Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
286 commits
Select commit Hold shift + click to select a range
b0e9dfc
Restore missing `status.push` resulting from a bad merge
mbg Nov 9, 2025
a47d550
Restore earlier log messages for `checkHashPatterns`
mbg Nov 9, 2025
4885eb2
Insert new `featurePrefix` after general cache key `prefix`
mbg Nov 9, 2025
48a56f6
Add some tests for `downloadDependencyCaches` related to feature pref…
mbg Nov 9, 2025
04bd5c6
Merge pull request #3279 from github/mbg/lint/jsdoc-param-names
mbg Nov 10, 2025
63bb415
Bump the npm-minor group with 4 updates
dependabot[bot] Nov 10, 2025
3d7be7b
Rebuild
github-actions[bot] Nov 10, 2025
1d9f357
Merge pull request #3281 from github/dependabot/npm_and_yarn/npm-mino…
henrymercer Nov 11, 2025
534824e
Merge pull request #3117 from github/mbg/csharp/new-cache-key-calcula…
mbg Nov 12, 2025
71c3720
Run `npm ci` in `update-supported-enterprise-server-versions.yml`
mbg Nov 12, 2025
a7e52b6
Perform sparse checkout
mbg Nov 12, 2025
fd830db
Trigger on PR for relevant changes
mbg Nov 12, 2025
7a7cd85
Don't push for PR event
mbg Nov 12, 2025
ba454b8
Merge pull request #3284 from github/mbg/ci/fix-enterprise-workflow
mbg Nov 12, 2025
5091e42
Overlay: Remove repository owner restriction
kaspersv Nov 13, 2025
cf8b7a6
Refactor C# cache content paths into a function
mbg Nov 12, 2025
d854ba6
Pass `FeatureEnablement` to `getDependencyPaths`
mbg Nov 12, 2025
a47d04c
Add FF for extra C# cache contents
mbg Nov 12, 2025
ecaa6db
Include `getCsharpTempDependencyDir` in C# caches if FF is enabled
mbg Nov 13, 2025
f5f9571
Configure temp dependency dir for C# extractor when FF is enabled
mbg Nov 13, 2025
362f8d1
Update default bundle to codeql-bundle-v2.23.5
github-actions[bot] Nov 13, 2025
8d3d400
Add changelog note
github-actions[bot] Nov 13, 2025
f20e021
Add support for adding `setup-dotnet` steps to `sync.sh`
mbg Nov 13, 2025
58c9eb6
Add `global.json`
mbg Nov 13, 2025
38a3a72
Enable `installDotNet` in all workflows that analyse C#
mbg Nov 13, 2025
3fac49c
Update remaining workflows
mbg Nov 13, 2025
456a74a
Merge pull request #3289 from github/mbg/ci/setup-dotnet
henrymercer Nov 13, 2025
9777b01
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.5
mbg Nov 13, 2025
8c10e89
Merge pull request #3288 from github/update-bundle/codeql-bundle-v2.23.5
mbg Nov 13, 2025
14d898e
Update changelog for v4.31.3
github-actions[bot] Nov 13, 2025
014f16e
Merge pull request #3293 from github/update-v4.31.3-8c10e89c7
mbg Nov 13, 2025
497c7f6
Update changelog and version after v4.31.3
github-actions[bot] Nov 13, 2025
246edb9
Rebuild
github-actions[bot] Nov 13, 2025
86b7d4f
Merge pull request #3294 from github/mergeback/v4.31.3-to-main-014f16e7
mbg Nov 13, 2025
85f1517
Merge pull request #3285 from github/kaspersv/remove-overlay-org-rest…
kaspersv Nov 14, 2025
11889c2
Return keys of restored caches from `downloadDependencyCaches`
mbg Nov 14, 2025
594c0cc
Store restored keys in action state
mbg Nov 14, 2025
51c9af3
Don't try to upload cache if we have restored a cache with the same key
mbg Nov 14, 2025
1ed85b4
Add test coverage for `uploadDependencyCaches`
mbg Nov 14, 2025
b9620e1
Bump js-yaml from 4.1.0 to 4.1.1
dependabot[bot] Nov 15, 2025
8c254d0
Rebuild
github-actions[bot] Nov 15, 2025
c1a2b73
Merge pull request #3301 from github/dependabot/npm_and_yarn/js-yaml-…
mbg Nov 16, 2025
ed3a013
Change v3 deprecation message to warning.
mario-campos Nov 17, 2025
023fd08
Add CHANGELOG.md entry for "v3 deprecation" to warning change.
mario-campos Nov 17, 2025
3b63581
Bump the npm-minor group with 2 updates
dependabot[bot] Nov 17, 2025
01577d4
Bump @eslint/compat from 1.4.1 to 2.0.0
dependabot[bot] Nov 17, 2025
cd808e1
Bump @types/sinon from 17.0.4 to 21.0.0
dependabot[bot] Nov 17, 2025
d4a7ccd
Rebuild
github-actions[bot] Nov 17, 2025
4f39cef
Rebuild
github-actions[bot] Nov 17, 2025
b595847
Rebuild
github-actions[bot] Nov 17, 2025
fc329e3
Revert "Add CHANGELOG.md entry for "v3 deprecation" to warning change."
mario-campos Nov 17, 2025
c418a0f
Bump ruby/setup-ruby
dependabot[bot] Nov 17, 2025
e546fff
Rebuild
github-actions[bot] Nov 17, 2025
07eae64
Merge pull request #3303 from github/mario-campos/v3-core-warning
mario-campos Nov 17, 2025
7bcdb4b
Add additional options to PR template and clarify some
mbg Nov 17, 2025
ffa63f0
Merge pull request #3307 from github/dependabot/github_actions/dot-gi…
mbg Nov 17, 2025
4f746e4
Overlay: Fall back to full analysis if runner disk space is low
kaspersv Nov 18, 2025
de12435
Merge pull request #3308 from github/mbg/pr-template/nov25
mbg Nov 18, 2025
528362a
Bump `glob` to at least `11.1.0`
mbg Nov 18, 2025
70434f6
Merge pull request #3311 from github/mbg/deps/bump-glob
mbg Nov 18, 2025
726a2a0
Overlay: Increase disk storage threshold to 20GB
kaspersv Nov 18, 2025
c9cb6f9
Update changelog for v4.31.4
github-actions[bot] Nov 18, 2025
249458a
Merge pull request #3296 from github/mbg/dependency-caching/skip-uplo…
mbg Nov 18, 2025
e12f017
Merge pull request #3312 from github/update-v4.31.4-70434f6dd
mbg Nov 18, 2025
fea2500
Update changelog and version after v4.31.4
github-actions[bot] Nov 18, 2025
28f4a61
Merge remote-tracking branch 'origin/main' into mergeback/v4.31.4-to-…
github-actions[bot] Nov 18, 2025
ce9b526
Rebuild
github-actions[bot] Nov 18, 2025
e24190a
Remove unused dependencies
henrymercer Nov 18, 2025
cac5926
Delete unused exports
henrymercer Nov 18, 2025
5da2098
Add feature flag for uploading overlay DBs to API
henrymercer Nov 18, 2025
31042e9
Rename function calls to make destructive operation clearer
henrymercer Nov 18, 2025
c649c59
Upload overlay base DB to API behind FF
henrymercer Nov 18, 2025
378219c
Merge pull request #3313 from github/mergeback/v4.31.4-to-main-e12f0178
henrymercer Nov 18, 2025
ed80d6e
Overlay: Reorder available disk space check
kaspersv Nov 19, 2025
4eccb37
Overlay: Round available disk space in MB
kaspersv Nov 19, 2025
86d2aa5
Merge pull request #3316 from github/henrymercer/upload-overlay-to-api
henrymercer Nov 19, 2025
ce07e7d
Merge pull request #3310 from github/kaspersv/overlay-disk-available-…
kaspersv Nov 19, 2025
de74d76
Overlay: Increase minimum CLI version
kaspersv Nov 19, 2025
a102014
Merge pull request #3317 from github/kaspersv/bump-minimum-overlay-ve…
kaspersv Nov 19, 2025
90871e1
Merge pull request #3304 from github/dependabot/npm_and_yarn/npm-mino…
mbg Nov 19, 2025
e818008
Merge pull request #3305 from github/dependabot/npm_and_yarn/eslint/c…
mbg Nov 19, 2025
0b43179
Merge pull request #3306 from github/dependabot/npm_and_yarn/types/si…
mbg Nov 19, 2025
112cd07
Merge branch 'main' into henrymercer/dead-code-elimination
henrymercer Nov 19, 2025
ac359aa
Add return type
henrymercer Nov 19, 2025
ce729e4
Merge pull request #3315 from github/henrymercer/dead-code-elimination
henrymercer Nov 19, 2025
1d2a238
Update default bundle to codeql-bundle-v2.23.6
github-actions[bot] Nov 24, 2025
ecc8787
Add changelog note
github-actions[bot] Nov 24, 2025
ec2ee57
Merge pull request #3321 from github/update-bundle/codeql-bundle-v2.23.6
redsun82 Nov 24, 2025
81f6d64
Update changelog for v4.31.5
github-actions[bot] Nov 24, 2025
fdbfb4d
Merge pull request #3322 from github/update-v4.31.5-ec2ee575c
redsun82 Nov 24, 2025
29e11fd
Update changelog and version after v4.31.5
github-actions[bot] Nov 24, 2025
4783501
Rebuild
github-actions[bot] Nov 24, 2025
52f930e
Merge pull request #3323 from github/mergeback/v4.31.5-to-main-fdbfb4d2
redsun82 Nov 24, 2025
e2a623d
Bump the npm-minor group with 3 updates
dependabot[bot] Nov 24, 2025
5142791
Rebuild
github-actions[bot] Nov 24, 2025
6feac2b
Bump actions/create-github-app-token
dependabot[bot] Nov 24, 2025
5bd8069
Bump actions/checkout from 5 to 6 in /.github/workflows
dependabot[bot] Nov 24, 2025
8484f54
Rebuild
github-actions[bot] Nov 24, 2025
62e9052
Merge pull request #3327 from github/dependabot/github_actions/dot-gi…
mbg Nov 25, 2025
0e52774
Merge pull request #3326 from github/dependabot/github_actions/dot-gi…
mbg Nov 25, 2025
6b7e963
Update supported GitHub Enterprise Server versions
github-actions[bot] Nov 26, 2025
0155561
Merge branch 'main' into mbg/csharp/more-cache-locations
mbg Nov 26, 2025
99d80b4
Merge pull request #3328 from github/update-supported-enterprise-serv…
henrymercer Nov 26, 2025
d8e497a
Update version in package.json too
henrymercer Nov 26, 2025
85fd3e5
Merge remote-tracking branch 'origin/main' into dependabot/npm_and_ya…
github-actions[bot] Nov 26, 2025
510d25f
Rebuild
github-actions[bot] Nov 26, 2025
a690945
Remove `push` triggers from workflow collections
mbg Nov 26, 2025
c370017
Merge pull request #3325 from github/dependabot/npm_and_yarn/npm-mino…
henrymercer Nov 26, 2025
7850b1c
Merge pull request #3330 from github/mbg/ci/remove-push-from-groups
mbg Nov 26, 2025
3e93966
Merge branch 'main' into mbg/csharp/more-cache-locations
henrymercer Nov 26, 2025
59ce4c1
Merge pull request #3286 from github/mbg/csharp/more-cache-locations
mbg Nov 26, 2025
0c204fc
Bump node-forge from 1.3.1 to 1.3.2
dependabot[bot] Nov 26, 2025
4822f93
Rebuild
github-actions[bot] Nov 26, 2025
bd30e75
Simplify getOverlayDatabaseMode
kaspersv Nov 27, 2025
bd8d26b
Overlay: Fall back to full analysis if memory flag is low
kaspersv Nov 27, 2025
1ffb7dd
Overlay: Add feature flag to skip resource checks
kaspersv Nov 27, 2025
d29b979
Merge pull request #3331 from github/dependabot/npm_and_yarn/node-for…
henrymercer Nov 27, 2025
c178e03
Merge pull request #3332 from github/kaspersv/overlay-memory-limit
kaspersv Nov 27, 2025
2f3bbce
Overlay: Introduce overlay memory limit constant
kaspersv Nov 27, 2025
8d91fa1
Rename getMemoryFlagValue
kaspersv Nov 27, 2025
b02fa13
Order feature flags alphabetically
kaspersv Nov 27, 2025
58c5954
Add comment to runnerSupportsOverlayAnalysis
kaspersv Nov 27, 2025
f036b1c
Merge branch 'main' into kaspersv/overlay-no-resource-checks-option
kaspersv Nov 28, 2025
75b2f49
Merge pull request #3333 from github/kaspersv/overlay-no-resource-che…
kaspersv Nov 28, 2025
32ada5e
Merge branch 'main' into kaspersv/overlay-minor-comments
kaspersv Nov 28, 2025
f7abc74
Remove branch filter for PR event in CodeQL workflow
mbg Nov 28, 2025
23da732
Merge pull request #3334 from github/kaspersv/overlay-minor-comments
kaspersv Nov 28, 2025
ecec1f8
Merge pull request #3335 from github/mbg/ci/run-codeql-on-all-prs
mbg Nov 28, 2025
88c2ab5
Update changelog for v4.31.6
github-actions[bot] Dec 1, 2025
fe4161a
Merge pull request #3336 from github/update-v4.31.6-ecec1f887
mbg Dec 1, 2025
c3455c5
Update changelog and version after v4.31.6
github-actions[bot] Dec 1, 2025
c1ca379
Rebuild
github-actions[bot] Dec 1, 2025
f0ac9bf
Merge pull request #3337 from github/mergeback/v4.31.6-to-main-fe4161a2
mbg Dec 1, 2025
43224eb
Bump @eslint/eslintrc from 3.3.1 to 3.3.3 in the npm-minor group
dependabot[bot] Dec 1, 2025
ce27e95
Rebuild
github-actions[bot] Dec 1, 2025
d61a6fa
Update CLI config test to account for overlay db changes on PRs
mbg Dec 3, 2025
78357d3
Merge pull request #3341 from github/mbg/ci/update-cs-config-cli-tests
mbg Dec 3, 2025
dd89143
CodeQL: Add resolveDatabase method
kaspersv Dec 3, 2025
c4efbda
Overlay: Check database metadata for overlayBaseSpecifier
kaspersv Dec 3, 2025
aeabef7
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-77d26487b0
mbg Dec 3, 2025
267c467
Merge pull request #3339 from github/dependabot/npm_and_yarn/npm-mino…
mbg Dec 3, 2025
ac34c13
Update default bundle to codeql-bundle-v2.23.7
github-actions[bot] Dec 5, 2025
a2c01e7
Add changelog note
github-actions[bot] Dec 5, 2025
f5c63fa
Merge pull request #3343 from github/update-bundle/codeql-bundle-v2.23.7
oscarsj Dec 5, 2025
f4ebe95
Update changelog for v4.31.7
github-actions[bot] Dec 5, 2025
cf1bb45
Merge pull request #3344 from github/update-v4.31.7-f5c63fadd
oscarsj Dec 5, 2025
b93926d
Update changelog and version after v4.31.7
github-actions[bot] Dec 5, 2025
97c2630
Rebuild
github-actions[bot] Dec 5, 2025
149d184
Merge pull request #3345 from github/mergeback/v4.31.7-to-main-cf1bb45a
oscarsj Dec 5, 2025
0ffebf7
Bump the npm-minor group with 5 updates
dependabot[bot] Dec 8, 2025
b73d396
Rebuild
github-actions[bot] Dec 8, 2025
44570be
Bump the actions-minor group across 1 directory with 2 updates
dependabot[bot] Dec 8, 2025
cd48547
Rebuild
github-actions[bot] Dec 8, 2025
5b7e7fc
Update src/codeql.ts
kaspersv Dec 9, 2025
002a7f2
Overlay: log overlayBaseSpecifier at debug log-level
kaspersv Dec 9, 2025
c43362b
Merge pull request #3340 from github/kaspersv/check-for-overlayBaseSp…
kaspersv Dec 9, 2025
7a55ffe
Determine CodeQL version from feature flags on GHEC-DR
henrymercer Dec 10, 2025
1fc7d37
Rename GHE_DOTCOM to GHEC_DR
henrymercer Dec 10, 2025
da50124
Update PR template to include GHEC-DR
henrymercer Dec 10, 2025
805b7e1
Clean up JavaMinimizeDependencyJars feature flag
nickrolfe Dec 11, 2025
2930dba
Update default bundle to codeql-bundle-v2.23.8
github-actions[bot] Dec 11, 2025
db812c1
Add changelog note
github-actions[bot] Dec 11, 2025
1b0b941
Merge pull request #3354 from github/update-bundle/codeql-bundle-v2.23.8
oscarsj Dec 11, 2025
120f277
Update changelog for v4.31.8
github-actions[bot] Dec 11, 2025
1b168cd
Merge pull request #3355 from github/update-v4.31.8-1b0b941e1
oscarsj Dec 12, 2025
4564f5e
Update changelog and version after v4.31.8
github-actions[bot] Dec 12, 2025
65bad62
Rebuild
github-actions[bot] Dec 12, 2025
4b675e4
Merge pull request #3356 from github/mergeback/v4.31.8-to-main-1b168cd3
oscarsj Dec 12, 2025
8e921c3
Return status report from `cleanupAndUploadDatabases`
henrymercer Dec 11, 2025
5d063dd
Populate database upload results telemetry
henrymercer Dec 11, 2025
2ac846d
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-38a2a793c5
henrymercer Dec 15, 2025
0264b51
Merge pull request #3348 from github/dependabot/npm_and_yarn/npm-mino…
henrymercer Dec 15, 2025
7e0b77e
Merge pull request #3349 from github/dependabot/github_actions/dot-gi…
henrymercer Dec 15, 2025
b1dea65
Make `postProcessAndUploadSarif` the default
mbg Nov 17, 2025
009fe6b
Remove `AnalyzeUseNewUpload` FF
mbg Nov 17, 2025
b30cb9a
Merge branch 'main' into mbg/ff/make-new-upload-default
mbg Dec 15, 2025
d4f39b0
Bump the npm-minor group with 3 updates
dependabot[bot] Dec 15, 2025
e1058e4
Rebuild
github-actions[bot] Dec 15, 2025
a539068
Bump ruby/setup-ruby
dependabot[bot] Dec 15, 2025
6dbc22c
Bump actions/download-artifact from 6 to 7 in /.github/workflows
dependabot[bot] Dec 15, 2025
034374e
Bump actions/upload-artifact from 5 to 6 in /.github/workflows
dependabot[bot] Dec 15, 2025
d6c1a79
Rebuild
github-actions[bot] Dec 15, 2025
7fd7db3
Rebuild
github-actions[bot] Dec 15, 2025
a682bbe
Merge pull request #3309 from github/mbg/ff/make-new-upload-default
mbg Dec 15, 2025
07cd437
Merge pull request #3366 from github/dependabot/github_actions/dot-gi…
mbg Dec 15, 2025
d0ad1da
Merge pull request #3364 from github/dependabot/github_actions/dot-gi…
mbg Dec 15, 2025
c2d4383
Merge branch 'main' into dependabot/github_actions/dot-github/workflo…
mbg Dec 15, 2025
b5e1a28
Merge pull request #3365 from github/dependabot/github_actions/dot-gi…
mbg Dec 16, 2025
a2ee53c
Use full names for GitHub variants
henrymercer Dec 16, 2025
a0fc644
Initial plan
Copilot Dec 16, 2025
db75d46
Bump @actions/* npm packages to latest versions
Copilot Dec 16, 2025
7a5748c
Remove changelog note
henrymercer Dec 16, 2025
c07cc0d
Merge pull request #3351 from github/henrymercer/ghec-dr-determine-to…
henrymercer Dec 16, 2025
0cb8633
Prefer `performance.now()`
henrymercer Dec 16, 2025
ae5de9a
Use `getErrorMessage` in log too
henrymercer Dec 16, 2025
19c7f96
Rename `isOverlayBase`
henrymercer Dec 16, 2025
e962687
Merge branch 'main' into henrymercer/database-upload-telemetry
henrymercer Dec 16, 2025
aff7998
Initial plan
Copilot Dec 16, 2025
d29eddb
Extract version number to constant
nickrolfe Dec 16, 2025
5eb7519
Merge pull request #3358 from github/henrymercer/database-upload-tele…
henrymercer Dec 16, 2025
89753aa
Add git version check for overlay analysis enablement
Copilot Dec 16, 2025
fc2bbb0
Address code review feedback
Copilot Dec 16, 2025
c3dc529
Address feedback: cache git version, improve error handling, add tele…
Copilot Dec 16, 2025
393c074
Refactor existing telemetry diagnostics to use makeTelemetryDiagnostic
Copilot Dec 16, 2025
998798e
Merge pull request #3352 from github/nickrolfe/jar-min-ff-cleanup
nickrolfe Dec 16, 2025
1dc115f
Update changelog for v4.31.9
github-actions[bot] Dec 16, 2025
5d4e8d1
Merge pull request #3371 from github/update-v4.31.9-998798e34
henrymercer Dec 16, 2025
6c6e810
Update changelog and version after v4.31.9
github-actions[bot] Dec 16, 2025
d4d47c0
Rebuild
github-actions[bot] Dec 16, 2025
6dba008
Merge pull request #3372 from github/mergeback/v4.31.9-to-main-5d4e8d1a
henrymercer Dec 16, 2025
1fe89fe
Merge pull request #3368 from github/copilot/bump-actions-npm-packages
henrymercer Dec 17, 2025
0c8bfea
Add artifact scanner
henrymercer Dec 17, 2025
5459b98
Add simple artifact scanner for tests only
henrymercer Dec 17, 2025
f28848a
Use artifact scanner in debug artifacts PR checks
henrymercer Dec 17, 2025
f2ccf3b
Ensure .gz files are extracted too
henrymercer Dec 17, 2025
488c1f1
Add regression test for artifact scanner
henrymercer Dec 17, 2025
de17262
Slim down test debug artifacts
henrymercer Dec 17, 2025
da77f9f
Suppress debug logs for artifact scanner test
henrymercer Dec 17, 2025
241948c
Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-b2e0062778
henrymercer Dec 17, 2025
b88acb2
Merge pull request #3359 from github/dependabot/npm_and_yarn/npm-mino…
henrymercer Dec 17, 2025
3b94cfe
Avoid logging each extract call
henrymercer Dec 17, 2025
faf6d35
Verify using post step
henrymercer Dec 17, 2025
6bc6217
Merge branch 'main' into henrymercer/scan-debug-artifacts
henrymercer Dec 17, 2025
3322491
Bump timeout on Windows
henrymercer Dec 17, 2025
6b5763e
Skip slow test on Windows
henrymercer Dec 17, 2025
32795b3
Merge branch 'main' into copilot/update-overlay-git-version-check
henrymercer Dec 17, 2025
7673a2d
Run testing Action using Node 24
henrymercer Dec 17, 2025
e052dbd
Remove caching mechanism
henrymercer Dec 17, 2025
3765106
Move git version logging to config utils
henrymercer Dec 17, 2025
9c5588d
Remove unnecessary stub restores
henrymercer Dec 17, 2025
056581e
Update `makeTelemetryDiagnostic` doc
henrymercer Dec 17, 2025
ac6c41b
Extract zstd files too
henrymercer Dec 17, 2025
cb26a02
Require tools feature for uploading overlay DBs
henrymercer Dec 17, 2025
67e683b
Report bundled DB size in error if known
henrymercer Dec 17, 2025
a2917b0
Check !== undefined rather than truthiness
henrymercer Dec 17, 2025
a13b404
Record both truncated and full git versions
henrymercer Dec 17, 2025
a2c3c8e
Bump log level for failing to parse git version
henrymercer Dec 17, 2025
003ddae
Avoid non-determinism in PR checks due to overlay FFs
henrymercer Dec 18, 2025
eb823a7
Merge pull request #3375 from github/henrymercer/overlay-upload-tools…
henrymercer Dec 18, 2025
358a55e
Throw in test mode if can't compute git version
henrymercer Dec 18, 2025
cec3cc5
Trim git version output
henrymercer Dec 18, 2025
948c7fb
Test mode: Tolerate missing git binary
henrymercer Dec 18, 2025
ff84c6f
Improve comment
henrymercer Dec 18, 2025
a7e88a4
Only enable overlay for the code scanning suite
henrymercer Dec 18, 2025
525b648
Merge pull request #3374 from github/henrymercer/scan-debug-artifacts
henrymercer Dec 18, 2025
95246ce
Prefer explicit env var to binary accessibility check
henrymercer Dec 18, 2025
034401b
Merge branch 'main' into copilot/update-overlay-git-version-check
henrymercer Dec 18, 2025
8b428c0
Use `EnvVar`
henrymercer Dec 18, 2025
3b6fef6
Fix import order
henrymercer Dec 18, 2025
f67ec12
Merge pull request #3370 from github/copilot/update-overlay-git-versi…
henrymercer Dec 18, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
name: Verify that the best-effort debug artifact scan completed
description: Verifies that the best-effort debug artifact scan completed successfully during tests
runs:
using: node24
main: index.js
post: post.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
// The main step is a no-op, since we can only verify artifact scan completion in the post step.
console.log("Will verify artifact scan completion in the post step.");
11 changes: 11 additions & 0 deletions .github/actions/verify-debug-artifact-scan-completed/post.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
// Post step - runs after the workflow completes, when artifact scan has finished
const process = require("process");

const scanFinished = process.env.CODEQL_ACTION_ARTIFACT_SCAN_FINISHED;

if (scanFinished !== "true") {
console.error("Error: Best-effort artifact scan did not complete. Expected CODEQL_ACTION_ARTIFACT_SCAN_FINISHED=true");
process.exit(1);
}

console.log("✓ Best-effort artifact scan completed successfully");
34 changes: 27 additions & 7 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,14 +18,25 @@ For internal use only. Please select the risk level of this change:

#### Which use cases does this change impact?

<!-- Delete options that don't apply. -->
<!-- Delete options that don't apply. If in doubt, do not delete an option. -->

Workflow types:

- **Advanced setup** - Impacts users who have custom CodeQL workflows.
- **Managed** - Impacts users with `dynamic` workflows (Default Setup, CCR, ...).

Products:

- **Code Scanning** - The changes impact analyses when `analysis-kinds: code-scanning`.
- **Code Quality** - The changes impact analyses when `analysis-kinds: code-quality`.
- **CCR** - The changes impact analyses for Copilot Code Reviews.
- **Third-party analyses** - The changes affect the `upload-sarif` action.

Environments:

- **Advanced setup** - Impacts users who have custom workflows.
- **Default setup** - Impacts users who use default setup.
- **Code Scanning** - Impacts Code Scanning (i.e. `analysis-kinds: code-scanning`).
- **Code Quality** - Impacts Code Quality (i.e. `analysis-kinds: code-quality`).
- **Third-party analyses** - Impacts third-party analyses (i.e. `upload-sarif`).
- **GHES** - Impacts GitHub Enterprise Server.
- **Dotcom** - Impacts CodeQL workflows on `github.com` and/or GitHub Enterprise Cloud with Data Residency.
- **GHES** - Impacts CodeQL workflows on GitHub Enterprise Server.
- **Testing/None** - This change does not impact any CodeQL workflows in production.

#### How did/will you validate this change?

Expand Down Expand Up @@ -54,6 +65,15 @@ For internal use only. Please select the risk level of this change:
- **Alerts** - New or existing monitors will trip if something goes wrong with this change.
- **Other** - Please provide details.

#### Are there any special considerations for merging or releasing this change?

<!--
Consider whether this change depends on a different change in another repository that should be released first.
-->

- **No special considerations** - This change can be merged at any time.
- **Special considerations** - This change should only be merged once certain preconditions are met. Please provide details of those or link to this PR from an internal issue.

### Merge / deployment checklist

- Confirm this change is backwards compatible with existing workflows.
Expand Down
16 changes: 15 additions & 1 deletion .github/workflows/__all-platform-bundle.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

16 changes: 15 additions & 1 deletion .github/workflows/__analyze-ref-input.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

20 changes: 17 additions & 3 deletions .github/workflows/__autobuild-action.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__autobuild-working-dir.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__build-mode-autobuild.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

16 changes: 15 additions & 1 deletion .github/workflows/__build-mode-manual.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__build-mode-none.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__build-mode-rollback.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__bundle-from-toolcache.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__bundle-toolcache.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions .github/workflows/__bundle-zstd.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__cleanup-db-cluster-dir.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions .github/workflows/__config-export.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__config-input.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__cpp-deptrace-disabled.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__cpp-deptrace-enabled-on-macos.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion .github/workflows/__cpp-deptrace-enabled.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading