Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
135 commits
Select commit Hold shift + click to select a range
f042742
Wrap JSON parse errors in `resolveExtractor` with context
mbg Sep 22, 2026
a5c2338
Wrap JSON parse errors in `restoreInputs` with context
mbg Sep 22, 2026
c036972
Wrap JSON parse errors in `getTracerConfigForCluster` with context
mbg Sep 22, 2026
2294a7a
Wrap JSON parse errors in `parseMatrixInput` with context
mbg Sep 22, 2026
8e36092
Wrap JSON parse errors in `cloneObject` with context
mbg Sep 22, 2026
fe0a932
Wrap JSON parse errors in `readSarifFile` with context
mbg Sep 22, 2026
660f7c5
Fix formatting
mbg Sep 22, 2026
fa47128
Restore previous `restoreInputs` behaviour
mbg Sep 22, 2026
f42df5b
Move bundle types and helpers out of setup-codeql.ts
henrymercer Sep 23, 2026
6aa6d55
Remove the getCodeQLBundleName wrapper from setup-codeql.ts
henrymercer Sep 24, 2026
477ba69
Name unnamed jobs in release workflow
mbg Sep 24, 2026
b435ce4
Disambiguate "Prepare release" job naming
mbg Sep 24, 2026
266e866
Update changelog and version after v4.38.2
github-actions[bot] Sep 24, 2026
73dc344
Rebuild
github-actions[bot] Sep 24, 2026
b5f938c
Log error in `restoreInputs` instead of re-throwing it
mbg Sep 24, 2026
415d925
Fix formatting of mergeback checklist
mbg Sep 24, 2026
9c97080
Merge pull request #4167 from github/henrymercer/move-bundle-helpers
henrymercer Sep 24, 2026
aa2cb99
Merge remote-tracking branch 'origin/main' into mbg/improve-json-fail…
mbg Sep 24, 2026
a7334dd
Merge pull request #4170 from github/mergeback/v4.38.2-to-main-2892aa5e
mbg Sep 24, 2026
19aa55d
Log error in `getTracerConfigForCluster` instead of re-throwing it
mbg Sep 24, 2026
38c1d74
Merge remote-tracking branch 'origin/main' into mbg/improve-json-fail…
mbg Sep 24, 2026
fa8392b
Merge pull request #4161 from github/mbg/improve-json-failures
mbg Sep 24, 2026
054b25e
Remove unnecessary `config` check
mbg Sep 25, 2026
9fb2fa5
Avoid duplicate `getApiDetails` in `getGitHubVersion`
mbg Sep 25, 2026
fa2bea7
Merge pull request #4176 from github/mbg/start-proxy/improve-post-git…
mbg Sep 25, 2026
29b01b6
Point at Dependabot `groups` docs in version mismatch error
mbg Sep 25, 2026
7b6a151
Merge pull request #4177 from github/mbg/version-check/recommend-depe…
mbg Sep 25, 2026
8102666
Improve return type for `wrapApiConfigurationError` and add docs
mbg Sep 25, 2026
8dfe937
Use `wrapApiConfigurationError` for `getGitHubVersionFromApi`
mbg Sep 25, 2026
0af3281
Use `gitHubVersion` from config if available in `init-action-post`
mbg Sep 25, 2026
1991d20
Use `wrapApiConfigurationError` in `init-action-post` error handler
mbg Sep 25, 2026
31252c2
Change `wrapApiConfigurationError` to not be `serial`
mbg Sep 28, 2026
260cb2a
Break up `wrapApiConfigurationError` tests
mbg Sep 28, 2026
503e2f6
Add test for repeated `wrapApiConfigurationError`
mbg Sep 28, 2026
85c0c09
Merge pull request #4178 from github/mbg/use-api-error-classification…
mbg Sep 28, 2026
97a91d9
Make `platform`+`arch` available in `BaseState`
mbg Sep 28, 2026
62a2268
Use `getBundlePlatform` in `getDownloadUrl`
mbg Sep 28, 2026
fc2d2f7
Make `ActionState` available to `getDownloadUrl`
mbg Sep 28, 2026
10e476c
Fix values used in log message
mbg Sep 29, 2026
8e838ff
Add tests
mbg Sep 29, 2026
cd1a7c1
Use test tags in `rollback-release.yml` workflow
mbg Sep 29, 2026
61817fa
Merge pull request #4181 from github/mbg/start-proxy/linux-arm64
mbg Sep 29, 2026
b5a476b
Disable per-language bundles in the file baseline PR check
henrymercer Sep 29, 2026
5e3132d
Move `defaultSuites` to `config/db-config.ts`
henrymercer Sep 29, 2026
1609a51
Avoid per-language bundles when queries may need other languages' lib…
henrymercer Sep 29, 2026
d8b6f2a
Always use the combined bundle in `setup-codeql`
henrymercer Sep 30, 2026
7816c33
Fix the docs for the `languages` and `analysis-kinds` inputs of `setu…
henrymercer Sep 30, 2026
99522b4
Bump the npm-minor group across 1 directory with 4 updates
dependabot[bot] Sep 30, 2026
f1b8b0f
Rebuild
github-actions[bot] Sep 30, 2026
cbe61e2
Bump ruby/setup-ruby
dependabot[bot] Sep 30, 2026
222d54a
Rebuild
github-actions[bot] Sep 30, 2026
87a1923
Use a new feature flag for per-language bundles
henrymercer Oct 1, 2026
2da0d29
Omit the feature flag name from the per-language bundle debug log
henrymercer Oct 1, 2026
a98f604
Read the `config` and `queries` inputs once in `init`
henrymercer Oct 1, 2026
a4fbe39
Extract parsing of the `queries` input and the extra queries reposito…
henrymercer Oct 1, 2026
70897a7
Reuse the parsing of query inputs when choosing a bundle
henrymercer Oct 1, 2026
725421c
Explain that the `config` input can configure queries
henrymercer Oct 1, 2026
1bb99cb
Explain what a reason to use the combined bundle means where it's che…
henrymercer Oct 1, 2026
a6cd2a5
Check what the `config` input sets instead of exempting dynamic workf…
henrymercer Oct 1, 2026
d06baaa
Update supported GitHub Enterprise Server versions
github-actions[bot] Oct 2, 2026
ffc4a0c
Merge pull request #4182 from github/dependabot/npm_and_yarn/npm-mino…
mbg Oct 2, 2026
f306a93
Bump brace-expansion from 1.1.18 to 1.1.21
dependabot[bot] Oct 2, 2026
d036b81
Rebuild
github-actions[bot] Oct 2, 2026
f45aab1
Trigger workflows
mbg Oct 2, 2026
f24d881
Merge pull request #4183 from github/dependabot/github_actions/dot-gi…
mbg Oct 2, 2026
ce28f3e
Explain why the file baseline PR check uses the combined bundle
henrymercer Oct 2, 2026
1c0814d
Parse lists of queries with a single function
henrymercer Oct 2, 2026
e869836
Share the check of the properties that Default Setup sets in the `con…
henrymercer Oct 2, 2026
113b18e
Parse the `config` input once
henrymercer Oct 2, 2026
f6a7f00
Point to the Default Setup config schema from the per-language bundle…
henrymercer Oct 2, 2026
05d2a1a
Trigger workflows
mbg Oct 2, 2026
dc1f3ac
Merge remote-tracking branch 'origin/main' into mbg/improve-release-w…
mbg Oct 2, 2026
488027b
Update comment
mbg Oct 2, 2026
c535168
Merge pull request #4189 from github/dependabot/npm_and_yarn/brace-ex…
mbg Oct 2, 2026
27c60c5
Fix detection of merge conflicts outside `lib` in the rebuild workflow
henrymercer Oct 2, 2026
a47cc9f
Merge remote-tracking branch 'origin/main' into henrymercer/per-langu…
Copilot Oct 2, 2026
b804ae9
Dependabot: Apply `cooldown` uniformly
mbg Oct 2, 2026
56b0d5f
Fix the rebuild workflow failing when merging the base branch conflicts
henrymercer Oct 2, 2026
1f8080a
Add `min-release-age=7` to `.npmrc`
mbg Oct 2, 2026
6ce88f6
Downgrade `@actions/cache`
mbg Oct 2, 2026
c26ee0c
Merge pull request #4193 from github/mbg/dependabot/uniform-cooldown
mbg Oct 2, 2026
0cd78b3
Merge pull request #4194 from github/mbg/dependency/downgrade-cache
mbg Oct 2, 2026
412197a
Bump ruby/setup-ruby
dependabot[bot] Oct 2, 2026
4d9cd8c
Rebuild
github-actions[bot] Oct 2, 2026
c275b4a
Merge branch 'main' into henrymercer/per-language-pr-check-failures
henrymercer Oct 2, 2026
62b0dd9
Add check for non-public feed URLs
mbg Oct 2, 2026
8948426
Install newer `npm` in Node 20 workflows
mbg Oct 2, 2026
b948c4d
Normalise feed URLs in `package-lock.json`
mbg Oct 2, 2026
b6d38e5
Merge pull request #4192 from github/mbg/project-changes
mbg Oct 2, 2026
d8251b8
Merge pull request #4191 from github/henrymercer/ci-job-failure-inves…
henrymercer Oct 5, 2026
fa90489
Replace deprecated config key
mbg Oct 5, 2026
363d874
Exclude "tests" folder from workspace
mbg Oct 5, 2026
aeafd00
Merge pull request #4197 from github/mbg/vscode/workspace-improvements
mbg Oct 5, 2026
1767808
Merge pull request #4196 from github/dependabot/github_actions/dot-gi…
henrymercer Oct 5, 2026
c1e7769
Reword the JSDoc for `parseQueriesFromInput`
henrymercer Oct 5, 2026
ac4b9b8
Return early from `parseQueriesFromInput` when there are no queries
henrymercer Oct 5, 2026
711f3bf
Remove the `checkDefaultSetupConfig` wrapper around `checkSchema`
henrymercer Oct 5, 2026
966f3c3
Say that the Default Setup config schema reflects what Default Setup …
henrymercer Oct 5, 2026
a4a04dc
Explain that the `config` input is written to disk without merging
henrymercer Oct 5, 2026
6cb83fa
Construct `UserConfig` objects directly in the `config-utils` tests
henrymercer Oct 5, 2026
e0b8480
Parse the `config` input in `init` without the `parseConfigInput` wra…
henrymercer Oct 5, 2026
9d3242e
Say that `parseUserConfig`'s `pathInput` may not be a file path
henrymercer Oct 5, 2026
8e6b600
Compare `originalUserInput` with a separate object in the `config` in…
henrymercer Oct 5, 2026
55e4091
Describe what `parseUserConfig` accepts, returns and throws more prec…
henrymercer Oct 5, 2026
12db63b
Explain why the `config` input test compares with a separate object
henrymercer Oct 5, 2026
61c3b54
Update CodeQL deprecation warning for GHES 3.17
henrymercer Oct 5, 2026
118af59
Remove unsupported GHES versions from compatibility table
henrymercer Oct 5, 2026
2c8d410
Merge pull request #4184 from github/henrymercer/per-language-pr-chec…
henrymercer Oct 6, 2026
d1ca36f
Update CHANGELOG.md
henrymercer Oct 6, 2026
7265309
Merge pull request #4188 from github/update-supported-enterprise-serv…
henrymercer Oct 6, 2026
f455295
Merge pull request #4169 from github/mbg/improve-release-workflow
mbg Oct 6, 2026
36f377b
Bump `@types/node` to `v24` for `pr-checks`
mbg Oct 6, 2026
4c98a0b
Add `nvmrc` for `pr-checks`
mbg Oct 6, 2026
b813f91
Add compatibility definitions to `config.ts`
mbg Oct 6, 2026
f5b4c32
Replace `require` check with `import.meta.main`
mbg Oct 6, 2026
1b38bb1
Set `type: module` for `pr-checks`
mbg Oct 6, 2026
4c932d9
Replace `.mts` extensions
mbg Oct 6, 2026
a2374c3
Replace `__dirname` in `sync-back.ts`
mbg Oct 6, 2026
0f3412f
Replace `.mts` with `.ts` in comments and workflows
mbg Oct 6, 2026
0a44f18
Remove `.mts` patterns from configurations
mbg Oct 6, 2026
a71b0c6
Replace `__dirname` in `sync.ts`
mbg Oct 6, 2026
d208ec7
Merge pull request #4200 from github/mbg/esm/migrate-pr-checks
mbg Oct 6, 2026
c1a30cd
Update default bundle to codeql-bundle-v2.27.2
github-actions[bot] Oct 7, 2026
7377a10
Add changelog note
github-actions[bot] Oct 7, 2026
63d3d63
Merge pull request #4203 from github/update-bundle/codeql-bundle-v2.27.2
navntoft Oct 7, 2026
6b99698
Pin Python 3.13.15 for older CLI versions in multi-language check
henrymercer Oct 7, 2026
e0b52db
Merge pull request #4210 from github/henrymercer/pin-python-for-older…
henrymercer Oct 7, 2026
23b6828
Update changelog for v4.38.3
github-actions[bot] Oct 8, 2026
69e87c5
Add changelog note for #4184
henrymercer Oct 8, 2026
24c5418
Merge pull request #4214 from github/update-v4.38.3-e0b52dbdc
navntoft Oct 8, 2026
45d97c3
Revert "Update version and changelog for v3.38.2"
github-actions[bot] Oct 8, 2026
1720989
Revert "Rebuild"
github-actions[bot] Oct 8, 2026
1d986a1
Merge remote-tracking branch 'origin/releases/v4' into backport-v3.38…
github-actions[bot] Oct 8, 2026
9c17bbc
Update version and changelog for v3.38.3
github-actions[bot] Oct 8, 2026
472ce8f
Rebuild
github-actions[bot] Oct 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions .github/actions/prepare-mergeback-branch/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -92,8 +92,7 @@ runs:
Please do the following:
- [ ] Approve running the full set of PR checks.
- [ ] Approve and merge the PR. When merging the PR, make sure "Create a merge commit" is
selected rather than "Squash and merge" or "Rebase and merge".
- [ ] Approve and merge the PR. When merging the PR, make sure "Create a merge commit" is selected rather than "Squash and merge" or "Rebase and merge".
EOF
)
Expand Down
4 changes: 0 additions & 4 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,6 @@ updates:
interval: weekly
cooldown:
default-days: 7
exclude:
- "@actions/*"
labels:
- Rebuild
# Ignore incompatible dependency updates
Expand All @@ -33,8 +31,6 @@ updates:
interval: weekly
cooldown:
default-days: 7
exclude:
- "actions/*"
labels:
- Rebuild
groups:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/__config-input.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/__export-file-baseline-information.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 4 additions & 3 deletions .github/workflows/__multi-language-autodetect.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions .github/workflows/__packaging-config-inputs-js.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions .github/workflows/__packaging-config-js.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions .github/workflows/__packaging-inputs-js.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__rubocop-multi-language.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

18 changes: 16 additions & 2 deletions .github/workflows/pr-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,12 @@ jobs:
node-version: ${{ matrix.node-version }}
cache: "npm"

# Install a new enough version of `npm` to understand `min-release-age`
# that is still compatible with Node 20.
- name: Install newer npm
if: matrix.node-version == 20
run: npm install -g npm@11.19.1

- name: Install dependencies
run: |
# Use the system Bash shell to ensure we can run commands like `npm ci`
Expand Down Expand Up @@ -95,6 +101,14 @@ jobs:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Check for incorrect addresses in package-lock.json
run: |
if git grep -nE '(pkgs\.visualstudio\.com|pkgs\.dev\.azure\.com|packagefeedproxy\.microsoft\.io)' -- \
'package-lock.json'; then
echo "::error::package-lock.json contains internal package feed URLs. Replace them with public registry URLs."
exit 1
fi
- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
Expand All @@ -114,9 +128,9 @@ jobs:
working-directory: pr-checks
run: npx tsx --test

- name: Run `pr-checks/changenotes.mts` to ensure that all unreleased change notes are valid
- name: Run `pr-checks/changenotes.ts` to ensure that all unreleased change notes are valid
if: ${{ !cancelled() && steps.install-deps.outcome == 'success' }}
run: npx tsx pr-checks/changenotes.mts validate
run: npx tsx pr-checks/changenotes.ts validate

- name: Verify all Actions use the same Node version
id: head-version
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/prepare-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ defaults:

jobs:
prepare:
name: "Prepare release"
name: "Release info"
runs-on: ubuntu-latest
if: github.repository == 'github/codeql-action'

Expand Down
29 changes: 12 additions & 17 deletions .github/workflows/rebuild.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,32 +54,27 @@ jobs:
run: |
git fetch origin "$BASE_BRANCH"
# Allow merge conflicts in `lib`, since rebuilding should resolve them.
git merge "origin/$BASE_BRANCH"
MERGE_RESULT=$?
if [ "$MERGE_RESULT" -eq 0 ]; then
# Allow merge conflicts in `lib`, since rebuilding should resolve them. Conflicts leave the
# merge in progress, so check for `MERGE_HEAD` to tell them apart from failures that don't.
if git merge "origin/$BASE_BRANCH"; then
echo "Merge succeeded cleanly."
elif [ "$MERGE_RESULT" -eq 1 ]; then
echo "Merge conflicts detected (exit code $MERGE_RESULT), continuing."
else
echo "git merge failed with unexpected exit code $MERGE_RESULT."
exit 1
fi
if [ "$MERGE_RESULT" -ne 0 ]; then
elif git rev-parse --verify MERGE_HEAD >/dev/null 2>&1; then
echo "Merge conflicts detected, continuing."
echo "merge-in-progress=true" >> $GITHUB_OUTPUT
# Check for merge conflicts outside of `lib`. Disable git diff's trailing whitespace check
# since `node_modules/@types/semver/README.md` fails it.
if git -c core.whitespace=-trailing-space diff --check | grep --invert-match '^lib/'; then
# Check for merge conflicts outside of `lib`.
CONFLICTS_OUTSIDE_LIB=$(git diff --name-only --diff-filter=U | grep --invert-match '^lib/' || true)
if [ -n "$CONFLICTS_OUTSIDE_LIB" ]; then
echo "Merge conflicts were detected outside of the lib directory. Please resolve them manually."
git -c core.whitespace=-trailing-space diff --check | grep --invert-match '^lib/' || true
echo "$CONFLICTS_OUTSIDE_LIB"
exit 1
fi
echo "No merge conflicts found outside the lib directory. We should be able to resolve all of" \
"these by rebuilding the Action."
else
echo "git merge failed for a reason other than merge conflicts."
exit 1
fi
- name: Compile TypeScript
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/rollback-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,7 @@ on:
required: true
# Only for dry-runs of changes to the workflow.
push:
# Don't run dry-run on release branches, to avoid an issue where the
# "new" tag determined by the "Prepare release" job already exists.
# Don't run dry-run on release branches, since that's unnecessary.
branches-ignore:
- releases/v*
paths:
Expand All @@ -24,7 +23,7 @@ defaults:

jobs:
prepare:
name: "Prepare release"
name: "Prepare"
if: github.repository == 'github/codeql-action'

permissions:
Expand Down Expand Up @@ -107,8 +106,10 @@ jobs:
# We usually expect to checkout `inputs.rollback-tag` (required for `workflow_dispatch`),
# but use `v0.0.0` for testing.
ROLLBACK_TAG: ${{ inputs.rollback-tag || 'v0.0.0' }}
RELEASE_TAG: ${{ needs.prepare.outputs.version }}
MAJOR_VERSION_TAG: ${{ needs.prepare.outputs.major_version }}
# Use `needs.prepare.outputs.version` for actual runs and `v0.0.1` for testing.
RELEASE_TAG: ${{ case(github.event_name == 'workflow_dispatch', needs.prepare.outputs.version, 'v0.0.1') }}
# Use `needs.prepare.outputs.major_version` for actual runs and `v0` for testing.
MAJOR_VERSION_TAG: ${{ case(github.event_name == 'workflow_dispatch', needs.prepare.outputs.major_version, 'v0') }}
run: |
git checkout "refs/tags/${ROLLBACK_TAG}"
git tag --annotate "${RELEASE_TAG}" --message "${RELEASE_TAG}"
Expand Down Expand Up @@ -184,4 +185,3 @@ jobs:
# Setting this to `true` for non-workflow_dispatch events will
# still push the `branch`, but won't create a corresponding PR
dry-run: "${{ github.event_name != 'workflow_dispatch' }}"

5 changes: 3 additions & 2 deletions .github/workflows/update-release-branch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,15 +16,15 @@ defaults:
shell: bash

jobs:

prepare:
name: "Prepare release"
name: "Prepare"
permissions:
contents: read

uses: ./.github/workflows/prepare-release.yml

update:
name: "Update release branch"
timeout-minutes: 45
runs-on: ubuntu-latest
if: github.event_name == 'workflow_dispatch'
Expand Down Expand Up @@ -77,6 +77,7 @@ jobs:
--conductor ${GITHUB_ACTOR}
backport:
name: "Create backport"
timeout-minutes: 45
runs-on: ubuntu-latest
environment: Automation
Expand Down
1 change: 1 addition & 0 deletions .npmrc
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
lockfile-version=3
min-release-age=7
6 changes: 5 additions & 1 deletion .vscode/settings.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@
// transpiled JavaScript
"build": true,
"lib": true,

// exclude "tests" by default because it causes VSCode to start language-specific extensions
// that are not typically needed during development (or indeed may not work correctly)
"tests": true
},
"search.exclude": {
"**/node_modules": true,
Expand All @@ -18,7 +22,7 @@
"git.ignoreLimitWarning": true,
// Use the vendored TypeScript version to have a consistent development experience across
// machines.
"typescript.tsdk": "node_modules/typescript/lib",
"js/ts.tsdk.path": "node_modules/typescript/lib",
"[typescript]": {
"editor.defaultFormatter": "esbenp.prettier-vscode"
},
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.

## 3.38.3 - 08 Oct 2026

- _Upcoming breaking change_: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. [#4188](https://github.com/github/codeql-action/pull/4188)
- Update default CodeQL bundle version to [2.27.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.2). [#4203](https://github.com/github/codeql-action/pull/4203)
- Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. [#4184](https://github.com/github/codeql-action/pull/4184)

## 3.38.2 - 24 Sept 2026

- Update default CodeQL bundle version to [2.27.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1). [#4160](https://github.com/github/codeql-action/pull/4160)
Expand Down
3 changes: 1 addition & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,12 +72,11 @@ We typically release new minor versions of the CodeQL Action and Bundle when a n

| Minimum CodeQL Action | Minimum CodeQL Bundle Version | GitHub Environment | Notes |
|-----------------------|-------------------------------|--------------------|-------|
| `v4.36.2` | `2.25.6` | Enterprise Server 3.22 | |
| `v4.33.0` | `2.24.3` | Enterprise Server 3.21 | |
| `v4.31.10` | `2.23.9` | Enterprise Server 3.20 | |
| `v3.29.11` | `2.22.4` | Enterprise Server 3.19 | |
| `v3.28.21` | `2.21.3` | Enterprise Server 3.18 | |
| `v3.28.12` | `2.20.7` | Enterprise Server 3.17 | |
| `v3.28.6` | `2.20.3` | Enterprise Server 3.16 | |

See the full list of GHES release and deprecation dates at [GitHub Enterprise Server releases](https://docs.github.com/en/enterprise-server/admin/all-releases#releases-of-github-enterprise-server).

Expand Down
4 changes: 2 additions & 2 deletions eslint.config.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,7 @@ export default [
},
},
{
files: ["**/*.ts", "**/*.js", "**/*.mts"],
files: ["**/*.ts", "**/*.js"],

rules: {
"@typescript-eslint/no-explicit-any": "off",
Expand All @@ -180,7 +180,7 @@ export default [
},
},
{
files: ["pr-checks/**/*.ts", "pr-checks/**/*.mts"],
files: ["pr-checks/**/*.ts"],

languageOptions: {
parserOptions: {
Expand Down
8 changes: 4 additions & 4 deletions lib/defaults.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"bundleVersion": "codeql-bundle-v2.27.1",
"cliVersion": "2.27.1",
"priorBundleVersion": "codeql-bundle-v2.27.0",
"priorCliVersion": "2.27.0"
"bundleVersion": "codeql-bundle-v2.27.2",
"cliVersion": "2.27.2",
"priorBundleVersion": "codeql-bundle-v2.27.1",
"priorCliVersion": "2.27.1"
}
Loading
Loading