)]}'
{
  "commit": "6fa29dc0d1ba496b6858b07c4465757e2025f548",
  "tree": "5448976471891fb919964b52276dfabf90d56e01",
  "parents": [
    "652654217f0c03274b5e8508296fd36550fd8c98"
  ],
  "author": {
    "name": "dependabot[bot]",
    "email": "49699333+dependabot[bot]@users.noreply.github.com",
    "time": "Wed May 03 11:43:03 2023 +0200"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Wed May 03 11:43:03 2023 +0200"
  },
  "message": "Bump github/codeql-action from 2.2.9 to 2.3.2 (#946)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action)\r\nfrom 2.2.9 to 2.3.2.\r\n\u003cdetails\u003e\r\n\u003csummary\u003eChangelog\u003c/summary\u003e\r\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\r\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\r\n\u003cblockquote\u003e\r\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\r\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eYou can now configure CodeQL within your code scanning workflow by\r\npassing a \u003ccode\u003econfig\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1590\"\u003e#1590\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.3.2 - 27 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.3.1 - 26 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.3.0 - 21 Apr 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.13.0. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1649\"\u003e#1649\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eBump the minimum CodeQL bundle version to 2.8.5. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1618\"\u003e#1618\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.12 - 13 Apr 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eInclude the value of the \u003ccode\u003eGITHUB_RUN_ATTEMPT\u003c/code\u003e environment\r\nvariable in the telemetry sent to GitHub. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1640\"\u003e#1640\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eImprove the ease of debugging failed runs configured using \u003ca\r\nhref\u003d\"https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning-for-a-repository#configuring-code-scanning-automatically\"\u003edefault\r\nsetup\u003c/a\u003e. The CodeQL Action will now upload diagnostic information to\r\nCode Scanning from failed runs configured using default setup. You can\r\nview this diagnostic information on the \u003ca\r\nhref\u003d\"https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/about-the-tool-status-page\"\u003etool\r\nstatus page\u003c/a\u003e. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1619\"\u003e#1619\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.11 - 06 Apr 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.10 - 05 Apr 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.6. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1629\"\u003e#1629\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.9 - 27 Mar 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eCustomers post-processing the SARIF output of the\r\n\u003ccode\u003eanalyze\u003c/code\u003e Action before uploading it to Code Scanning will\r\nbenefit from an improved debugging experience. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1598\"\u003e#1598\u003c/a\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eThe CodeQL Action will now upload a SARIF file with debugging\r\ninformation to Code Scanning on failed runs for customers using\r\n\u003ccode\u003eupload: false\u003c/code\u003e. Previously, this was only available for\r\ncustomers using the default value of the \u003ccode\u003eupload\u003c/code\u003e input.\u003c/li\u003e\r\n\u003cli\u003eThe \u003ccode\u003eupload\u003c/code\u003e input to the \u003ccode\u003eanalyze\u003c/code\u003e Action now\r\naccepts the following values:\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ccode\u003ealways\u003c/code\u003e is the default value, which uploads the SARIF\r\nfile to Code Scanning for successful and failed runs.\u003c/li\u003e\r\n\u003cli\u003e\u003ccode\u003efailure-only\u003c/code\u003e is recommended for customers\r\npost-processing the SARIF file before uploading it to Code Scanning.\r\nThis option uploads debugging information to Code Scanning for failed\r\nruns to improve the debugging experience.\u003c/li\u003e\r\n\u003cli\u003e\u003ccode\u003enever\u003c/code\u003e avoids uploading the SARIF file to Code Scanning\r\neven if the code scanning run fails. This is not recommended for\r\nexternal users since it complicates debugging.\u003c/li\u003e\r\n\u003cli\u003eThe legacy \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003efalse\u003c/code\u003e options will be\r\ninterpreted as \u003ccode\u003ealways\u003c/code\u003e and \u003ccode\u003efailure-only\u003c/code\u003e\r\nrespectively.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.8 - 22 Mar 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.5. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1585\"\u003e#1585\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.7 - 15 Mar 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003c!-- raw HTML omitted --\u003e\r\n\u003c/blockquote\u003e\r\n\u003cp\u003e... (truncated)\u003c/p\u003e\r\n\u003c/details\u003e\r\n\u003cdetails\u003e\r\n\u003csummary\u003eCommits\u003c/summary\u003e\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/f3feb00acb00f31a6f60280e6ace9ca31d91c76a\"\u003e\u003ccode\u003ef3feb00\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1662\"\u003e#1662\u003c/a\u003e\r\nfrom github/update-v2.3.2-8b12d99ee\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/1c9e206df383bfc09ee3e171f439c1c17eec2e8f\"\u003e\u003ccode\u003e1c9e206\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog for v2.3.2\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/8b12d99ee5a822a549eddd7b4d0fa8debbb5229e\"\u003e\u003ccode\u003e8b12d99\u003c/code\u003e\u003c/a\u003e\r\nFix bug where run attempt was reported as run ID (\u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1661\"\u003e#1661\u003c/a\u003e)\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/dcf71cf79bcf5f35de270a5eaece62a77b559094\"\u003e\u003ccode\u003edcf71cf\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1660\"\u003e#1660\u003c/a\u003e\r\nfrom github/mergeback/v2.3.1-to-main-8662eabe\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/194450bdd6b6d3ba51090467f99d0db4a9894718\"\u003e\u003ccode\u003e194450b\u003c/code\u003e\u003c/a\u003e\r\nUpdate checked-in dependencies\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/e78ef455a83f42e33e3a5102cc2657468c126668\"\u003e\u003ccode\u003ee78ef45\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog and version after v2.3.1\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/8662eabe0e9f338a07350b7fd050732745f93848\"\u003e\u003ccode\u003e8662eab\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1659\"\u003e#1659\u003c/a\u003e\r\nfrom github/update-v2.3.1-da583b07a\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/1f2f707d999190f10a1f8a336f3d6e7972cbf00a\"\u003e\u003ccode\u003e1f2f707\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog for v2.3.1\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/da583b07a7c587e17604358c799ad8adf110f3e4\"\u003e\u003ccode\u003eda583b0\u003c/code\u003e\u003c/a\u003e\r\nAdd \u003ccode\u003eworkload_run_attempt\u003c/code\u003e to analysis upload (\u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/a9648ea7c684e61497d9a56b7b560a9640298dce\"\u003e\u003ccode\u003ea9648ea\u003c/code\u003e\u003c/a\u003e\r\nThrow full error for CLI bundle download (\u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1657\"\u003e#1657\u003c/a\u003e)\u003c/li\u003e\r\n\u003cli\u003eAdditional commits viewable in \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/compare/04df1262e6247151b5ac09cd2c303ac36ad3f62b...f3feb00acb00f31a6f60280e6ace9ca31d91c76a\"\u003ecompare\r\nview\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/details\u003e\r\n\u003cbr /\u003e\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.2.9\u0026new-version\u003d2.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n\u003cdetails\u003e\r\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\r\n\u003cbr /\u003e\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\n\r\n\r\n\u003c/details\u003e\r\n\r\n---------\r\n\r\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\r\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\r\nCo-authored-by: Pierre-Louis \u003c6655696+guidezpl@users.noreply.github.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "168fcdb0359e566d07e9721c0a9afb46d7a879f9",
      "old_mode": 33188,
      "old_path": ".github/workflows/scorecards-analysis.yml",
      "new_id": "495a151c0e6ff2130bc9140d3a8b11b54644d027",
      "new_mode": 33188,
      "new_path": ".github/workflows/scorecards-analysis.yml"
    }
  ]
}
