#1175</a>
 from apache/fix/aube-lock-support</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/6d9bb8a0a8edb1e9ba5a49f272460d7110dd77a0";><code>6d9bb8a</code></a>
 Merge pull request <a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1174";>#1174</a>
 from apache/fix/npm-registry-definitelytyped-root</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/34a2cd5b9748fb1dcb72f743dfaf6be5d3cfc407";><code>34a2cd5</code></a>
 Bump actions/setup-java from 5.7.0 to 6.0.0 in /.github/workflows (<a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1221";>#1221</a>)</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/984c2f4d3f941ae6a224ba81be9c7f0176a3c3b7";><code>984c2f4</code></a>
 Bump ruff from 0.16.3 to 0.16.4 in /stash (<a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1212";>#1212</a>)</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/ce3f92f8d016873cb336db0fb8adb08cd3c7c82a";><code>ce3f92f</code></a>
 Bump mypy from 2.3.0 to 2.3.1 in /stash (<a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1211";>#1211</a>)</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/9aa69f84a8877f4459718419f06783406c1162ef";><code>9aa69f8</code></a>
 Bump mypy from 2.3.0 to 2.3.1 in /pelican (<a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1210";>#1210</a>)</li>
   <li><a 
href="https://github.com/apache/infrastructure-actions/commit/7973673d107322d02c24304774c4bc6418d8bba3";><code>7973673</code></a>
 Bump types-pyyaml from 6.0.12.20260724 to 6.0.12.20260815 in /pelican (<a 
href="https://redirect.github.com/apache/infrastructure-actions/issues/1209";>#1209</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/apache/infrastructure-actions/compare/4e9c961f587f72b170874b6f5cd4ac15f7f26eb8...ce952724eb5210790bd5d466d70d5d60ac3e6c21";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `github/codeql-action/init` from 4.37.3 to 4.37.9
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/releases";>github/codeql-action/init's
 releases</a>.</em></p>
   <blockquote>
   <h2>v4.37.9</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>v4.37.8</h2>
   <p>No user facing changes.</p>
   <h2>v4.37.7</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>v4.37.6</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>v4.37.5</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>v4.37.4</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action/init's
 changelog</a>.</em></p>
   <blockquote>
   <h1>CodeQL Action Changelog</h1>
   <p>See the <a 
href="https://github.com/github/codeql-action/releases";>releases page</a> for 
the relevant changes to the CodeQL CLI and language packs.</p>
   <h2>[UNRELEASED]</h2>
   <p>No user facing changes.</p>
   <h2>4.37.9 - 26 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>4.37.8 - 21 Aug 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.7 - 13 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>4.37.6 - 04 Aug 2026</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>4.37.5 - 03 Aug 2026</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>4.37.4 - 29 Jul 2026</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   <h2>4.37.3 - 22 Jul 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.2 - 21 Jul 2026</h2>
   <ul>
   <li>The new address format for the <code>config-file</code> input that was 
introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to 
the format described there, the <code>remote=</code> prefix can now be used to 
explicitly indicate that the input refers to a remote file. All previous input 
formats continue to be accepted as well. <a 
href="https://redirect.github.com/github/codeql-action/pull/4023";>#4023</a></li>
   <li>The CodeQL Action can now make use of <a 
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries";>configured
 private registries</a> in Default Setup to retrieve CodeQL configuration files 
from remote repositories that require authentication. This will allow customers 
to store their CodeQL configuration in a single repository that can then be 
referenced by Default Setup workflows in other repositories. We expect to roll 
this and other, related changes out to everyone in July. <a 
href="https://redirect.github.com/github/codeql-action/pull/4007";>#4007</a></li>
   </ul>
   <h2>4.37.1 - 16 Jul 2026</h2>
   <ul>
   <li><em>Upcoming breaking change</em>: Add a deprecation warning for 
customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL 
were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and 
will be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3956";>#3956</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1";>2.26.1</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4019";>#4019</a></li>
   </ul>
   <h2>4.37.0 - 08 Jul 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0";>2.26.0</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3995";>#3995</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/github/codeql-action/commit/cdf488f595d80d6e07e03d4674febd5ab45fa938";><code>cdf488f</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4107";>#4107</a> 
from github/update-v4.37.9-920ba7cd1</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/7243f38558d187dde99730d224bb47aa26a95306";><code>7243f38</code></a>
 Update changelog for v4.37.9</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/920ba7cd1596037e042122c00381eb16b397d68e";><code>920ba7c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4106";>#4106</a> 
from github/update-bundle/codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ecfa6e16817b8f490bc9a59baa391baf4fa3e3c2";><code>ecfa6e1</code></a>
 Add changelog note</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/adcdf4a70d247343cf9c29e0f7a6658b51c3a2b1";><code>adcdf4a</code></a>
 Update default bundle to codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/486fec2a3ea2626afcd8c7e9208b4f515078dd7e";><code>486fec2</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4099";>#4099</a> 
from github/update-supported-enterprise-server-versions</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/134624c67b20869c2aaa36dafa726375b78a5d76";><code>134624c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4101";>#4101</a> 
from github/dependabot/npm_and_yarn/npm-minor-457d82...</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ff43db8f982a368288f117354fb8d046e937124c";><code>ff43db8</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4103";>#4103</a> 
from github/mergeback/v4.37.8-to-main-db488dde</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/4605e03a74cf891614c4d76f82384a16c1c11816";><code>4605e03</code></a>
 Rebuild</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/099c869cad6bf3b88657154d4ae47ffed27e632d";><code>099c869</code></a>
 Update changelog and version after v4.37.8</li>
   <li>Additional commits viewable in <a 
href="https://github.com/github/codeql-action/compare/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81...cdf488f595d80d6e07e03d4674febd5ab45fa938";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.9
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/releases";>github/codeql-action/analyze's
 releases</a>.</em></p>
   <blockquote>
   <h2>v4.37.9</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>v4.37.8</h2>
   <p>No user facing changes.</p>
   <h2>v4.37.7</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>v4.37.6</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>v4.37.5</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>v4.37.4</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action/analyze's
 changelog</a>.</em></p>
   <blockquote>
   <h1>CodeQL Action Changelog</h1>
   <p>See the <a 
href="https://github.com/github/codeql-action/releases";>releases page</a> for 
the relevant changes to the CodeQL CLI and language packs.</p>
   <h2>[UNRELEASED]</h2>
   <p>No user facing changes.</p>
   <h2>4.37.9 - 26 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>4.37.8 - 21 Aug 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.7 - 13 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>4.37.6 - 04 Aug 2026</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>4.37.5 - 03 Aug 2026</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>4.37.4 - 29 Jul 2026</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   <h2>4.37.3 - 22 Jul 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.2 - 21 Jul 2026</h2>
   <ul>
   <li>The new address format for the <code>config-file</code> input that was 
introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to 
the format described there, the <code>remote=</code> prefix can now be used to 
explicitly indicate that the input refers to a remote file. All previous input 
formats continue to be accepted as well. <a 
href="https://redirect.github.com/github/codeql-action/pull/4023";>#4023</a></li>
   <li>The CodeQL Action can now make use of <a 
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries";>configured
 private registries</a> in Default Setup to retrieve CodeQL configuration files 
from remote repositories that require authentication. This will allow customers 
to store their CodeQL configuration in a single repository that can then be 
referenced by Default Setup workflows in other repositories. We expect to roll 
this and other, related changes out to everyone in July. <a 
href="https://redirect.github.com/github/codeql-action/pull/4007";>#4007</a></li>
   </ul>
   <h2>4.37.1 - 16 Jul 2026</h2>
   <ul>
   <li><em>Upcoming breaking change</em>: Add a deprecation warning for 
customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL 
were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and 
will be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3956";>#3956</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1";>2.26.1</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4019";>#4019</a></li>
   </ul>
   <h2>4.37.0 - 08 Jul 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0";>2.26.0</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3995";>#3995</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/github/codeql-action/commit/cdf488f595d80d6e07e03d4674febd5ab45fa938";><code>cdf488f</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4107";>#4107</a> 
from github/update-v4.37.9-920ba7cd1</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/7243f38558d187dde99730d224bb47aa26a95306";><code>7243f38</code></a>
 Update changelog for v4.37.9</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/920ba7cd1596037e042122c00381eb16b397d68e";><code>920ba7c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4106";>#4106</a> 
from github/update-bundle/codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ecfa6e16817b8f490bc9a59baa391baf4fa3e3c2";><code>ecfa6e1</code></a>
 Add changelog note</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/adcdf4a70d247343cf9c29e0f7a6658b51c3a2b1";><code>adcdf4a</code></a>
 Update default bundle to codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/486fec2a3ea2626afcd8c7e9208b4f515078dd7e";><code>486fec2</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4099";>#4099</a> 
from github/update-supported-enterprise-server-versions</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/134624c67b20869c2aaa36dafa726375b78a5d76";><code>134624c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4101";>#4101</a> 
from github/dependabot/npm_and_yarn/npm-minor-457d82...</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ff43db8f982a368288f117354fb8d046e937124c";><code>ff43db8</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4103";>#4103</a> 
from github/mergeback/v4.37.8-to-main-db488dde</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/4605e03a74cf891614c4d76f82384a16c1c11816";><code>4605e03</code></a>
 Rebuild</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/099c869cad6bf3b88657154d4ae47ffed27e632d";><code>099c869</code></a>
 Update changelog and version after v4.37.8</li>
   <li>Additional commits viewable in <a 
href="https://github.com/github/codeql-action/compare/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81...cdf488f595d80d6e07e03d4674febd5ab45fa938";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `actions/setup-java` from 5.6.0 to 6.0.0
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/actions/setup-java/releases";>actions/setup-java's 
releases</a>.</em></p>
   <blockquote>
   <h2>v6.0.0</h2>
   <h2>What's Changed</h2>
   <ul>
   <li>dist: Migrate from Zulu Discovery API to Azul Metadata API by <a 
href="https://github.com/jameswald";><code>@​jameswald</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1010";>actions/setup-java#1010</a></li>
   <li>feat: add .mvn/extensions.xml to Maven cache key pattern by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1041";>actions/setup-java#1041</a></li>
   <li>Migrate to ESM and upgrade dependencies by <a 
href="https://github.com/priyagupta108";><code>@​priyagupta108</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1078";>actions/setup-java#1078</a></li>
   <li>Map Zulu x86 architecture to i686 for Azul Metadata API by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1079";>actions/setup-java#1079</a></li>
   <li>Rename jdkFile input to jdk-file with deprecated alias by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1083";>actions/setup-java#1083</a></li>
   <li>Infer distribution from asdf .tool-versions vendor prefix by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1084";>actions/setup-java#1084</a></li>
   <li>Add Maven compiler problem matcher for javac diagnostics by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1086";>actions/setup-java#1086</a></li>
   <li>feat: expose cache-primary-key output (<a 
href="https://redirect.github.com/actions/setup-java/issues/597";>#597</a>) by 
<a href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1088";>actions/setup-java#1088</a></li>
   <li>docs: clarify V6 ESM migration is not a user-facing breaking change by 
<a href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1090";>actions/setup-java#1090</a></li>
   <li>Support multi-field Java versions like <code>18.0.1.1</code> by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1092";>actions/setup-java#1092</a></li>
   <li>docs: document seeding the Maven cache for plugin dependencies by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1094";>actions/setup-java#1094</a></li>
   <li>docs: clarify Maven cache paths and key hash inputs by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1096";>actions/setup-java#1096</a></li>
   <li>Support pinning java-version as &quot;latest&quot; by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1093";>actions/setup-java#1093</a></li>
   <li>chore(deps-dev): bump eslint from 10.6.0 to 10.7.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1101";>actions/setup-java#1101</a></li>
   <li>chore(deps-dev): bump eslint-plugin-n from 18.2.1 to 18.2.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1103";>actions/setup-java#1103</a></li>
   <li>chore(deps-dev): bump prettier from 3.9.4 to 3.9.5 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1105";>actions/setup-java#1105</a></li>
   <li>chore(deps): bump actions/checkout from 6 to 7 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1106";>actions/setup-java#1106</a></li>
   <li>chore(deps-dev): bump <code>@​types/node</code> from 26.1.0 to 26.1.1 by 
<a href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in 
<a 
href="https://redirect.github.com/actions/setup-java/pull/1104";>actions/setup-java#1104</a></li>
   <li>dist: Cover Tencent Kona JDK 25 by <a 
href="https://github.com/johnshajiang";><code>@​johnshajiang</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1108";>actions/setup-java#1108</a></li>
   <li>chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1102";>actions/setup-java#1102</a></li>
   <li>Preserve Maven toolchains across repeated setup-java runs (<a 
href="https://redirect.github.com/actions/setup-java/issues/1099";>#1099</a>) by 
<a href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1111";>actions/setup-java#1111</a></li>
   <li>dist: Support Liberica NIK (<a 
href="https://redirect.github.com/actions/setup-java/issues/878";>#878</a>) by 
<a href="https://github.com/asm0dey";><code>@​asm0dey</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1112";>actions/setup-java#1112</a></li>
   <li>Fix template injection (zizmor alert <a 
href="https://redirect.github.com/actions/setup-java/issues/118";>#118</a>) in 
e2e-versions.yml by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1114";>actions/setup-java#1114</a></li>
   <li>Fix template injection in e2e-versions.yml (zizmor alert <a 
href="https://redirect.github.com/actions/setup-java/issues/122";>#122</a>) by 
<a href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1120";>actions/setup-java#1120</a></li>
   <li>Disable persisted checkout credentials in e2e workflow by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1115";>actions/setup-java#1115</a></li>
   <li>feat: Update recommended configuration for GPG signing by <a 
href="https://github.com/wetneb";><code>@​wetneb</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/608";>actions/setup-java#608</a></li>
   <li>Cache Maven and Gradle wrapper distributions separately from the 
dependency cache by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1097";>actions/setup-java#1097</a></li>
   <li>Consolidate cache-dependency-path e2e workflow and add maven/sbt 
coverage by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1124";>actions/setup-java#1124</a></li>
   <li>Use gpg.passphraseEnvName instead of the deprecated gpg.passphrase 
server by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1123";>actions/setup-java#1123</a></li>
   <li>Extract repeated directory-check assertions into check-dir.sh helper by 
<a href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1127";>actions/setup-java#1127</a></li>
   <li>Consolidate duplicate jobs in e2e-versions workflow by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1125";>actions/setup-java#1125</a></li>
   <li>Use YAML anchors to reduce boilerplate in e2e-versions workflow by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1126";>actions/setup-java#1126</a></li>
   <li>Updated msft json for now by <a 
href="https://github.com/jmjaffe37";><code>@​jmjaffe37</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1129";>actions/setup-java#1129</a></li>
   <li>Document missing action inputs in README by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1130";>actions/setup-java#1130</a></li>
   <li>chore(deps): bump <code>@​actions/cache</code> to 6.2.0 by <a 
href="https://github.com/philip-gai";><code>@​philip-gai</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1128";>actions/setup-java#1128</a></li>
   <li>Add an option to disable Java problem matchers by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1133";>actions/setup-java#1133</a></li>
   <li>docs: update setup-java examples by <a 
href="https://github.com/HarithaVattikuti";><code>@​HarithaVattikuti</code></a> 
in <a 
href="https://redirect.github.com/actions/setup-java/pull/1131";>actions/setup-java#1131</a></li>
   <li>Clarify credential environment variable inputs by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1134";>actions/setup-java#1134</a></li>
   <li>chore(deps-dev): bump <code>@​typescript-eslint/eslint-plugin</code> 
from 8.63.0 to 8.64.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1135";>actions/setup-java#1135</a></li>
   <li>chore(deps): bump actions/setup-python from 6 to 7 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1143";>actions/setup-java#1143</a></li>
   <li>chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1142";>actions/setup-java#1142</a></li>
   <li>chore(deps-dev): bump <code>@​typescript-eslint/parser</code> from 
8.64.0 to 8.65.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1138";>actions/setup-java#1138</a></li>
   <li>chore(deps-dev): bump lint-staged from 17.0.8 to 17.2.0 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1136";>actions/setup-java#1136</a></li>
   <li>chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/actions/setup-java/pull/1137";>actions/setup-java#1137</a></li>
   <li>chore(deps): fix npm audited vulnerabilities by <a 
href="https://github.com/mhoffrog";><code>@​mhoffrog</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1140";>actions/setup-java#1140</a></li>
   <li>Fix formatting issues in README.md by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1144";>actions/setup-java#1144</a></li>
   <li>Remediate npm audit findings and rebuild distributions by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1145";>actions/setup-java#1145</a></li>
   <li>Set GRAALVM_HOME for GraalVM distributions by <a 
href="https://github.com/brunoborges";><code>@​brunoborges</code></a> with <a 
href="https://github.com/Copilot";><code>@​Copilot</code></a> in <a 
href="https://redirect.github.com/actions/setup-java/pull/1146";>actions/setup-java#1146</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/actions/setup-java/commit/dd06d9cba3e5552c54d9f8ea23572deb30010f7c";><code>dd06d9c</code></a>
 Prepare documentation for v6 release (<a 
href="https://redirect.github.com/actions/setup-java/issues/1253";>#1253</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/59b3450628e54f250d3a3bfd413cd68b83bce8ed";><code>59b3450</code></a>
 chore(deps): combine open Dependabot npm updates (<a 
href="https://redirect.github.com/actions/setup-java/issues/1252";>#1252</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/b96213d9d21fbd1dd447987fe15dd75fce7f7726";><code>b96213d</code></a>
 Set default signature verification for supported distributions (<a 
href="https://redirect.github.com/actions/setup-java/issues/1246";>#1246</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/1dbac3c9e137b6d4d280bae1ae4e9902bb4ce1b9";><code>1dbac3c</code></a>
 docs: expose contributing guide to GitHub (<a 
href="https://redirect.github.com/actions/setup-java/issues/1245";>#1245</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/11741d6cfaf82354eb314633583a9ce43399238b";><code>11741d6</code></a>
 ci: constrain cache e2e job modes (<a 
href="https://redirect.github.com/actions/setup-java/issues/1244";>#1244</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/ff99aa1c87709f29685194226dae7d9b476c594f";><code>ff99aa1</code></a>
 Fix Oracle macOS E2E version (<a 
href="https://redirect.github.com/actions/setup-java/issues/1243";>#1243</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/416c6d1e8ab4ffb67a533d502fd7b21f70c5d9ee";><code>416c6d1</code></a>
 Add Red Hat Build of OpenJDK support (<a 
href="https://redirect.github.com/actions/setup-java/issues/1241";>#1241</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/5f75b27283990add95cd9c4ceaca74d789324bf7";><code>5f75b27</code></a>
 Add Maven dependency-resolution repositories (<a 
href="https://redirect.github.com/actions/setup-java/issues/1240";>#1240</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/a42a52cfb590b0682db41c911da5dc7798ba620e";><code>a42a52c</code></a>
 Add multiple Maven server credentials (<a 
href="https://redirect.github.com/actions/setup-java/issues/1239";>#1239</a>)</li>
   <li><a 
href="https://github.com/actions/setup-java/commit/fb4abd7a7075173ac733c41f723ac0c47c41ad17";><code>fb4abd7</code></a>
 test: cover JDK 26 from SDKMAN (<a 
href="https://redirect.github.com/actions/setup-java/issues/1238";>#1238</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/actions/setup-java/compare/03ad4de0992f5dab5e18fcb136590ce7c4a0ac95...dd06d9cba3e5552c54d9f8ea23572deb30010f7c";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `j178/prek-action` from 2.0.6 to 3.0.0
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/j178/prek-action/releases";>j178/prek-action's 
releases</a>.</em></p>
   <blockquote>
   <h2>v3.0.0</h2>
   <h2><code>prek-action</code> releases are now immutable</h2>
   <p>Starting with v3, <code>prek-action</code> will no longer publish moving 
major or minor tags. References such as <code>j178/prek-action@v3</code> and 
<code>j178/[email protected]</code> will <strong>not</strong> be available.</p>
   <p>Moving tags can be retargeted after users adopt them, creating 
unnecessary supply-chain risk. Use an exact release tag or, for stronger 
protection, pin the action to a full commit SHA.</p>
   <blockquote>
   <p>[!TIP]
   Use an exact release tag:</p>
   <pre lang="yaml"><code>- uses: j178/[email protected]
   </code></pre>
   <p>Or, even better, pin the full commit SHA:</p>
   <pre lang="yaml"><code>- uses: 
j178/prek-action@4e14d07f9231acabce116ccfca13b13dd9755ece # v3.0.0
   </code></pre>
   </blockquote>
   <h2>What's Changed</h2>
   <ul>
   <li>Fix cache key hashing by <a 
href="https://github.com/akx";><code>@​akx</code></a> in <a 
href="https://redirect.github.com/j178/prek-action/pull/153";>j178/prek-action#153</a></li>
   <li>Drop floating version tag support by <a 
href="https://github.com/j178";><code>@​j178</code></a> in <a 
href="https://redirect.github.com/j178/prek-action/pull/170";>j178/prek-action#170</a></li>
   <li>Update known versions for prek 0.4.11 by <a 
href="https://github.com/j178";><code>@​j178</code></a> in <a 
href="https://redirect.github.com/j178/prek-action/pull/169";>j178/prek-action#169</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/j178/prek-action/compare/v2...v3.0.0";>https://github.com/j178/prek-action/compare/v2...v3.0.0</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/j178/prek-action/commit/4e14d07f9231acabce116ccfca13b13dd9755ece";><code>4e14d07</code></a>
 Drop floating version tag support (<a 
href="https://redirect.github.com/j178/prek-action/issues/170";>#170</a>)</li>
   <li><a 
href="https://github.com/j178/prek-action/commit/d8e544e9912c0fb7d1bf9c29e41ad70260c2e5a3";><code>d8e544e</code></a>
 Fix cache key hashing (<a 
href="https://redirect.github.com/j178/prek-action/issues/153";>#153</a>)</li>
   <li><a 
href="https://github.com/j178/prek-action/commit/cd7e67c2f14f90c6f58cb542a2b60d59af5de5db";><code>cd7e67c</code></a>
 Update known versions for prek 0.4.11 (<a 
href="https://redirect.github.com/j178/prek-action/issues/169";>#169</a>)</li>
   <li>See full diff in <a 
href="https://github.com/j178/prek-action/compare/5337cb91e0fa35a7ff31b9ca345126d8bbbcdf16...4e14d07f9231acabce116ccfca13b13dd9755ece";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.9
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/releases";>github/codeql-action/upload-sarif's
 releases</a>.</em></p>
   <blockquote>
   <h2>v4.37.9</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>v4.37.8</h2>
   <p>No user facing changes.</p>
   <h2>v4.37.7</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>v4.37.6</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>v4.37.5</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>v4.37.4</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action/upload-sarif's
 changelog</a>.</em></p>
   <blockquote>
   <h1>CodeQL Action Changelog</h1>
   <p>See the <a 
href="https://github.com/github/codeql-action/releases";>releases page</a> for 
the relevant changes to the CodeQL CLI and language packs.</p>
   <h2>[UNRELEASED]</h2>
   <p>No user facing changes.</p>
   <h2>4.37.9 - 26 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4";>2.26.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4106";>#4106</a></li>
   </ul>
   <h2>4.37.8 - 21 Aug 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.7 - 13 Aug 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3";>2.26.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4085";>#4085</a></li>
   </ul>
   <h2>4.37.6 - 04 Aug 2026</h2>
   <ul>
   <li>Changed the default filepath for the new remote file address format that 
was introduced in CodeQL Action 4.37.0 / 3.37.0 to 
<code>.github/codeql-config.yml</code> to align it with the suggested path that 
is used elsewhere. <a 
href="https://redirect.github.com/github/codeql-action/pull/4070";>#4070</a></li>
   </ul>
   <h2>4.37.5 - 03 Aug 2026</h2>
   <ul>
   <li>Fixed a bug where a network error while streaming the download of the 
CodeQL bundle could terminate the <code>init</code> Action instead of falling 
back to downloading the bundle before extracting it. <a 
href="https://redirect.github.com/github/codeql-action/pull/4061";>#4061</a></li>
   </ul>
   <h2>4.37.4 - 29 Jul 2026</h2>
   <ul>
   <li>This version of the CodeQL Action adds support for the 
<code>tools</code> input for the <code>codeql-action/init</code> step to be 
specified using a <code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <
 code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
   </ul>
   <h2>4.37.3 - 22 Jul 2026</h2>
   <p>No user facing changes.</p>
   <h2>4.37.2 - 21 Jul 2026</h2>
   <ul>
   <li>The new address format for the <code>config-file</code> input that was 
introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to 
the format described there, the <code>remote=</code> prefix can now be used to 
explicitly indicate that the input refers to a remote file. All previous input 
formats continue to be accepted as well. <a 
href="https://redirect.github.com/github/codeql-action/pull/4023";>#4023</a></li>
   <li>The CodeQL Action can now make use of <a 
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries";>configured
 private registries</a> in Default Setup to retrieve CodeQL configuration files 
from remote repositories that require authentication. This will allow customers 
to store their CodeQL configuration in a single repository that can then be 
referenced by Default Setup workflows in other repositories. We expect to roll 
this and other, related changes out to everyone in July. <a 
href="https://redirect.github.com/github/codeql-action/pull/4007";>#4007</a></li>
   </ul>
   <h2>4.37.1 - 16 Jul 2026</h2>
   <ul>
   <li><em>Upcoming breaking change</em>: Add a deprecation warning for 
customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL 
were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and 
will be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3956";>#3956</a></li>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1";>2.26.1</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4019";>#4019</a></li>
   </ul>
   <h2>4.37.0 - 08 Jul 2026</h2>
   <ul>
   <li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0";>2.26.0</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3995";>#3995</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/github/codeql-action/commit/cdf488f595d80d6e07e03d4674febd5ab45fa938";><code>cdf488f</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4107";>#4107</a> 
from github/update-v4.37.9-920ba7cd1</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/7243f38558d187dde99730d224bb47aa26a95306";><code>7243f38</code></a>
 Update changelog for v4.37.9</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/920ba7cd1596037e042122c00381eb16b397d68e";><code>920ba7c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4106";>#4106</a> 
from github/update-bundle/codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ecfa6e16817b8f490bc9a59baa391baf4fa3e3c2";><code>ecfa6e1</code></a>
 Add changelog note</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/adcdf4a70d247343cf9c29e0f7a6658b51c3a2b1";><code>adcdf4a</code></a>
 Update default bundle to codeql-bundle-v2.26.4</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/486fec2a3ea2626afcd8c7e9208b4f515078dd7e";><code>486fec2</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4099";>#4099</a> 
from github/update-supported-enterprise-server-versions</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/134624c67b20869c2aaa36dafa726375b78a5d76";><code>134624c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4101";>#4101</a> 
from github/dependabot/npm_and_yarn/npm-minor-457d82...</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/ff43db8f982a368288f117354fb8d046e937124c";><code>ff43db8</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4103";>#4103</a> 
from github/mergeback/v4.37.8-to-main-db488dde</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/4605e03a74cf891614c4d76f82384a16c1c11816";><code>4605e03</code></a>
 Rebuild</li>
   <li><a 
href="https://github.com/github/codeql-action/commit/099c869cad6bf3b88657154d4ae47ffed27e632d";><code>099c869</code></a>
 Update changelog and version after v4.37.8</li>
   <li>Additional commits viewable in <a 
href="https://github.com/github/codeql-action/compare/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81...cdf488f595d80d6e07e03d4674febd5ab45fa938";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to