Skip to content

Chore(deps): Bump github/codeql-action from 4.31.6 to 4.31.7#28

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/github/codeql-action-4.31.7
Closed

Chore(deps): Bump github/codeql-action from 4.31.6 to 4.31.7#28
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/github/codeql-action-4.31.7

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 8, 2025

Bumps github/codeql-action from 4.31.6 to 4.31.7.

Release notes

Sourced from github/codeql-action's releases.

v4.31.7

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.7 - 05 Dec 2025

  • Update default CodeQL bundle version to 2.23.7. #3343

See the full CHANGELOG.md for more information.

Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.31.7 - 05 Dec 2025

  • Update default CodeQL bundle version to 2.23.7. #3343

4.31.6 - 01 Dec 2025

No user facing changes.

4.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #3321

4.31.4 - 18 Nov 2025

No user facing changes.

4.31.3 - 13 Nov 2025

  • CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
  • Update default CodeQL bundle version to 2.23.5. #3288

4.31.2 - 30 Oct 2025

No user facing changes.

4.31.1 - 30 Oct 2025

  • The add-snippets input has been removed from the analyze action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

4.31.0 - 24 Oct 2025

  • Bump minimum CodeQL bundle version to 2.17.6. #3223
  • When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #3222

4.30.9 - 17 Oct 2025

  • Update default CodeQL bundle version to 2.23.3. #3205
  • Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204

4.30.8 - 10 Oct 2025

No user facing changes.

... (truncated)

Commits
  • cf1bb45 Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
  • f4ebe95 Update changelog for v4.31.7
  • f5c63fa Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
  • a2c01e7 Add changelog note
  • ac34c13 Update default bundle to codeql-bundle-v2.23.7
  • 267c467 Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d264...
  • aeabef7 Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
  • 78357d3 Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
  • d61a6fa Update CLI config test to account for overlay db changes on PRs
  • ce27e95 Rebuild
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Dec 8, 2025
@github-actions
Copy link

github-actions bot commented Dec 8, 2025

PR: #28
Mode: squash
Topic: GH-releng-gerrit_to_platform-28
Change-Ids:
I05c7d4c5c9d9385c1888e6b66eb7f38f1dfba057
GitHub-Hash: 7ec47aef36adcd66

@github-actions
Copy link

github-actions bot commented Dec 8, 2025

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/releng/gerrit_to_platform/+/73961

lfit-replication pushed a commit that referenced this pull request Dec 31, 2025
Bumps github/codeql-action from 4.31.6 to 4.31.7.
## Release notes

Sourced from github/codeql-action's releases.

v4.31.7
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.7 - 05 Dec 2025

Update default CodeQL bundle version to 2.23.7. #3343

See the full CHANGELOG.md for more information.

## Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.31.7 - 05 Dec 2025

Update default CodeQL bundle version to 2.23.7. #3343

4.31.6 - 01 Dec 2025
No user facing changes.
4.31.5 - 24 Nov 2025

Update default CodeQL bundle version to 2.23.6. #3321

4.31.4 - 18 Nov 2025
No user facing changes.
4.31.3 - 13 Nov 2025

CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
Update default CodeQL bundle version to 2.23.5. #3288

4.31.2 - 30 Oct 2025
No user facing changes.
4.31.1 - 30 Oct 2025

The add-snippets input has been removed from the analyze action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

4.31.0 - 24 Oct 2025

Bump minimum CodeQL bundle version to 2.17.6. #3223
When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #3222

4.30.9 - 17 Oct 2025

Update default CodeQL bundle version to 2.23.3. #3205
Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204

4.30.8 - 10 Oct 2025
No user facing changes.

... (truncated)

## Commits

cf1bb45 Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
f4ebe95 Update changelog for v4.31.7
f5c63fa Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
a2c01e7 Add changelog note
ac34c13 Update default bundle to codeql-bundle-v2.23.7
267c467 Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d264
aeabef7 Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
78357d3 Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
d61a6fa Update CLI config test to account for overlay db changes on PRs
ce27e95 Rebuild
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org>
Change-Id: Ib1a3f3f948a77529623c8e7adee6016097171222
GitHub-PR: #28
GitHub-Hash: 7ec47aef36adcd66
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.31.6 to 4.31.7.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@fe4161a...cf1bb45)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.31.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/github/codeql-action-4.31.7 branch from e27cb06 to 60ff8b2 Compare December 31, 2025 15:01
@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/releng/gerrit_to_platform/+/74029

@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/releng/gerrit_to_platform/+/74030

@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/releng/gerrit_to_platform/+/74031

lfit-replication pushed a commit that referenced this pull request Dec 31, 2025
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Change-Id: I0da1fb429fe12c47f75dac83827bfe9b50db74c5

---

[//]: # (dependabot-end)

Bumps github/codeql-action from 4.31.6 to 4.31.7.
## Release notes

Sourced from github/codeql-action's releases.

v4.31.7
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
4.31.7 - 05 Dec 2025

Update default CodeQL bundle version to 2.23.7. #3343

See the full CHANGELOG.md for more information.

## Changelog

Sourced from github/codeql-action's changelog.

CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.31.7 - 05 Dec 2025

Update default CodeQL bundle version to 2.23.7. #3343

4.31.6 - 01 Dec 2025
No user facing changes.
4.31.5 - 24 Nov 2025

Update default CodeQL bundle version to 2.23.6. #3321

4.31.4 - 18 Nov 2025
No user facing changes.
4.31.3 - 13 Nov 2025

CodeQL Action v3 will be deprecated in December 2026. The Action now logs a warning for customers who are running v3 but could be running v4. For more information, see Upcoming deprecation of CodeQL Action v3.
Update default CodeQL bundle version to 2.23.5. #3288

4.31.2 - 30 Oct 2025
No user facing changes.
4.31.1 - 30 Oct 2025

The add-snippets input has been removed from the analyze action. This input has been deprecated since CodeQL Action 3.26.4 in August 2024 when this removal was announced.

4.31.0 - 24 Oct 2025

Bump minimum CodeQL bundle version to 2.17.6. #3223
When SARIF files are uploaded by the analyze or upload-sarif actions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for the upload-sarif action. For analyze, this may affect Advanced Setup for CodeQL users who specify a value other than always for the upload input. #3222

4.30.9 - 17 Oct 2025

Update default CodeQL bundle version to 2.23.3. #3205
Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204

4.30.8 - 10 Oct 2025
No user facing changes.

... (truncated)

## Commits

cf1bb45 Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
f4ebe95 Update changelog for v4.31.7
f5c63fa Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
a2c01e7 Add changelog note
ac34c13 Update default bundle to codeql-bundle-v2.23.7
267c467 Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-minor-77d264
aeabef7 Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
78357d3 Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
d61a6fa Update CLI config test to account for overlay db changes on PRs
ce27e95 Rebuild
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org>
Change-Id: I05c7d4c5c9d9385c1888e6b66eb7f38f1dfba057
GitHub-PR: #28
GitHub-Hash: 7ec47aef36adcd66
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 31, 2025

Looks like github/codeql-action is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Dec 31, 2025
@dependabot dependabot bot deleted the dependabot/github_actions/github/codeql-action-4.31.7 branch December 31, 2025 16:35
ModeSevenIndustrialSolutions pushed a commit to modeseven-lfit/releng-gerrit_to_platform that referenced this pull request Mar 10, 2026
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Change-Id: I49a38ab7430ef2a3ca7977e071ac12c9930b381f

---

[//]: # (dependabot-end)

Bumps lfit/gerrit-review-action from 0.8 to 0.9.
## Release notes

Sourced from lfit/gerrit-review-action's releases.

v0.9

CI: Add basic config for validation @​tykeal (#2)
Feat: Initial try at gerrit-review action @​tykeal (lfit#3)
Fix: quote all inputs @​tykeal (lfit#4)
Feat: Make current jobs status an input @​tykeal (lfit#5)
Fix: Use job.status @​tykeal (lfit#6)
Fix: Correct job.status call @​tykeal (lfit#7)
Refactor: reuse vote-type @​tykeal (lfit#8)
Chore: Upgrade pre-commit hooks @​tykeal (lfit#10)
Feat!: Switch to new ssh method @​tykeal (lfit#11)
Fix: Add shell specifier to all run commands @​tykeal (lfit#12)
Fix: Do a single line ssh command @​tykeal (lfit#13)
Fix: Gerrit review options must be quoted @​tykeal (lfit#14)
Feat: Allow non-voting status comments @​tykeal (lfit#16)
Fix: Add missing '/' to GHA URL @​tykeal (lfit#17)
Fix: Attempt to fix bad voting @​tykeal (lfit#18)
CI: Build vote command up @​tykeal (lfit#19)
CI: Add a debug statement @​tykeal (lfit#20)
Fix: Remove unneeded single quotes @​tykeal (lfit#21)
Chore: Update pre-commit hooks @​tykeal (lfit#22)
Chore: Update deps and pre-commit @​tykeal (lfit#26)
Chore: Update shimataro/ssh-key-action to v2.7.0 @​askb (lfit#28)
Fix: Skip when jobs are run locally @​askb (lfit#29)
Fix: Set ACT env for install SSH keys @​askb (lfit#30)
[pre-commit.ci] pre-commit autoupdate @pre-commit-ci[bot] (lfit#27)

Maintenance

Feat: Add README.md content, import updated template files @​ModeSevenIndustrialSolutions (lfit#31)

Links

Submit bugs/feature requests

## Commits

537251e Merge pull request lfit#31 from modeseven-lfreleng-actions/import-template
17c7024 Feat: Add README.md content, import updated template files
7cde442 Merge pull request lfit#27 from lfit/pre-commit-ci-update-config
eed4e10 Chore: pre-commit autoupdate
ea252e6 [pre-commit.ci] pre-commit autoupdate
See full diff in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org>
Change-Id: I03b903a3a7a631a5352aab29e66aef6124020fe3
GitHub-PR: lfit#1
GitHub-Hash: 137fd78ffec4615f
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants