Bump github/codeql-action from 1.0.26 to 2.3.2#386
Bump github/codeql-action from 1.0.26 to 2.3.2#386dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1.0.26 to 2.3.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@5f53256...f3feb00) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
2e46202 to
7dd5c4c
Compare
There was a problem hiding this comment.
Please find ChatGPT generated code comments below
.github/workflows/codeql-analysis.yml:This pull request updates the CodeQL tools versions used in the workflow by updating the uses fields in the Initialize CodeQL, Autobuild, and Perform CodeQL Analysis steps.
From an engineering best practices perspective, this update is good because we always want to stay up to date with the latest versions of tools and dependencies we use in our software development workflow.
Therefore, there are no code review comments.
.github/workflows/scorecard-analysis.yml:The only change in this pull request is updating the version of the github/codeql-action/upload-sarif action being used. This looks like a valid update to a newer version of the action, which could contain important bug fixes or security improvements.
Therefore, I have no comments on this code change.
Codecov ReportPatch coverage has no change and project coverage change:
📣 This organization is not using Codecov’s GitHub App Integration. We recommend you install it so Codecov can continue to function properly for your repositories. Learn more Additional details and impacted files@@ Coverage Diff @@
## main #386 +/- ##
==========================================
+ Coverage 68.38% 68.86% +0.47%
==========================================
Files 15 15
Lines 1670 1670
==========================================
+ Hits 1142 1150 +8
+ Misses 409 399 -10
- Partials 119 121 +2 ☔ View full report in Codecov by Sentry. |
|
Superseded by #392. |
Bumps github/codeql-action from 1.0.26 to 2.3.2.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
f3feb00Merge pull request #1662 from github/update-v2.3.2-8b12d99ee1c9e206Update changelog for v2.3.28b12d99Fix bug where run attempt was reported as run ID (#1661)dcf71cfMerge pull request #1660 from github/mergeback/v2.3.1-to-main-8662eabe194450bUpdate checked-in dependenciese78ef45Update changelog and version after v2.3.18662eabMerge pull request #1659 from github/update-v2.3.1-da583b07a1f2f707Update changelog for v2.3.1da583b0Addworkload_run_attemptto analysis upload (#1658)a9648eaThrow full error for CLI bundle download (#1657)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)