Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
5091e42
Overlay: Remove repository owner restriction
kaspersv Nov 13, 2025
497c7f6
Update changelog and version after v4.31.3
github-actions[bot] Nov 13, 2025
246edb9
Rebuild
github-actions[bot] Nov 13, 2025
86b7d4f
Merge pull request #3294 from github/mergeback/v4.31.3-to-main-014f16e7
mbg Nov 13, 2025
85f1517
Merge pull request #3285 from github/kaspersv/remove-overlay-org-rest…
kaspersv Nov 14, 2025
b9620e1
Bump js-yaml from 4.1.0 to 4.1.1
dependabot[bot] Nov 15, 2025
8c254d0
Rebuild
github-actions[bot] Nov 15, 2025
c1a2b73
Merge pull request #3301 from github/dependabot/npm_and_yarn/js-yaml-…
mbg Nov 16, 2025
ed3a013
Change v3 deprecation message to warning.
mario-campos Nov 17, 2025
023fd08
Add CHANGELOG.md entry for "v3 deprecation" to warning change.
mario-campos Nov 17, 2025
fc329e3
Revert "Add CHANGELOG.md entry for "v3 deprecation" to warning change."
mario-campos Nov 17, 2025
c418a0f
Bump ruby/setup-ruby
dependabot[bot] Nov 17, 2025
e546fff
Rebuild
github-actions[bot] Nov 17, 2025
07eae64
Merge pull request #3303 from github/mario-campos/v3-core-warning
mario-campos Nov 17, 2025
7bcdb4b
Add additional options to PR template and clarify some
mbg Nov 17, 2025
ffa63f0
Merge pull request #3307 from github/dependabot/github_actions/dot-gi…
mbg Nov 17, 2025
de12435
Merge pull request #3308 from github/mbg/pr-template/nov25
mbg Nov 18, 2025
528362a
Bump `glob` to at least `11.1.0`
mbg Nov 18, 2025
70434f6
Merge pull request #3311 from github/mbg/deps/bump-glob
mbg Nov 18, 2025
c9cb6f9
Update changelog for v4.31.4
github-actions[bot] Nov 18, 2025
e12f017
Merge pull request #3312 from github/update-v4.31.4-70434f6dd
mbg Nov 18, 2025
e3cb862
Revert "Update version and changelog for v3.31.3"
github-actions[bot] Nov 18, 2025
7ab96a0
Revert "Rebuild"
github-actions[bot] Nov 18, 2025
1f1c162
Merge remote-tracking branch 'origin/releases/v4' into backport-v3.31…
github-actions[bot] Nov 18, 2025
f58938a
Update version and changelog for v3.31.4
github-actions[bot] Nov 18, 2025
9031cd9
Rebuild
github-actions[bot] Nov 18, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update version and changelog for v3.31.4
  • Loading branch information
github-actions[bot] committed Nov 18, 2025
commit f58938aee27eb1b0fe2f9769e223b76c030d8c91
25 changes: 9 additions & 16 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,40 +2,40 @@

See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.

## 4.31.4 - 18 Nov 2025
## 3.31.4 - 18 Nov 2025

No user facing changes.

## 4.31.3 - 13 Nov 2025
## 3.31.3 - 13 Nov 2025

- CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see [Upcoming deprecation of CodeQL Action v3](https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/).
- Update default CodeQL bundle version to 2.23.5. [#3288](https://github.com/github/codeql-action/pull/3288)

## 4.31.2 - 30 Oct 2025
## 3.31.2 - 30 Oct 2025

No user facing changes.

## 4.31.1 - 30 Oct 2025
## 3.31.1 - 30 Oct 2025

- The `add-snippets` input has been removed from the `analyze` action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

## 4.31.0 - 24 Oct 2025
## 3.31.0 - 24 Oct 2025

- Bump minimum CodeQL bundle version to 2.17.6. [#3223](https://github.com/github/codeql-action/pull/3223)
- When SARIF files are uploaded by the `analyze` or `upload-sarif` actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the `upload-sarif` action. For `analyze`, this may affect Advanced Setup for CodeQL users who specify a value other than `always` for the `upload` input. [#3222](https://github.com/github/codeql-action/pull/3222)

## 4.30.9 - 17 Oct 2025
## 3.30.9 - 17 Oct 2025

- Update default CodeQL bundle version to 2.23.3. [#3205](https://github.com/github/codeql-action/pull/3205)
- Experimental: A new `setup-codeql` action has been added which is similar to `init`, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. [#3204](https://github.com/github/codeql-action/pull/3204)

## 4.30.8 - 10 Oct 2025
## 3.30.8 - 10 Oct 2025

No user facing changes.

## 4.30.7 - 06 Oct 2025
## 3.30.7 - 06 Oct 2025

- [v4+ only] The CodeQL Action now runs on Node.js v24. [#3169](https://github.com/github/codeql-action/pull/3169)
No user facing changes.

## 3.30.6 - 02 Oct 2025

Expand Down Expand Up @@ -271,17 +271,13 @@ No user facing changes.
## 3.26.12 - 07 Oct 2024

- _Upcoming breaking change_: Add a deprecation warning for customers using CodeQL version 2.14.5 and earlier. These versions of CodeQL were discontinued on 24 September 2024 alongside GitHub Enterprise Server 3.10, and will be unsupported by CodeQL Action versions 3.27.0 and later and versions 2.27.0 and later. [#2520](https://github.com/github/codeql-action/pull/2520)

- If you are using one of these versions, please update to CodeQL CLI version 2.14.6 or later. For instance, if you have specified a custom version of the CLI using the 'tools' input to the 'init' Action, you can remove this input to use the default version.

- Alternatively, if you want to continue using a version of the CodeQL CLI between 2.13.5 and 2.14.5, you can replace `github/codeql-action/*@v3` by `github/codeql-action/*@v3.26.11` and `github/codeql-action/*@v2` by `github/codeql-action/*@v2.26.11` in your code scanning workflow to ensure you continue using this version of the CodeQL Action.

## 3.26.11 - 03 Oct 2024

- _Upcoming breaking change_: Add support for using `actions/download-artifact@v4` to programmatically consume CodeQL Action debug artifacts.

Starting November 30, 2024, GitHub.com customers will [no longer be able to use `actions/download-artifact@v3`](https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/). Therefore, to avoid breakage, customers who programmatically download the CodeQL Action debug artifacts should set the `CODEQL_ACTION_ARTIFACT_V4_UPGRADE` environment variable to `true` and bump `actions/download-artifact@v3` to `actions/download-artifact@v4` in their workflows. The CodeQL Action will enable this behavior by default in early November and workflows that have not yet bumped `actions/download-artifact@v3` to `actions/download-artifact@v4` will begin failing then.

This change is currently unavailable for GitHub Enterprise Server customers, as `actions/upload-artifact@v4` and `actions/download-artifact@v4` are not yet compatible with GHES.
- Update default CodeQL bundle version to 2.19.1. [#2519](https://github.com/github/codeql-action/pull/2519)

Expand Down Expand Up @@ -404,12 +400,9 @@ No user facing changes.
## 3.25.0 - 15 Apr 2024

- The deprecated feature for extracting dependencies for a Python analysis has been removed. [#2224](https://github.com/github/codeql-action/pull/2224)

As a result, the following inputs and environment variables are now ignored:

- The `setup-python-dependencies` input to the `init` Action
- The `CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION` environment variable

We recommend removing any references to these from your workflows. For more information, see the release notes for CodeQL Action v3.23.0 and v2.23.0.
- Automatically overwrite an existing database if found on the filesystem. [#2229](https://github.com/github/codeql-action/pull/2229)
- Bump the minimum CodeQL bundle version to 2.12.6. [#2232](https://github.com/github/codeql-action/pull/2232)
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codeql",
"version": "4.31.4",
"version": "3.31.4",
"private": true,
"description": "CodeQL action",
"scripts": {
Expand Down
Loading