Skip to content

build(deps): bump github/codeql-action from 2 to 3#1389

Merged
lvca merged 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-3
Dec 18, 2023
Merged

build(deps): bump github/codeql-action from 2 to 3#1389
lvca merged 1 commit into
mainfrom
dependabot/github_actions/github/codeql-action-3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Dec 18, 2023

Bumps github/codeql-action from 2 to 3.

Release notes

Sourced from github/codeql-action's releases.

CodeQL Bundle v2.15.4

Bundles CodeQL CLI v2.15.4

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.4:

CodeQL Bundle

Bundles CodeQL CLI v2.15.3

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.3:

CodeQL Bundle

Bundles CodeQL CLI v2.15.2

Includes the following CodeQL language packs from github/codeql@codeql-cli/v2.15.2:

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

Commits
  • 3a9f6a8 update javascript files
  • cc4fead update version in various hardcoded locations
  • 183559c Merge branch 'main' into update-bundle/codeql-bundle-v2.15.4
  • 5b52b36 reintroduce PR check that confirm action can be still be compiled on node16
  • 5b19bef change to node20 for all actions
  • f2d0c2e upgrade node type definitions
  • d651fbc change to node20 for all actions
  • 382a50a Merge pull request #2021 from github/mergeback/v2.22.9-to-main-c0d1daa7
  • 458b422 Update checked-in dependencies
  • 5e0f9db Update changelog and version after v2.22.9
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2 to 3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v2...v3)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions labels Dec 18, 2023
@lvca lvca self-assigned this Dec 18, 2023
@lvca lvca added this to the 23.12.1 milestone Dec 18, 2023
@lvca lvca merged commit 1cfda17 into main Dec 18, 2023
@dependabot dependabot Bot deleted the dependabot/github_actions/github/codeql-action-3 branch December 18, 2023 06:07
mergify Bot added a commit that referenced this pull request Jun 7, 2026
Bumps [neo4j-driver](https://github.com/neo4j/neo4j-javascript-driver) from 6.0.1 to 6.1.0.
Release notes

*Sourced from [neo4j-driver's releases](https://github.com/neo4j/neo4j-javascript-driver/releases).*

> v6.1.0
> ------
>
> Introduces the full, stabilized version of Object Mapping, as well as very simple retries that should make `Session.run()` handle rate-limiting on Aura more gracefully. Alongside a number of minor fixes.
>
> #### ⭐ New Features
>
> ---
>
> * Stabilized Record Object Mapping and introduced Parameter Object Mapping. [#1362](https://github.com/neo4j/neo4j-javascript-driver/pull/1362) [#1407](https://github.com/neo4j/neo4j-javascript-driver/pull/1407) NOTE: A usage guide can be found in the PR description on [#1407](https://github.com/neo4j/neo4j-javascript-driver/pull/1407)
> * Add single-shot retry for Idempotent errors on `Session.run()`, these will currently only trigger on errors caused by Aura rate-limiting. [#1404](https://github.com/neo4j/neo4j-javascript-driver/pull/1404)
>
> #### 🔧 Fixes
>
> ---
>
> * Correct TypeScript exports for Record Object Mapping. [#1359](https://github.com/neo4j/neo4j-javascript-driver/pull/1359)
> * Improve error message for starting work on a busy session. [#1363](https://github.com/neo4j/neo4j-javascript-driver/pull/1363)
> * Fix error handling for unexpected errors in Authentication Provider. [#1366](https://github.com/neo4j/neo4j-javascript-driver/pull/1366)
> * Fix issue causing SNI deprecation warnings when correcting to an IP. [#1369](https://github.com/neo4j/neo4j-javascript-driver/pull/1369)
> * Eagerly send discard on close if connection is waiting to pull more, solves issue related to corner-case missuse that could make the driver release an unclean connection to the pool. [#1403](https://github.com/neo4j/neo4j-javascript-driver/pull/1403)
> * Do not mark Result as consumed when `Result.keys()` is awaited. [#1402](https://github.com/neo4j/neo4j-javascript-driver/pull/1402)
>
> #### 🧹 Housekeeping
>
> ---
>
> * Improve `Session.run()` docs with warnings on the auto-commit nature of the function. [#1389](https://github.com/neo4j/neo4j-javascript-driver/pull/1389) [#1390](https://github.com/neo4j/neo4j-javascript-driver/pull/1390)
> * Update docs reference to dbms.setTXMetaData which is renamed to tx.setMetaData.[#1408](https://github.com/neo4j/neo4j-javascript-driver/pull/1408)


Commits

* [`81f7d82`](neo4j/neo4j-javascript-driver@81f7d82) bump deno to 6.1.0 ([#1421](https://github.com/neo4j/neo4j-javascript-driver/issues/1421))
* [`a06109c`](neo4j/neo4j-javascript-driver@a06109c) Pre-release changes to Object Mapping ([#1407](https://github.com/neo4j/neo4j-javascript-driver/issues/1407))
* [`2595d67`](neo4j/neo4j-javascript-driver@2595d67) Update docs reference to dbms.setTXMetaData ([#1408](https://github.com/neo4j/neo4j-javascript-driver/issues/1408))
* [`18c681a`](neo4j/neo4j-javascript-driver@18c681a) Result.close() send discard directly if waiting for more ([#1403](https://github.com/neo4j/neo4j-javascript-driver/issues/1403))
* [`a98f9c5`](neo4j/neo4j-javascript-driver@a98f9c5) Add retries for idempotent errors on Session.run() ([#1404](https://github.com/neo4j/neo4j-javascript-driver/issues/1404))
* [`d884171`](neo4j/neo4j-javascript-driver@d884171) Development Dependency updates and tightening security ([#1405](https://github.com/neo4j/neo4j-javascript-driver/issues/1405))
* [`6714eba`](neo4j/neo4j-javascript-driver@6714eba) Fix error piping in gulpfile ([#1406](https://github.com/neo4j/neo4j-javascript-driver/issues/1406))
* [`2caa88a`](neo4j/neo4j-javascript-driver@2caa88a) Expand Record Object Mapping to allow Parameter Mapping ([#1362](https://github.com/neo4j/neo4j-javascript-driver/issues/1362))
* [`6357e65`](neo4j/neo4j-javascript-driver@6357e65) do not add "onCompleted" on keys observer ([#1402](https://github.com/neo4j/neo4j-javascript-driver/issues/1402))
* [`1ec186a`](neo4j/neo4j-javascript-driver@1ec186a) TestKit backend: fix BigInt serialization ([#1397](https://github.com/neo4j/neo4j-javascript-driver/issues/1397))
* Additional commits viewable in [compare view](neo4j/neo4j-javascript-driver@6.0.1...6.1.0)

Install script changes

This version modifies `prepare` script that runs during installation. Review the package contents before updating.

  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=neo4j-driver&package-manager=npm\_and\_yarn&previous-version=6.0.1&new-version=6.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant