Skip to content

build(deps): bump github/codeql-action from 3 to 4#10

Open
dependabot[bot] wants to merge 47 commits into
mainfrom
dependabot/github_actions/github/codeql-action-4
Open

build(deps): bump github/codeql-action from 3 to 4#10
dependabot[bot] wants to merge 47 commits into
mainfrom
dependabot/github_actions/github/codeql-action-4

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 8, 2026

Bumps github/codeql-action from 3 to 4.

Release notes

Sourced from github/codeql-action's releases.

v3.32.6

  • Update default CodeQL bundle version to 2.24.3. #3548

v3.32.5

  • Repositories owned by an organization can now set up the github-codeql-disable-overlay custom repository property to disable improved incremental analysis for CodeQL. First, create a custom repository property with the name github-codeql-disable-overlay and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to true to disable improved incremental analysis. For more information, see Managing custom properties for repositories in your organization. This feature is not yet available on GitHub Enterprise Server. #3507
  • Added an experimental change so that when improved incremental analysis fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. #3487
  • The minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. #3515
  • Reduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. #3516
  • Added an experimental change which lowers the minimum disk space requirement for improved incremental analysis, enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. #3498
  • Added an experimental change which allows the start-proxy action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. #3512
  • The previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. #3503, #3504

v3.32.4

  • Update default CodeQL bundle version to 2.24.2. #3493
  • Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when private package registries are configured. This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. #3473
  • When the CodeQL Action is run with debugging enabled in Default Setup and private package registries are configured, the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. #3486
  • Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. #3485
  • Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a nightly CodeQL CLI release instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. #3484

v3.32.3

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #3466

v3.32.2

  • Update default CodeQL bundle version to 2.24.1. #3460

v3.32.1

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #3421

v3.32.0

  • Update default CodeQL bundle version to 2.24.0. #3425

v3.31.11

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #3409
  • Improved error handling throughout the CodeQL Action. #3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #3403

v3.31.10

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

3.31.10 - 12 Jan 2026

  • Update default CodeQL bundle version to 2.23.9. #3393

See the full CHANGELOG.md for more information.

v3.31.9

... (truncated)

Changelog

Sourced from github/codeql-action's changelog.

4.32.3 - 13 Feb 2026

  • Added experimental support for testing connections to private package registries. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. #3466

4.32.2 - 05 Feb 2026

  • Update default CodeQL bundle version to 2.24.1. #3460

4.32.1 - 02 Feb 2026

  • A warning is now shown in Default Setup workflow logs if a private package registry is configured using a GitHub Personal Access Token (PAT), but no username is configured. #3422
  • Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. #3421

4.32.0 - 26 Jan 2026

  • Update default CodeQL bundle version to 2.24.0. #3425

4.31.11 - 23 Jan 2026

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #3409
  • Improved error handling throughout the CodeQL Action. #3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #3403

4.31.10 - 12 Jan 2026

  • Update default CodeQL bundle version to 2.23.9. #3393

4.31.9 - 16 Dec 2025

No user facing changes.

4.31.8 - 11 Dec 2025

  • Update default CodeQL bundle version to 2.23.8. #3354

4.31.7 - 05 Dec 2025

  • Update default CodeQL bundle version to 2.23.7. #3343

4.31.6 - 01 Dec 2025

No user facing changes.

4.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #3321

4.31.4 - 18 Nov 2025

... (truncated)

Commits
  • 4cd47ad Address review comments
  • 5fa8dad Use Results for enablement return types
  • 6a77217 Add disabled by env var disablement reason
  • b6dfacb Merge pull request #3542 from github/henrymercer/parallel-unit-tests
  • 6123416 Merge remote-tracking branch 'origin/main' into henrymercer/parallel-unit-tests
  • a6594f9 Merge pull request #3540 from github/henrymercer/stub-actions-vars
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

MohamedBabker and others added 30 commits September 6, 2025 19:42
Allowing everyone to work on the individual files and run the app locally.
I downloaded npm to be able to run locally on my machine as well as add auth path
downloading npm to run on dev server & adding auth page for sign up and log in.
Add sign-in and sign-up pages with placeholder logic
Implement autosave, version history tracking, and Cosmos DB integration for document persistence. Add reset button to clear all version history with confirmation dialog. Include localStorage fallback for offline support.
…ates

feat: add version control with Cosmos DB and reset functionality
Add dashboard page with placeholder
Adding a feature that can be added due to being ahead of schedule
Trillymatt and others added 17 commits December 4, 2025 00:13
Implemented Foundry AI from Microsoft using OpenAI chatgpt 5.1 for chat about resume and adding inline edits as well.
AI chat backend working with foundry which is needed for the imagine cup. LLM being used to read resume and suggest changes to resume based on information provided to make better. This feature does not change the words on the resume yet.
…tical fixes

- Added Claude AI integration via secure MCP server with API authentication
- Implemented multi-format support (PDF, DOCX, LaTeX, RTF, TXT)
- Complete landing page redesign for new product capabilities
- Fixed critical PDF upload parsing and export corruption bugs
- Implemented working user profile dropdown with sign out/re-login
- Fixed guide modal close button and improved UI consistency
- Updated design system with Claude branding and consistent iconography
- Added comprehensive security measures for API key protection
- Enhanced document parsing and export for professional output
- Removed template selector and updated all product messaging

BREAKING CHANGES: Major architecture overhaul with new authentication flow and document handling system.

This transforms the product into a fully-functional, enterprise-ready resume editor with AI assistance.
- Added Claude AI integration via secure MCP server with API authentication
- Implemented multi-format support (PDF, DOCX, LaTeX, RTF, TXT)
- Complete landing page redesign for new product capabilities
- Implemented working user profile dropdown with sign out/re-login
- Fixed guide modal close button and improved UI consistency
- Updated design system with Claude branding and consistent iconography
- Added comprehensive security measures for API key protection
- Enhanced document parsing and export for professional output
- Removed template selector and updated all product messaging
…v, test, stage, prod)

Replace server-only CI with full-stack workflows covering both Next.js frontend
and Express backend. Deployments are branch-driven (develop→dev, test→test,
staging→stage, main→prod) with manual dispatch support.
…ment

Provision all Azure resources (CosmosDB, Blob Storage, Container Apps,
App Service, Redis, ACR, Monitoring) across dev/test/stage/prod with
environment-specific sizing via tfvars files.
# Conflicts:
#	package-lock.json
Changes for backend to work with sup abase as well as the auth. Project is working on local and AWS with good auth and backend migrated
- Fix handleFileUpload to use actual parsed file content instead of hardcoded data
- Add real DOCX export using docx library (was faking it with RTF)
- Improve parseResumeText with smart date/location extraction and better entry detection
- Add 10MB file size validation on upload
- Remove dead code: unused suggestion popup, formatLastSaved, stale state variables
- Fix VersionHistory type mismatch for optional content field

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…envs

- Add GitHub Actions Terraform workflow for dev/test/stage/prod (validate + plan)
- Add missing Terraform CosmosDB module (account, SQL database, containers)
- Document per-env backend state keys in init-backend.sh
- Fix deploy workflow server artifact paths for correct upload
- Add multi-stage server Dockerfile with /api/health check
- Add frontend Dockerfile (Next.js standalone) and DOCKER_BUILD in next.config

Made-with: Cursor
- CI: add timeouts, NODE_VERSION env, job summaries
- Deploy: add branch output, deployment summary job, structured notifications
- Terraform: add fmt check, job summary
- Add dependabot.yml for npm and github-actions
- Add CodeQL security analysis workflow
- Add PULL_REQUEST_TEMPLATE.md
- Terraform: cost allocation tags, environment output, tfvars.example
- Terraform: storage lifecycle block, .terraform-version, README

Made-with: Cursor
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 8, 2026
@namesarnav namesarnav self-requested a review as a code owner March 27, 2026 06:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants