)]}'
{
  "commit": "2ee942ab6455e3cb956eec88ffa17a79a59d5067",
  "tree": "84ee300dae2459bc913dd296285548b54753b3c0",
  "parents": [
    "873b7054da3ae56f099df92405eed4fc406498af"
  ],
  "author": {
    "name": "dependabot[bot]",
    "email": "49699333+dependabot[bot]@users.noreply.github.com",
    "time": "Wed Aug 09 14:01:14 2023 +0200"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Wed Aug 09 14:01:14 2023 +0200"
  },
  "message": "Bump github/codeql-action from 2.20.1 to 2.21.2 (#985)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action)\r\nfrom 2.20.1 to 2.21.2.\r\n\u003cdetails\u003e\r\n\u003csummary\u003eChangelog\u003c/summary\u003e\r\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\r\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\r\n\u003cblockquote\u003e\r\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\r\n\u003cp\u003eSee the \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\r\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\r\npacks.\u003c/p\u003e\r\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eWe are rolling out a feature in August 2023 that will improve\r\nmulti-threaded performance on larger runners. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1817\"\u003e#1817\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.21.2 - 28 Jul 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.1. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1797\"\u003e#1797\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eAvoid duplicating the analysis summary within the logs. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1811\"\u003e#1811\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.21.1 - 26 Jul 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eImprove the handling of fatal errors from the CodeQL CLI. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1795\"\u003e#1795\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eAdd the \u003ccode\u003esarif-output\u003c/code\u003e output to the analyze action that\r\ncontains the path to the directory of the generated SARIF. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1799\"\u003e#1799\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.21.0 - 19 Jul 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eCodeQL Action now requires CodeQL CLI 2.9.4 or later. For more\r\ninformation, see the corresponding changelog entry for CodeQL Action\r\nversion 2.20.4. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1724\"\u003e#1724\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.20.4 - 14 Jul 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eThis is the last release of the Action that supports CodeQL CLI\r\nversions 2.8.5 to 2.9.3. These versions of the CodeQL CLI were\r\ndeprecated on June 20, 2023 alongside GitHub Enterprise Server 3.5 and\r\nwill not be supported by the next release of the CodeQL Action (2.21.0).\r\n\u003cul\u003e\r\n\u003cli\u003eIf you are using one of these versions, please update to CodeQL CLI\r\nversion 2.9.4 or later. For instance, if you have specified a custom\r\nversion of the CLI using the \u0027tools\u0027 input to the \u0027init\u0027 Action, you can\r\nremove this input to use the default version.\u003c/li\u003e\r\n\u003cli\u003eAlternatively, if you want to continue using a version of the CodeQL\r\nCLI between 2.8.5 and 2.9.3, you can replace\r\n\u0027github/codeql-action/\u003cem\u003e\u003ca\r\nhref\u003d\"https://github.com/v2\"\u003e\u003ccode\u003e@​v2\u003c/code\u003e\u003c/a\u003e\u0027 by\r\n\u0027github/codeql-action/\u003c/em\u003e\u003ca\r\nhref\u003d\"https://github.com/v2\"\u003e\u003ccode\u003e@​v2\u003c/code\u003e\u003c/a\u003e.20.4\u0027 in your code\r\nscanning workflow to ensure you continue using this version of the\r\nCodeQL Action.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003cli\u003eWe are rolling out a feature in July 2023 that will slightly reduce\r\nthe default amount of RAM used for query execution, in proportion to the\r\nrunner\u0027s total memory. This will help to avoid out-of-memory failures on\r\nlarger runners. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1760\"\u003e#1760\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.0. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1762\"\u003e#1762\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.20.3 - 06 Jul 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.5. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1743\"\u003e#1743\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.20.2 - 03 Jul 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.20.1 - 21 Jun 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.4. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1721\"\u003e#1721\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eExperimental: add a new \u003ccode\u003eresolve-environment\u003c/code\u003e action\r\nwhich attempts to infer a configuration for the build environment that\r\nis required to build a given project. Do not use this in production as\r\nit is part of an internal experiment and subject to change at any\r\ntime.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.20.0 - 13 Jun 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eBump the version of the Action to 2.20.0. This ensures that users\r\nwho received a Dependabot upgrade to \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/cdcdbb579706841c47f7063dda365e292e5cad7a\"\u003e\u003ccode\u003ecdcdbb5\u003c/code\u003e\u003c/a\u003e,\r\nwhich was mistakenly marked as Action version 2.13.4, continue to\r\nreceive updates to the CodeQL Action. Full details in \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1729\"\u003e#1729\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.3.6 - 01 Jun 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.3. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1698\"\u003e#1698\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c!-- raw HTML omitted --\u003e\r\n\u003c/blockquote\u003e\r\n\u003cp\u003e... (truncated)\u003c/p\u003e\r\n\u003c/details\u003e\r\n\u003cdetails\u003e\r\n\u003csummary\u003eCommits\u003c/summary\u003e\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/0ba4244466797eb048eb91a6cd43d5c03ca8bd05\"\u003e\u003ccode\u003e0ba4244\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1813\"\u003e#1813\u003c/a\u003e\r\nfrom github/update-v2.21.2-10c6bfee1\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/a9a416c8f416ad4eb757d9dfb734f7c7c2135b59\"\u003e\u003ccode\u003ea9a416c\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog for v2.21.2\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/10c6bfee1203aaee088328bf6c8b5e1a68b10d52\"\u003e\u003ccode\u003e10c6bfe\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1811\"\u003e#1811\u003c/a\u003e\r\nfrom github/henrymercer/print-summary-once\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/feea86eed3312cf8448c22bc5a887f26f4023c78\"\u003e\u003ccode\u003efeea86e\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1810\"\u003e#1810\u003c/a\u003e\r\nfrom github/henrymercer/ci/use-platform-specific-bun...\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/2e6f8c08c115f4741890e32679542130a51f53d1\"\u003e\u003ccode\u003e2e6f8c0\u003c/code\u003e\u003c/a\u003e\r\nAdd changelog note\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/8342844ea722dd44af414e7eed5ced0e67fe5c44\"\u003e\u003ccode\u003e8342844\u003c/code\u003e\u003c/a\u003e\r\nOnly print the analysis summary once\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/679aac1b20947026d7575616383725ec2d5928cf\"\u003e\u003ccode\u003e679aac1\u003c/code\u003e\u003c/a\u003e\r\nUse platform specific bundles in PR checks\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/de6681ceb7967227f8760bfad7bde8540662f894\"\u003e\u003ccode\u003ede6681c\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1797\"\u003e#1797\u003c/a\u003e\r\nfrom github/update-bundle/codeql-bundle-v2.14.1\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/f6fe5c5c7031df5b91cc10eab7f02444d9880834\"\u003e\u003ccode\u003ef6fe5c5\u003c/code\u003e\u003c/a\u003e\r\nMerge branch \u0027main\u0027 into update-bundle/codeql-bundle-v2.14.1\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/62762170e1531f7cbc3cfc2d654408173f80d3ca\"\u003e\u003ccode\u003e6276217\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1808\"\u003e#1808\u003c/a\u003e\r\nfrom github/mergeback/v2.21.1-to-main-6ca1aa8c\u003c/li\u003e\r\n\u003cli\u003eAdditional commits viewable in \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/compare/f6e388ebf0efc915c6c5b165b019ee61a6746a38...0ba4244466797eb048eb91a6cd43d5c03ca8bd05\"\u003ecompare\r\nview\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/details\u003e\r\n\u003cbr /\u003e\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.20.1\u0026new-version\u003d2.21.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n\u003cdetails\u003e\r\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\r\n\u003cbr /\u003e\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\n\r\n\r\n\u003c/details\u003e\r\n\r\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\r\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "73cde8123bafd6f65b9ee1989d562443a43ae872",
      "old_mode": 33188,
      "old_path": ".github/workflows/scorecards-analysis.yml",
      "new_id": "a67a8ab1986e6e1fe9d1347c3adc57f5b82dbf38",
      "new_mode": 33188,
      "new_path": ".github/workflows/scorecards-analysis.yml"
    }
  ]
}
