)]}'
{
  "commit": "c591b0570390b767dc6ae039eacaa6328fd17eac",
  "tree": "8807e75c9f706ef51b9fdc59c613f0bce673b8bf",
  "parents": [
    "610003ea5040313c8d3f3f6964a95fa622d8e520"
  ],
  "author": {
    "name": "dependabot[bot]",
    "email": "49699333+dependabot[bot]@users.noreply.github.com",
    "time": "Mon Apr 24 14:50:04 2023 +0200"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Mon Apr 24 14:50:04 2023 +0200"
  },
  "message": "Bump github/codeql-action from 2.2.5 to 2.2.9 (#919)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action)\r\nfrom 2.2.5 to 2.2.9.\r\n\u003cdetails\u003e\r\n\u003csummary\u003eChangelog\u003c/summary\u003e\r\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\r\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\r\n\u003cblockquote\u003e\r\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\r\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.9 - 27 Mar 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eCustomers post-processing the SARIF output of the\r\n\u003ccode\u003eanalyze\u003c/code\u003e Action before uploading it to Code Scanning will\r\nbenefit from an improved debugging experience. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1598\"\u003e#1598\u003c/a\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eThe CodeQL Action will now upload a SARIF file with debugging\r\ninformation to Code Scanning on failed runs for customers using\r\n\u003ccode\u003eupload: false\u003c/code\u003e. Previously, this was only available for\r\ncustomers using the default value of the \u003ccode\u003eupload\u003c/code\u003e input.\u003c/li\u003e\r\n\u003cli\u003eThe \u003ccode\u003eupload\u003c/code\u003e input to the \u003ccode\u003eanalyze\u003c/code\u003e Action now\r\naccepts the following values:\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ccode\u003ealways\u003c/code\u003e is the default value, which uploads the SARIF\r\nfile to Code Scanning for successful and failed runs.\u003c/li\u003e\r\n\u003cli\u003e\u003ccode\u003efailure-only\u003c/code\u003e is recommended for customers\r\npost-processing the SARIF file before uploading it to Code Scanning.\r\nThis option uploads debugging information to Code Scanning for failed\r\nruns to improve the debugging experience.\u003c/li\u003e\r\n\u003cli\u003e\u003ccode\u003enever\u003c/code\u003e avoids uploading the SARIF file to Code Scanning\r\neven if the code scanning run fails. This is not recommended for\r\nexternal users since it complicates debugging.\u003c/li\u003e\r\n\u003cli\u003eThe legacy \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003efalse\u003c/code\u003e options will be\r\ninterpreted as \u003ccode\u003ealways\u003c/code\u003e and \u003ccode\u003efailure-only\u003c/code\u003e\r\nrespectively.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.8 - 22 Mar 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.5. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1585\"\u003e#1585\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.7 - 15 Mar 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.6 - 10 Mar 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.4. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1561\"\u003e#1561\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.5 - 24 Feb 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.3. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1543\"\u003e#1543\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.4 - 10 Feb 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.3 - 08 Feb 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eUpdate default CodeQL bundle version to 2.12.2. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1518\"\u003e#1518\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.2 - 06 Feb 2023\u003c/h2\u003e\r\n\u003cul\u003e\r\n\u003cli\u003eFix an issue where customers using the CodeQL Action with the \u003ca\r\nhref\u003d\"https://docs.github.com/en/enterprise-server@3.7/admin/code-security/managing-github-advanced-security-for-your-enterprise/configuring-code-scanning-for-your-appliance#configuring-codeql-analysis-on-a-server-without-internet-access\"\u003eCodeQL\r\nAction sync tool\u003c/a\u003e would not be able to obtain the CodeQL tools. \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/1517\"\u003e#1517\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003ch2\u003e2.2.1 - 27 Jan 2023\u003c/h2\u003e\r\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\r\n\u003ch2\u003e2.2.0 - 26 Jan 2023\u003c/h2\u003e\r\n\u003c!-- raw HTML omitted --\u003e\r\n\u003c/blockquote\u003e\r\n\u003cp\u003e... (truncated)\u003c/p\u003e\r\n\u003c/details\u003e\r\n\u003cdetails\u003e\r\n\u003csummary\u003eCommits\u003c/summary\u003e\r\n\u003cul\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/04df1262e6247151b5ac09cd2c303ac36ad3f62b\"\u003e\u003ccode\u003e04df126\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1608\"\u003e#1608\u003c/a\u003e\r\nfrom github/update-v2.2.9-fb32c3fef\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/f0988cbd79ff403435044fdb9947c1ec20d01f6a\"\u003e\u003ccode\u003ef0988cb\u003c/code\u003e\u003c/a\u003e\r\nMove changelog note to correct section\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/fef20d6c357cfcd261d53a2d55b0b2132d0f6892\"\u003e\u003ccode\u003efef20d6\u003c/code\u003e\u003c/a\u003e\r\nUpdate changelog for v2.2.9\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/fb32c3fefdc4ffebe80488e4ed5d862348621d72\"\u003e\u003ccode\u003efb32c3f\u003c/code\u003e\u003c/a\u003e\r\nMerge pull request \u003ca\r\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/1605\"\u003e#1605\u003c/a\u003e\r\nfrom github/henrymercer/diagnostics-grouping-workaround\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/329c022f486ae3deced8c256a11365c7a7799041\"\u003e\u003ccode\u003e329c022\u003c/code\u003e\u003c/a\u003e\r\nJust check the number of locations\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/c8935d5a9dbe3383438a0f489ca0c6f7fa2743c3\"\u003e\u003ccode\u003ec8935d5\u003c/code\u003e\u003c/a\u003e\r\nRemove duplicate locations from failed run SARIF\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/ade432fd683e818e4efbc4a803160f5b4f13926e\"\u003e\u003ccode\u003eade432f\u003c/code\u003e\u003c/a\u003e\r\nRemove duplicate locations from output of \u003ccode\u003edatabase\r\ninterpret-results\u003c/code\u003e\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/6f852eeb3899f7918bf6f5d7a201a98a18ce5b51\"\u003e\u003ccode\u003e6f852ee\u003c/code\u003e\u003c/a\u003e\r\nImplement removing duplicate locations from a SARIF file\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/097ab4665fecf3c04acc545d74e40d782046c9e3\"\u003e\u003ccode\u003e097ab46\u003c/code\u003e\u003c/a\u003e\r\nSpeed up checks a bit by just running the standard suite\u003c/li\u003e\r\n\u003cli\u003e\u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/commit/befd804b8b0075fbae00d57bc215f6e0ea6033a5\"\u003e\u003ccode\u003ebefd804\u003c/code\u003e\u003c/a\u003e\r\nExtend diagnostics export integration test to capture location bug\u003c/li\u003e\r\n\u003cli\u003eAdditional commits viewable in \u003ca\r\nhref\u003d\"https://github.com/github/codeql-action/compare/32dc499307d133bb5085bae78498c0ac2cf762d5...04df1262e6247151b5ac09cd2c303ac36ad3f62b\"\u003ecompare\r\nview\u003c/a\u003e\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/details\u003e\r\n\u003cbr /\u003e\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.2.5\u0026new-version\u003d2.2.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n\u003cdetails\u003e\r\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\r\n\u003cbr /\u003e\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\n\r\n\r\n\u003c/details\u003e\r\n\r\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\r\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\r\nCo-authored-by: Pierre-Louis \u003c6655696+guidezpl@users.noreply.github.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "a9afd3ac956cae25c41d19ea30e15d261f093b38",
      "old_mode": 33188,
      "old_path": ".github/workflows/scorecards-analysis.yml",
      "new_id": "b5b29a3f0d2290d1258a67072e14762f2a1e40bc",
      "new_mode": 33188,
      "new_path": ".github/workflows/scorecards-analysis.yml"
    }
  ]
}
