)]}'
{
  "commit": "21b1257437f7ca52ae96bfa9e4f8bfdc18794d73",
  "tree": "dee9b99d92548709904b343f58d9afa1fadb5080",
  "parents": [
    "2a41c50231c0446a86ded1756f8af6d37fef69b9"
  ],
  "author": {
    "name": "dependabot[bot]",
    "email": "49699333+dependabot[bot]@users.noreply.github.com",
    "time": "Thu Jun 01 21:58:10 2023 +0200"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Thu Jun 01 21:58:10 2023 +0200"
  },
  "message": "Bump github/codeql-action from 2.3.2 to 2.3.6 (#958)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action)\r\nfrom 2.3.2 to 2.3.6.\r\n\u003cdetails\u003e\r\n\u003csummary\u003eChangelog\u003c/summary\u003e\r\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\r\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\r\n\u003cblockquote\u003e\r\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\r\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.3.5 - 25 May 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eAllow invalid URIs to be used as values to\r\n\u003ccode\u003eartifactLocation.uri\u003c/code\u003e properties. This reverses a change\r\nfrom \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1668\"\u003e#1668\u003c/a\u003e\r\nthat inadvertently led to stricter validation of some URI values. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1705\"\u003e#1705\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eGracefully handle invalid URIs when fingerprinting. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1694\"\u003e#1694\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.3.4 - 24 May 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdated the SARIF 2.1.0 JSON schema file to the latest from \u003ca\r\nhref\u003d\"https://github.com/oasis-tcs/sarif-spec/blob/123e95847b13fbdd4cbe2120fa5e33355d4a042b/Schemata/sarif-schema-2.1.0.json\"\u003eoasis-tcs/sarif-spec\u003c/a\u003e.\r\n\u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1668\"\u003e#1668\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eWe are rolling out a feature in May 2023 that will disable Python\r\ndependency installation for new users of the CodeQL Action. This\r\nimproves the speed of analysis while having only a very minor impact on\r\nresults. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1676\"\u003e#1676\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eWe are improving the way that \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003eCodeQL\r\nbundles\u003c/a\u003e are tagged to make it possible to easily identify bundles by\r\ntheir CodeQL semantic version. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1682\"\u003e#1682\u003c/a\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eAs of CodeQL CLI 2.13.4, CodeQL bundles will be tagged using\r\nsemantic versions, for example \u003ccode\u003ecodeql-bundle-v2.13.4\u003c/code\u003e,\r\ninstead of timestamps, like \u003ccode\u003ecodeql-bundle-20230615\u003c/code\u003e.\u003c/li\u003e\r\n\u003cli\u003eThis change does not affect the majority of workflows, and we will\r\nnot be changing tags for existing bundle releases.\u003c/li\u003e\r\n\u003cli\u003eSome workflows with custom logic that depends on the specific format\r\nof the CodeQL bundle tag may need to be updated. For example, if your\r\nworkflow matches CodeQL bundle tag names against a\r\n\u003ccode\u003ecodeql-bundle-yyyymmdd\u003c/code\u003e pattern, you should update it to\r\nalso recognize \u003ccode\u003ecodeql-bundle-vx.y.z\u003c/code\u003e tags.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003cli\u003eRemove the requirement for \u003ccode\u003eon.push\u003c/code\u003e and\r\n\u003ccode\u003eon.pull_request\u003c/code\u003e to trigger on the same branches. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1675\"\u003e#1675\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.3. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1698\"\u003e#1698\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.3.3 - 04 May 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.1. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1664\"\u003e#1664\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eYou can now configure CodeQL within your code scanning workflow by\r\npassing a \u003ccode\u003econfig\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. See\r\n\u003ca href\u003d\"https://aka.ms/code-scanning-docs/config-file\"\u003eUsing a custom\r\nconfiguration file\u003c/a\u003e for more information about configuring code\r\nscanning. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1590\"\u003e#1590\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.3.2 - 27 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.3.1 - 26 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.3.0 - 21 Apr 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.0. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1649\"\u003e#1649\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eBump the minimum CodeQL bundle version to 2.8.5. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1618\"\u003e#1618\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.12 - 13 Apr 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eInclude the value of the \u003ccode\u003eGITHUB_RUN_ATTEMPT\u003c/code\u003e environment\r\nvariable in the telemetry sent to GitHub. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1640\"\u003e#1640\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eImprove the ease of debugging failed runs configured using \u003ca\r\nhref\u003d\"https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning-for-a-repository#configuring-code-scanning-automatically\"\u003edefault\r\nsetup\u003c/a\u003e. The CodeQL Action will now upload diagnostic information to\r\nCode Scanning from failed runs configured using default setup. You can\r\nview this diagnostic information on the \u003ca\r\nhref\u003d\"https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/about-the-tool-status-page\"\u003etool\r\nstatus page\u003c/a\u003e. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1619\"\u003e#1619\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.11 - 06 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.10 - 05 Apr 2023\u003c/h2\u003e\r\n\u003c!-- raw HTML omitted --\u003e\r\n\u003c/blockquote\u003e\r\n\u003cp\u003e... (truncated)\u003c/p\u003e\r\n\u003c/details\u003e\r\n\u003cdetails\u003e\r\n\u003csummary\u003eCommits\u003c/summary\u003e\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/83f0fe6c4988d98a455712a27f0255212bba9bd4\"\u003e\u003ccode\u003e83f0fe6\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1713\"\u003e#1713\u003c/a\u003e\r\nfrom github/update-v2.3.6-96f284028\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/5c8f4be0e98de2abecc7af538676cf2384a881fc\"\u003e\u003ccode\u003e5c8f4be\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog for v2.3.6\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/96f284028262d223858647b5680642a84608cc87\"\u003e\u003ccode\u003e96f2840\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1711\"\u003e#1711\u003c/a\u003e\r\nfrom github/henrymercer/improve-supported-versions-u...\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/89c4c9e65cd3faf5d84dba8f43bb308fae40336d\"\u003e\u003ccode\u003e89c4c9e\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1678\"\u003e#1678\u003c/a\u003e\r\nfrom github/henrymercer/default-setup-safeguarding\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/26f16a5e63c7bebdcf17b2a6d1c7fc1861a0c611\"\u003e\u003ccode\u003e26f16a5\u003c/code\u003e\u003c/a\u003e\r\nRephrase the still supported calculation to make it clearer\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/955f8596aed9d71c454c46b251302b150bc1adcb\"\u003e\u003ccode\u003e955f859\u003c/code\u003e\u003c/a\u003e\r\nFix sign error\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/e7cff66ce1871fdb3b9cdf054e5550485c0b8d12\"\u003e\u003ccode\u003ee7cff66\u003c/code\u003e\u003c/a\u003e\r\nFix push\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/afdba763260a797d16bcce8e498641fefd604731\"\u003e\u003ccode\u003eafdba76\u003c/code\u003e\u003c/a\u003e\r\nWait a week before dropping support for end of life GHES versions\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/07e43a22080d8828875556729afa669d200b9515\"\u003e\u003ccode\u003e07e43a2\u003c/code\u003e\u003c/a\u003e\r\nOpen PR with gh CLI\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/9632771630d75f08faa5a3b6f5afc9d44a6a65b0\"\u003e\u003ccode\u003e9632771\u003c/code\u003e\u003c/a\u003e\r\nAddress review comments\u003c/li\u003e\r\n\u003cli\u003eAdditional commits viewable in \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/compare/f3feb00acb00f31a6f60280e6ace9ca31d91c76a...83f0fe6c4988d98a455712a27f0255212bba9bd4\"\u003ecompare\r\nview\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/details\u003e\r\n\u003cbr /\u003e\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.3.2\u0026new-version\u003d2.3.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n\u003cdetails\u003e\r\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\r\n\u003cbr /\u003e\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\n\r\n\r\n\u003c/details\u003e\r\n\r\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\r\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "495a151c0e6ff2130bc9140d3a8b11b54644d027",
      "old_mode": 33188,
      "old_path": ".github/workflows/scorecards-analysis.yml",
      "new_id": "97d0109d0ae1d599a7ac0d9d9c60ee395eec8138",
      "new_mode": 33188,
      "new_path": ".github/workflows/scorecards-analysis.yml"
    }
  ]
}
