Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
dd6e398
Bump the npm_and_yarn group across 8 directories with 5 updates
dependabot[bot] Oct 8, 2026
8a8bde4
Bump lazy_static from 1.5.0 to 1.5.1 in /ql
dependabot[bot] Oct 8, 2026
00e5c94
Bump actions/checkout from 5 to 7
dependabot[bot] Oct 8, 2026
c73c969
Bump tree-sitter from 0.26.13 to 0.27.0 in /ql
dependabot[bot] Oct 8, 2026
6110948
Bump actions/upload-artifact from 4 to 6
dependabot[bot] Oct 8, 2026
6196fd1
Merge branch 'main' into dependabot/npm_and_yarn/javascript/ql/test/l…
krishnprakash Oct 9, 2026
4ba38d8
Merge pull request #893 from krishnprakash/dependabot/npm_and_yarn/ja…
krishnprakash Oct 9, 2026
0ec9e64
Merge branch 'main' into dependabot/github_actions/actions/checkout-7
krishnprakash Oct 9, 2026
bde0fb5
Bump golang.org/x/text
dependabot[bot] Oct 9, 2026
a6b1d0a
Bump golang.org/x/sys
dependabot[bot] Oct 9, 2026
efb72cd
Merge pull request #895 from krishnprakash/dependabot/github_actions/…
krishnprakash Oct 9, 2026
8827be1
Merge branch 'main' into dependabot/cargo/ql/lazy_static-1.5.1
krishnprakash Oct 9, 2026
42a3bfb
Bump actions/download-artifact from 4 to 7
dependabot[bot] Oct 9, 2026
bb94752
Merge pull request #894 from krishnprakash/dependabot/cargo/ql/lazy_s…
krishnprakash Oct 9, 2026
86eb24b
Merge branch 'main' into dependabot/github_actions/actions/upload-art…
krishnprakash Oct 9, 2026
14b4cd9
Merge pull request #898 from krishnprakash/dependabot/github_actions/…
krishnprakash Oct 9, 2026
8619b54
Merge branch 'main' into dependabot/cargo/ql/tree-sitter-0.27.0
krishnprakash Oct 9, 2026
f2854c6
Merge pull request #896 from krishnprakash/dependabot/cargo/ql/tree-s…
krishnprakash Oct 9, 2026
9927bb4
Merge branch 'main' into dependabot/go_modules/go/ql/test/library-tes…
krishnprakash Oct 9, 2026
5e89c9e
Merge pull request #899 from krishnprakash/dependabot/go_modules/go/q…
krishnprakash Oct 9, 2026
b18d371
Merge branch 'main' into dependabot/go_modules/go/ql/test/library-tes…
krishnprakash Oct 9, 2026
91e678d
Merge pull request #900 from krishnprakash/dependabot/go_modules/go/q…
krishnprakash Oct 9, 2026
e79a28f
Merge branch 'main' into dependabot/github_actions/actions/download-a…
krishnprakash Oct 9, 2026
239f41d
Merge pull request #897 from krishnprakash/dependabot/github_actions/…
krishnprakash Oct 9, 2026
2e25add
Potential fix for code scanning alert no. 820: Generic catch clause
krishnprakash Oct 9, 2026
40a196a
Merge pull request #902 from krishnprakash/alert-autofix-820.12
krishnprakash Oct 9, 2026
ceeb3a6
Potential fix for code scanning alert no. 821: Generic catch clause
krishnprakash Oct 9, 2026
706c697
Merge pull request #903 from krishnprakash/alert-autofix-821.12
krishnprakash Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/buildifier.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Check bazel formatting
uses: pre-commit/action@646c83fcd040023954eafda54b4db0192ce70507
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/check-implicit-this.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Check that implicit this warnings is enabled for all packs
shell: bash
run: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/check-overlay-annotations.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Check overlay annotations
run: python config/add-overlay-annotations.py --check java

2 changes: 1 addition & 1 deletion .github/workflows/check-qldoc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
with:
fetch-depth: 2

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/check-query-ids.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,6 @@ jobs:
name: Check query IDs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Check for duplicate query IDs
run: python3 misc/scripts/check-query-ids.py
2 changes: 1 addition & 1 deletion .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
dotnet-version: 10.0.100

- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cpp-swift-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/csharp-qltest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ jobs:
os: [ubuntu-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Setup dotnet
uses: actions/setup-dotnet@v4
with:
Expand All @@ -63,7 +63,7 @@ jobs:
stubgentest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- uses: ./csharp/actions/create-extractor-pack
- name: Run stub generator tests
run: |
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/csv-coverage-metrics.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Setup CodeQL
uses: ./.github/actions/fetch-codeql
- name: Create empty database
Expand All @@ -37,7 +37,7 @@ jobs:
run: |
DATABASE="${{ runner.temp }}/java-database"
codeql database analyze --format=sarif-latest --output=metrics-java.sarif -- "$DATABASE" ./java/ql/src/Metrics/Summaries/FrameworkCoverage.ql
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: metrics-java.sarif
path: metrics-java.sarif
Expand All @@ -51,7 +51,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Setup CodeQL
uses: ./.github/actions/fetch-codeql
- name: Create empty database
Expand All @@ -64,7 +64,7 @@ jobs:
run: |
DATABASE="${{ runner.temp }}/csharp-database"
codeql database analyze --format=sarif-latest --output=metrics-csharp.sarif -- "$DATABASE" ./csharp/ql/src/Metrics/Summaries/FrameworkCoverage.ql
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: metrics-csharp.sarif
path: metrics-csharp.sarif
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/csv-coverage-pr-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,11 +35,11 @@ jobs:
GITHUB_CONTEXT: ${{ toJSON(github.event) }}
run: echo "$GITHUB_CONTEXT"
- name: Clone self (github/codeql) - MERGE
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: merge
- name: Clone self (github/codeql) - BASE
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
fetch-depth: 2
path: base
Expand Down Expand Up @@ -71,21 +71,21 @@ jobs:
run: |
python base/misc/scripts/library-coverage/compare-folders.py out_base out_merge comparison.md
- name: Upload CSV package list
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: csv-framework-coverage-merge
path: |
out_merge/framework-coverage-*.csv
out_merge/framework-coverage-*.rst
- name: Upload CSV package list
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: csv-framework-coverage-base
path: |
out_base/framework-coverage-*.csv
out_base/framework-coverage-*.rst
- name: Upload comparison results
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: comparison
path: |
Expand All @@ -97,7 +97,7 @@ jobs:
env:
PR_NUMBER: ${{ github.event.pull_request.number }}
- name: Upload PR number
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: pr
path: pr/
Expand All @@ -117,7 +117,7 @@ jobs:
GITHUB_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.pull_request.number }}
- name: Upload comment ID (if it exists)
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: comment
path: comment/
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/csv-coverage-pr-comment.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
GITHUB_CONTEXT: ${{ toJSON(github.event) }}
run: echo "$GITHUB_CONTEXT"
- name: Clone self (github/codeql)
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Set up Python 3.8
uses: actions/setup-python@v4
with:
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/csv-coverage-timeseries.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@ jobs:

steps:
- name: Clone self (github/codeql)
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: script
- name: Clone self (github/codeql) for analysis
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: codeqlModels
fetch-depth: 0
Expand All @@ -30,7 +30,7 @@ jobs:
run: |
python script/misc/scripts/library-coverage/generate-timeseries.py codeqlModels
- name: Upload timeseries CSV
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: framework-coverage-timeseries
path: framework-coverage-timeseries-*.csv
2 changes: 1 addition & 1 deletion .github/workflows/csv-coverage-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
GITHUB_CONTEXT: ${{ toJSON(github.event) }}
run: echo "$GITHUB_CONTEXT"
- name: Clone self (github/codeql)
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: ql
fetch-depth: 0
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/csv-coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,11 +16,11 @@ jobs:

steps:
- name: Clone self (github/codeql)
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: script
- name: Clone self (github/codeql) for analysis
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: codeqlModels
ref: ${{ github.event.inputs.qlModelShaOverride || github.ref }}
Expand All @@ -34,12 +34,12 @@ jobs:
run: |
python script/misc/scripts/library-coverage/generate-report.py ci codeqlModels script
- name: Upload CSV package list
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: framework-coverage-csv
path: framework-coverage-*.csv
- name: Upload RST package list
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: framework-coverage-rst
path: framework-coverage-*.rst
2 changes: 1 addition & 1 deletion .github/workflows/fast-forward.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
exit 1

- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Git config
shell: bash
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/go-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
runs-on: ubuntu-latest-xl
steps:
- name: Check out code
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Run tests
uses: ./go/actions/test
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/go-version-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
fetch-depth: 0

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/kotlin-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- run: |
bazel query //java/kotlin-extractor/...
# only build the default version as a quick check that we can build from `codeql`
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ jobs:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
with:
persist-credentials: false
sparse-checkout: .github/labeler.yml
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/mad_modelDiff.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,12 +28,12 @@ jobs:
slug: ${{fromJson(github.event.inputs.projects || '["apache/commons-codec", "apache/commons-io", "apache/commons-beanutils", "apache/commons-logging", "apache/commons-fileupload", "apache/commons-lang", "apache/commons-validator", "apache/commons-csv", "apache/dubbo"]' )}}
steps:
- name: Clone github/codeql from PR
uses: actions/checkout@v5
uses: actions/checkout@v7
if: github.event.pull_request
with:
path: codeql-pr
- name: Clone github/codeql from main
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: codeql-main
ref: main
Expand Down Expand Up @@ -99,12 +99,12 @@ jobs:
name="diff_${basename/.model.yml/""}"
(diff -w -u $m $t | diff2html -i stdin -F $MODELS/$name.html) || true
done
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: models-${{ steps.shortname.outputs.SHORTNAME }}
path: tmp-models/**/**/*.model.yml
retention-days: 20
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: diffs-${{ steps.shortname.outputs.SHORTNAME }}
path: tmp-models/*.html
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/mad_regenerate-models.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,11 @@ jobs:
ref: "placeholder"
steps:
- name: Clone self (github/codeql)
uses: actions/checkout@v5
uses: actions/checkout@v7
- name: Setup CodeQL binaries
uses: ./.github/actions/fetch-codeql
- name: Clone repositories
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
path: repos/${{ matrix.ref }}
ref: ${{ matrix.ref }}
Expand All @@ -59,7 +59,7 @@ jobs:
find java -name "*.model.yml" -print0 | xargs -0 git add
git status
git diff --cached > models.patch
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: patch
path: models.patch
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/python-tooling.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
check-python-tooling:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- uses: actions/setup-python@v5
with:
python-version: '3.12'
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/qhelp-pr-preview.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,14 +36,14 @@ jobs:
- run: echo "${PR_NUMBER}" > pr_number.txt
env:
PR_NUMBER: ${{ github.event.number }}
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: comment-pr-number
path: pr_number.txt
if-no-files-found: error
retention-days: 1

- uses: actions/checkout@v5
- uses: actions/checkout@v7
with:
fetch-depth: 2
persist-credentials: false
Expand Down Expand Up @@ -78,7 +78,7 @@ jobs:
exit "${EXIT_CODE}"

- if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: comment-body
path: comment_body.txt
Expand All @@ -94,7 +94,7 @@ jobs:
GITHUB_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.number }}

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v6
with:
name: comment-id
path: comment_id.txt
Expand Down
Loading