You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070
Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061
The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
Update default CodeQL bundle version to 2.26.1. #4019
Update default CodeQL bundle version to 2.26.0. #3995
In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #3892
Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #3837
Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #3850
Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853
Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #3852
Update default CodeQL bundle version to 2.25.3. #3865
Configuration
📅 Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer TIP This summary will be updated as you push new changes.
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.35.3
chore(deps): update github/codeql-action action to v4.35.4
May 7, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.35.4
chore(deps): update github/codeql-action action to v4.35.5
May 15, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.35.5
chore(deps): update github/codeql-action action to v4.36.0
May 22, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.36.0
chore(deps): update github/codeql-action action to v4.36.1
Jun 2, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.36.1
chore(deps): update github/codeql-action action to v4.36.2
Jun 4, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.36.2
chore(deps): update github/codeql-action action to v4.36.3
Jul 2, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.36.3
chore(deps): update github/codeql-action action to v4.37.0
Jul 8, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.0
chore(deps): update github/codeql-action action to v4.37.1
Jul 16, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.1
chore(deps): update github/codeql-action action to v4.37.2
Jul 21, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.2
chore(deps): update github/codeql-action action to v4.37.3
Jul 22, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.3
chore(deps): update github/codeql-action action to v4.37.4
Jul 30, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.4
chore(deps): update github/codeql-action action to v4.37.5
Aug 3, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.5
chore(deps): update github/codeql-action action to v4.37.6
Aug 4, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.6
chore(deps): update github/codeql-action action to v4.37.7
Aug 13, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.7
chore(deps): update github/codeql-action action to v4.37.8
Aug 21, 2026
renovateBot
changed the title
chore(deps): update github/codeql-action action to v4.37.8
chore(deps): update github/codeql-action action to v4.37.9
Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.35.2→v4.37.9Release Notes
github/codeql-action (github/codeql-action)
v4.37.9Compare Source
v4.37.8Compare Source
No user facing changes.
v4.37.7Compare Source
v4.37.6Compare Source
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #4070v4.37.5Compare Source
initAction instead of falling back to downloading the bundle before extracting it. #4061v4.37.4Compare Source
v4.37.3Compare Source
No user facing changes.
v4.37.2Compare Source
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023v4.37.1Compare Source
v4.37.0Compare Source
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973v4.36.3Compare Source
No user facing changes.
v4.36.2Compare Source
v4.36.1Compare Source
No user facing changes.
v4.36.0Compare Source
v4.35.5Compare Source
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892v4.35.4Compare Source
v4.35.3Compare Source
GETrequests instead ofHEADfor better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.