Title: Bump the actions group with 2 updates by dependabot[bot] · Pull Request #82 · matplotlib/matplotlib.org · GitHub
Open Graph Title: Bump the actions group with 2 updates by dependabot[bot] · Pull Request #82 · matplotlib/matplotlib.org
X Title: Bump the actions group with 2 updates by dependabot[bot] · Pull Request #82 · matplotlib/matplotlib.org
Description: Bumps the actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze.
Updates github/codeql-action/init from 4.36.3 to 4.37.0
Release notes
Sourced from github/codeql-action/init's releases.
v4.37.0
Update default CodeQL bundle version to 2.26.0. #3995
In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
Changelog
Sourced from github/codeql-action/init's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
4.37.0 - 08 Jul 2026
Update default CodeQL bundle version to 2.26.0. #3995
In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
4.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
Cache CodeQL CLI version information across Actions steps. #3943
Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
Add support for SHA-256 Git object IDs. #3893
Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
Update default CodeQL bundle version to 2.25.4. #3881
4.35.3 - 01 May 2026
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #3837
Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #3850
Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853
Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #3852
... (truncated)
Commits
99df26d Merge pull request #3996 from github/update-v4.37.0-c7c896d71
31c2707 Add changenote for #3973
72df218 Update changelog for v4.37.0
c7c896d Merge pull request #3995 from github/update-bundle/codeql-bundle-v2.26.0
3f34ff0 Add changelog note
43bec09 Update default bundle to codeql-bundle-v2.26.0
f58f0d1 Merge pull request #3973 from github/mbg/repo-props/config-file-shorthands
7dc37cb Merge remote-tracking branch 'origin/main' into mbg/repo-props/config-file-sh...
8e22350 Thread ActionState to initConfig
69c9e8c Mark some status-report imports as type-only to avoid circular dependencies
Additional commits viewable in compare view
Updates github/codeql-action/analyze from 4.36.3 to 4.37.0
Release notes
Sourced from github/codeql-action/analyze's releases.
v4.37.0
Update default CodeQL bundle version to 2.26.0. #3995
In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
Changelog
Sourced from github/codeql-action/analyze's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
4.37.0 - 08 Jul 2026
Update default CodeQL bundle version to 2.26.0. #3995
In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
4.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
Cache CodeQL CLI version information across Actions steps. #3943
Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
Add support for SHA-256 Git object IDs. #3893
Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
Update default CodeQL bundle version to 2.25.4. #3881
4.35.3 - 01 May 2026
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #3837
Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #3850
Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853
Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #3852
... (truncated)
Commits
99df26d Merge pull request #3996 from github/update-v4.37.0-c7c896d71
31c2707 Add changenote for #3973
72df218 Update changelog for v4.37.0
c7c896d Merge pull request #3995 from github/update-bundle/codeql-bundle-v2.26.0
3f34ff0 Add changelog note
43bec09 Update default bundle to codeql-bundle-v2.26.0
f58f0d1 Merge pull request #3973 from github/mbg/repo-props/config-file-shorthands
7dc37cb Merge remote-tracking branch 'origin/main' into mbg/repo-props/config-file-sh...
8e22350 Thread ActionState to initConfig
69c9e8c Mark some status-report imports as type-only to avoid circular dependencies
Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show
Open Graph Description: Bumps the actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze. Updates github/codeql-action/init from 4.36.3 to 4.37.0 Release notes Sourced from github/codeql...
X Description: Bumps the actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze. Updates github/codeql-action/init from 4.36.3 to 4.37.0 Release notes Sourced from github/codeql...
Opengraph URL: https://github.com/matplotlib/matplotlib.org/pull/82
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:be62a351-91e5-a5d2-8c2e-3f2a8d1b2f94 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | EC8A:20569A:6FD676:9FEB79:6A63761A |
| html-safe-nonce | e01bfbd6c945f41f777452071ee438971e9be1d651c01c789d1ce62746767323 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJFQzhBOjIwNTY5QTo2RkQ2NzY6OUZFQjc5OjZBNjM3NjFBIiwidmlzaXRvcl9pZCI6IjY4NDE3ODc4Mzk1MDY3NzM1MzAiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | e3402a243d69a2fece29eef8fbe9acc9daa68b4091a85cf2e27d74d2a88de53c |
| hovercard-subject-tag | pull_request:4041186793 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/matplotlib/matplotlib.org/pull/82/files |
| twitter:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| og:image:alt | Bumps the actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze. Updates github/codeql-action/init from 4.36.3 to 4.37.0 Release notes Sourced from github/codeql... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 15e78334bb345f3864e70c5a376ed0383374123629b9e3022398d9431f6cd8bf |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/matplotlib/matplotlib.org git https://github.com/matplotlib/matplotlib.org.git |
| octolytics-dimension-user_id | 215947 |
| octolytics-dimension-user_login | matplotlib |
| octolytics-dimension-repository_id | 457721632 |
| octolytics-dimension-repository_nwo | matplotlib/matplotlib.org |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 457721632 |
| octolytics-dimension-repository_network_root_nwo | matplotlib/matplotlib.org |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 51da2d8d0a841a1393b806a6559fa9ad757e1666 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width