Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 
4.37.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a 
href="https://github.com/github/codeql-action/releases";>github/codeql-action's 
releases</a>.</em></p>
<blockquote>
<h2>v4.37.4</h2>
<ul>
<li>This version of the CodeQL Action adds support for the <code>tools</code> 
input for the <code>codeql-action/init</code> step to be specified using a 
<code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
</ul>
<h2>v4.37.3</h2>
<p>No user facing changes.</p>
<h2>v4.37.2</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that was 
introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to 
the format described there, the <code>remote=</code> prefix can now be used to 
explicitly indicate that the input refers to a remote file. All previous input 
formats continue to be accepted as well. <a 
href="https://redirect.github.com/github/codeql-action/pull/4023";>#4023</a></li>
<li>The CodeQL Action can now make use of <a 
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries";>configured
 private registries</a> in Default Setup to retrieve CodeQL configuration files 
from remote repositories that require authentication. This will allow customers 
to store their CodeQL configuration in a single repository that can then be 
referenced by Default Setup workflows in other repositories. We expect to roll 
this and other, related changes out to everyone in July. <a 
href="https://redirect.github.com/github/codeql-action/pull/4007";>#4007</a></li>
</ul>
<h2>v4.37.1</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for customers 
using CodeQL version 2.20.6 and earlier. These versions of CodeQL were 
discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will 
be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3956";>#3956</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1";>2.26.1</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4019";>#4019</a></li>
</ul>
<h2>v4.37.0</h2>
<ul>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0";>2.26.0</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3995";>#3995</a></li>
<li>In addition to the existing input format, the <code>config-file</code> 
input for the <code>codeql-action/init</code> step will soon support a new 
<code>[owner/]repo[@ref][:path]</code> format. All components except the 
repository name are optional. If omitted, <code>owner</code> defaults to the 
same owner as the repository the analysis is running for, <code>ref</code> to 
<code>main</code>, and <code>path</code> to 
<code>.github/codeql-action.yaml</code>. Support for this format ships in this 
version of the CodeQL Action, but will only be enabled over the coming weeks. 
<a 
href="https://redirect.github.com/github/codeql-action/pull/3973";>#3973</a></li>
</ul>
<h2>v4.36.3</h2>
<p>No user facing changes.</p>
<h2>v4.36.2</h2>
<ul>
<li>Cache CodeQL CLI version information across Actions steps. <a 
href="https://redirect.github.com/github/codeql-action/pull/3943";>#3943</a></li>
<li>Reduce requests while waiting for analysis processing by using exponential 
backoff when polling SARIF processing status. <a 
href="https://redirect.github.com/github/codeql-action/pull/3937";>#3937</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6";>2.25.6</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3948";>#3948</a></li>
</ul>
<h2>v4.36.1</h2>
<p>No user facing changes.</p>
<h2>v4.36.0</h2>
<ul>
<li><em>Breaking change</em>: Bump the minimum required CodeQL bundle version 
to 2.19.4. <a 
href="https://redirect.github.com/github/codeql-action/pull/3894";>#3894</a></li>
<li>Add support for SHA-256 Git object IDs. <a 
href="https://redirect.github.com/github/codeql-action/pull/3893";>#3893</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5";>2.25.5</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3926";>#3926</a></li>
</ul>
<h2>v4.35.5</h2>
<ul>
<li>We have improved how the JavaScript bundles for the CodeQL Action are 
generated to avoid duplication across bundles and reduce the size of the 
repository by around 70%. This should have no effect on the runtime behaviour 
of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3899";>#3899</a></li>
<li>For performance and accuracy reasons, <a 
href="https://redirect.github.com/github/roadmap/issues/1158";>improved 
incremental analysis</a> will now only be enabled on a pull request when 
diff-informed analysis is also enabled for that run. If diff-informed analysis 
is unavailable (for example, because the PR diff ranges could not be computed), 
the action will fall back to a full analysis. <a 
href="https://redirect.github.com/github/codeql-action/pull/3791";>#3791</a></li>
<li>If multiple inputs are provided for the GitHub-internal 
<code>analysis-kinds</code> input, only <code>code-scanning</code> will be 
enabled. The <code>analysis-kinds</code> input is experimental, for 
GitHub-internal use only, and may change without notice at any time. <a 
href="https://redirect.github.com/github/codeql-action/pull/3892";>#3892</a></li>
<li>Added an experimental change which, when running a Code Scanning analysis 
for a PR with <a 
href="https://redirect.github.com/github/roadmap/issues/1158";>improved 
incremental analysis</a> enabled, prefers CodeQL CLI versions that have a 
cached overlay-base database for the configured languages. This speeds up 
analysis for a repository when there is not yet a cached overlay-base database 
for the latest CLI version. We expect to roll this change out to everyone in 
May. <a 
href="https://redirect.github.com/github/codeql-action/pull/3880";>#3880</a></li>
</ul>
<h2>v4.35.4</h2>
<ul>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.4";>2.25.4</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3881";>#3881</a></li>
</ul>
<h2>v4.35.3</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for customers 
using CodeQL version 2.19.3 and earlier. These versions of CodeQL were 
discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will 
be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3837";>#3837</a></li>
<li>Configurations for private registries that use Cloudsmith or GCP OIDC are 
now accepted. <a 
href="https://redirect.github.com/github/codeql-action/pull/3850";>#3850</a></li>
<li>Best-effort connection tests for private registries now use 
<code>GET</code> requests instead of <code>HEAD</code> for better compatibility 
with various registry implementations. For NuGet feeds, the test is now always 
performed against the service index. <a 
href="https://redirect.github.com/github/codeql-action/pull/3853";>#3853</a></li>
<li>Fixed a bug where two diagnostics produced within the same millisecond 
could overwrite each other on disk, causing one of them to be lost. <a 
href="https://redirect.github.com/github/codeql-action/pull/3852";>#3852</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.3";>2.25.3</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3865";>#3865</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a 
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action's
 changelog</a>.</em></p>
<blockquote>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the <code>tools</code> 
input for the <code>codeql-action/init</code> step to be specified using a 
<code>github-codeql-tools</code> <a 
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization";>repository
 property</a>. This feature will gradually be rolled out following the release 
of this version. Once rolled out, this allows for the CodeQL CLI version that 
is used in GitHub-managed workflows, such as Default Setup, to be set to a 
custom value. For example, customers who run into issues with rate limits when 
a new CodeQL CLI version is released can set the value to 
<code>toolcache</code> to always use the CodeQL CLI version that is available 
in the runner toolcache. For Advanced Setup workflows, the value provided for 
<code>tools</code> in the workflow definition always takes precedence unless 
the value of the repository property starts with <code>!</code>. <a 
href="https://redirect.github.com/github/codeql-action/pull/4037";>#4037</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2";>2.26.2</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4051";>#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that was 
introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to 
the format described there, the <code>remote=</code> prefix can now be used to 
explicitly indicate that the input refers to a remote file. All previous input 
formats continue to be accepted as well. <a 
href="https://redirect.github.com/github/codeql-action/pull/4023";>#4023</a></li>
<li>The CodeQL Action can now make use of <a 
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries";>configured
 private registries</a> in Default Setup to retrieve CodeQL configuration files 
from remote repositories that require authentication. This will allow customers 
to store their CodeQL configuration in a single repository that can then be 
referenced by Default Setup workflows in other repositories. We expect to roll 
this and other, related changes out to everyone in July. <a 
href="https://redirect.github.com/github/codeql-action/pull/4007";>#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for customers 
using CodeQL version 2.20.6 and earlier. These versions of CodeQL were 
discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will 
be unsupported by the next minor release of the CodeQL Action. <a 
href="https://redirect.github.com/github/codeql-action/pull/3956";>#3956</a></li>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1";>2.26.1</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/4019";>#4019</a></li>
</ul>
<h2>4.37.0 - 08 Jul 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a 
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0";>2.26.0</a>.
 <a 
href="https://redirect.github.com/github/codeql-action/pull/3995";>#3995</a></li>
<li>In addition to the existing input format, the <code>config-file</code> 
input for the <code>codeql-action/init</code> step will soon support a new 
<code>[owner/]repo[@ref][:path]</code> format. All components except the 
repository name are optional. If omitted, <code>owner</code> defaults to the 
same owner as the repository the analysis is running for, <code>ref</code> to 
<code>main</code>, and <code>path</code> to 
<code>.github/codeql-action.yaml</code>. Support for this format ships in this 
version of the CodeQL Action, but will only be enabled over the coming weeks. 
<a 
href="https://redirect.github.com/github/codeql-action/pull/3973";>#3973</a></li>
</ul>
<h2>4.36.3 - 01 Jul 2026</h2>
<p>No user facing changes.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a 
href="https://github.com/github/codeql-action/commit/18420e3271f74589575af831a523c833acda327f";><code>18420e3</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4043";>#4043</a> 
from github/mbg/ts/changelog</li>
<li><a 
href="https://github.com/github/codeql-action/commit/7e8d8970f03ec5a78ab372fc0778e8e4194111a5";><code>7e8d897</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4046";>#4046</a> 
from github/mbg/repo-prop/code-quality</li>
<li><a 
href="https://github.com/github/codeql-action/commit/2d4c474c2ca5ea2965b9e53fabb7b67b0100016c";><code>2d4c474</code></a>
 Log <code>!analysisKindSupported</code> case</li>
<li><a 
href="https://github.com/github/codeql-action/commit/98c05a17d327d7c4055fca83114434ab56baacf6";><code>98c05a1</code></a>
 Fix argument validation in <code>rollback-changelog.ts</code></li>
<li><a 
href="https://github.com/github/codeql-action/commit/8289a49271cbb335d374e7e2e7a50c1576be0afe";><code>8289a49</code></a>
 Ignore repository property for unsupported analysis kinds</li>
<li><a 
href="https://github.com/github/codeql-action/commit/2a8731cc0636c612147a349ccc88166bd482a9e1";><code>2a8731c</code></a>
 Move <code>config-file</code> computation after determining the 
<code>analysisKinds</code></li>
<li><a 
href="https://github.com/github/codeql-action/commit/3434fbbc53af0fe47685ef3897703b39ef77b5cb";><code>3434fbb</code></a>
 Merge pull request <a 
href="https://redirect.github.com/github/codeql-action/issues/4044";>#4044</a> 
from github/mbg/ff/promote-toolcache</li>
<li><a 
href="https://github.com/github/codeql-action/commit/3013ac07bdb913cf5b7a1a8a63fe51422ce5a91e";><code>3013ac0</code></a>
 Promote <code>AllowToolcacheInput</code> feature</li>
<li><a 
href="https://github.com/github/codeql-action/commit/74b15aa2c6c649153cb2e5f7a9d3bd2f0c8f82d1";><code>74b15aa</code></a>
 Install JS deps if needed in <code>post-release-mergeback</code> workflow</li>
<li><a 
href="https://github.com/github/codeql-action/commit/f00f809405a0571f02079a483378ba1102bd3d1e";><code>f00f809</code></a>
 Fix checking keys rather than values</li>
<li>Additional commits viewable in <a 
href="https://github.com/github/codeql-action/compare/v4...v4.37.4";>compare 
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=4&new-version=4.37.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't alter 
it yourself. You can also trigger a rebase manually by commenting `@dependabot 
rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have 
been made to it
- `@dependabot show <dependency name> ignore conditions` will show all of the 
ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot 
creating any more for this dependency (unless you reopen the PR or upgrade to 
it yourself)


</details>
You can view, comment on, or merge this pull request online at:

  https://github.com/geany/geany/pull/4639

-- Commit Summary --

  * Bump github/codeql-action from 4 to 4.37.4

-- File Changes --

    M .github/workflows/codeql.yml (6)

-- Patch Links --

https://github.com/geany/geany/pull/4639.patch
https://github.com/geany/geany/pull/4639.diff

-- 
Reply to this email directly or view it on GitHub:
https://github.com/geany/geany/pull/4639
You are receiving this because you are subscribed to this thread.

Message ID: <geany/geany/pull/[email protected]>

Reply via email to