build(deps): Bump github/codeql-action from 2.20.1 to 2.20.4#742
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.20.1 to 2.20.4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v2.20.1...489225d) --- updated-dependencies: - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Codecov Report
❗ Your organization is not using the GitHub App Integration. As a result you may experience degraded service beginning May 15th. Please install the Github App Integration for your organization. Read more. @@ Coverage Diff @@
## main #742 +/- ##
=======================================
Coverage 63.66% 63.66%
=======================================
Files 40 40
Lines 2232 2232
=======================================
Hits 1421 1421
Misses 690 690
Partials 121 121 📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more |
| retention-days: 5 | ||
|
|
||
| - name: "Upload to code-scanning" | ||
| uses: github/codeql-action/upload-sarif@4c8f13758e748234abaa6a831d6f53981844a524 # tag=v2.1.26 |
There was a problem hiding this comment.
This looks malicious that commit is updated but the tag is not.
There was a problem hiding this comment.
There are other version comments that are incorrect. I will create a PR to fix them after merge this one.
|
According to |
Update pinned source version comment Signed-off-by: Junjie Gao <junjiegao@microsoft.com> Signed-off-by: Junjie Gao <junjiegao@microsoft.com>
Signed-off-by: Junjie Gao <junjiegao@microsoft.com> Signed-off-by: Junjie Gao <junjiegao@microsoft.com>
|
Manually updated the version comment. |
…roject#742) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.20.1 to 2.20.4. Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Junjie Gao <junjiegao@microsoft.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Junjie Gao <junjiegao@microsoft.com>
…roject#742) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.20.1 to 2.20.4. Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Junjie Gao <junjiegao@microsoft.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Junjie Gao <junjiegao@microsoft.com>
Bumps github/codeql-action from 2.20.1 to 2.20.4.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
489225dMerge pull request #1777 from github/update-v2.20.4-a148c58071b6383dUpdate changelog for v2.20.4a148c58Merge pull request #1776 from github/aeisenberg/changelog-releases50527c5Add link to releases page in changelog814b2edMerge pull request #1762 from github/update-bundle/codeql-bundle-v2.14.0d2baed4Merge branch 'main' into update-bundle/codeql-bundle-v2.14.0c552617Merge pull request #1774 from github/dependabot/npm_and_yarn/npm-a34e423e98c1f4958Fix dependency incompatibilities40a500cUpdate checked-in dependencies4fad06fBump the npm group with 21 updatesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)