)]}'
{
  "commit": "d8b5ea202e70989625d489f7ad6679fcfa251acf",
  "tree": "50b480c68becf877bee9c8ca2d1279304e23d080",
  "parents": [
    "ee8b61eae1f6169b1bc09a17bfb163e12196c8d1"
  ],
  "author": {
    "name": "dependabot[bot]",
    "email": "49699333+dependabot[bot]@users.noreply.github.com",
    "time": "Fri Oct 06 22:15:19 2023 +0000"
  },
  "committer": {
    "name": "dart-internal-monorepo",
    "email": "dart-internal-monorepo@dart-ci-internal.iam.gserviceaccount.com",
    "time": "Fri Oct 06 15:21:10 2023 -0700"
  },
  "message": "Bump github/codeql-action from 2.21.6 to 2.22.0 (#136095)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action) from 2.21.6 to 2.22.0.\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e2.22.0 - 06 Oct 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe CodeQL Action now requires CodeQL version 2.10.5 or later. For more information, see the corresponding changelog entry for CodeQL Action version 2.21.8. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1907\"\u003e#1907\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action no longer runs ML-powered queries. For more information, including details on our investment in AI-powered security technology, see \u003ca href\u003d\"https://github.blog/changelog/2023-09-29-codeql-code-scanning-deprecates-ml-powered-alerts/\"\u003e\u0026quot;CodeQL code scanning deprecates ML-powered alerts.\u0026quot;\u003c/a\u003e \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1910\"\u003e#1910\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix a bug which prevented tracing of projects using Go 1.21 and above on Linux. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1909\"\u003e#1909\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.9 - 27 Sep 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.6. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1897\"\u003e#1897\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out a feature in October 2023 that will improve the success rate of C/C++ autobuild. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1889\"\u003e#1889\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out a feature in October 2023 that will provide specific file coverage information for C and C++, Java and Kotlin, and JavaScript and TypeScript. Currently file coverage information for each of these pairs of languages is grouped together. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1903\"\u003e#1903\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a warning to help customers avoid inadvertently analyzing the same CodeQL language in multiple matrix jobs. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1901\"\u003e#1901\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.8 - 19 Sep 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd a deprecation warning for customers using CodeQL version 2.10.4 and earlier. These versions of CodeQL were discontinued on 12 September 2023 alongside GitHub Enterprise Server 3.6, and will be unsupported by the next minor release of the CodeQL Action. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1884\"\u003e#1884\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eIf you are using one of these versions, please update to CodeQL CLI version 2.10.5 or later. For instance, if you have specified a custom version of the CLI using the \u0027tools\u0027 input to the \u0027init\u0027 Action, you can remove this input to use the default version.\u003c/li\u003e\n\u003cli\u003eAlternatively, if you want to continue using a version of the CodeQL CLI between 2.9.5 and 2.10.4, you can replace \u003ccode\u003egithub/codeql-action/*@v2\u003c/code\u003e by \u003ccode\u003egithub/codeql-action/*@v2.21.7\u003c/code\u003e in your code scanning workflow to ensure you continue using this version of the CodeQL Action.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eEnable the following language aliases when using CodeQL 2.14.4 and later: \u003ccode\u003ec-cpp\u003c/code\u003e for C/C++ analysis, \u003ccode\u003ejava-kotlin\u003c/code\u003e for Java/Kotlin analysis, and \u003ccode\u003ejavascript-typescript\u003c/code\u003e for JavaScript/TypeScript analysis. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1883\"\u003e#1883\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.7 - 14 Sep 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.5. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1882\"\u003e#1882\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.6 - 13 Sep 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBetter error message when there is a failure to determine the merge base of the code to analysis. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1860\"\u003e#1860\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove the calculation of default amount of RAM used for query execution on GitHub Enterprise Server. This now reduces in proportion to the runner\u0027s total memory to better account for system memory usage, helping to avoid out-of-memory failures on larger runners. This feature is already available to GitHub.com users. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1866\"\u003e#1866\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable improved file coverage information for GitHub Enterprise Server users. This feature is already available to GitHub.com users. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1867\"\u003e#1867\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.4. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1873\"\u003e#1873\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.5 - 28 Aug 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.3. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1845\"\u003e#1845\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in CodeQL Action 2.21.3 onwards that affected beta support for \u003ca href\u003d\"https://projectlombok.org/\"\u003eProject Lombok\u003c/a\u003e when analyzing Java. The environment variable \u003ccode\u003eCODEQL_EXTRACTOR_JAVA_RUN_ANNOTATION_PROCESSORS\u003c/code\u003e will now be respected if it was manually configured in the workflow. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1844\"\u003e#1844\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable support for Kotlin 1.9.20 when running with CodeQL CLI v2.13.4 through v2.14.3. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1853\"\u003e#1853\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.21.4 - 14 Aug 2023\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.14.2. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1831\"\u003e#1831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLog a warning if the amount of available disk space runs low during a code scanning run. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1825\"\u003e#1825\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen downloading CodeQL bundle version 2.13.4 and later, cache these bundles in the Actions tool cache using a simpler version number. \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/pull/1832\"\u003e#1832\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/2cb752a87e96af96708ab57187ab6372ee1973ab\"\u003e\u003ccode\u003e2cb752a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/issues/1924\"\u003e#1924\u003c/a\u003e from github/update-v2.22.0-3f7850a17\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/e50f53baa18da7571fefe4e56edeba46be9f183b\"\u003e\u003ccode\u003ee50f53b\u003c/code\u003e\u003c/a\u003e Add changelog note for tracing Go 1.21\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/0a65c007f6b702f7d53f89a44248406aae709942\"\u003e\u003ccode\u003e0a65c00\u003c/code\u003e\u003c/a\u003e Update changelog for v2.22.0\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/3f7850a17964ee76fbc058c4cf3360bfd6840486\"\u003e\u003ccode\u003e3f7850a\u003c/code\u003e\u003c/a\u003e Improve downloading log message (\u003ca href\u003d\"https://redirect.github.com/github/codeql-action/issues/1920\"\u003e#1920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/27235304e07da3d62be5a72ef5df0f30d8a4e137\"\u003e\u003ccode\u003e2723530\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/issues/1923\"\u003e#1923\u003c/a\u003e from github/henrymercer/fix-resolve-environment-aliases\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/8f0e8b0890952ad94f9d4f1a44170b0f27723054\"\u003e\u003ccode\u003e8f0e8b0\u003c/code\u003e\u003c/a\u003e Tweak language parsing to improve clarity\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/f243294ab74b285a547a838884ca660a740ce2a6\"\u003e\u003ccode\u003ef243294\u003c/code\u003e\u003c/a\u003e Extend PR check to test \u003ccode\u003eresolve-environment\u003c/code\u003e works with language alias\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/1ea6a10947dbce58fd4e0ff685cdec23e7f50145\"\u003e\u003ccode\u003e1ea6a10\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href\u003d\"https://redirect.github.com/github/codeql-action/issues/1909\"\u003e#1909\u003c/a\u003e from github/mbg/go-1.21-workaround\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/e26ed57a228512338332f937ef0f121a739d548c\"\u003e\u003ccode\u003ee26ed57\u003c/code\u003e\u003c/a\u003e Defer language aliasing to CLI when appropriate\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/github/codeql-action/commit/0ac7669167fa236dc2e1eec93d82674b1a265327\"\u003e\u003ccode\u003e0ac7669\u003c/code\u003e\u003c/a\u003e Fix using \u003ccode\u003eresolve-environment\u003c/code\u003e Action with language aliases\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href\u003d\"https://github.com/github/codeql-action/compare/701f152f28d4350ad289a5e31435e9ab6169a7ca...2cb752a87e96af96708ab57187ab6372ee1973ab\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.21.6\u0026new-version\u003d2.22.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\u003c/details\u003e\nhttps://dart.googlesource.com/external/github.com/flutter/flutter/+/bc315144340373d20cf34d47100f4c0d94444882\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "b2334a4cd54cac0406dcd83513e734bcab47febd",
      "old_mode": 33188,
      "old_path": "DEPS",
      "new_id": "7b8c8bafef916c484d3db0ffdfc5542b340c75f4",
      "new_mode": 33188,
      "new_path": "DEPS"
    },
    {
      "type": "modify",
      "old_id": "7c2cab3ea7ac199c6cbeb6cc0a3becb73b73a3d9",
      "old_mode": 33188,
      "old_path": "commits.json",
      "new_id": "e75209f22534f764c2672505670aadb844f26376",
      "new_mode": 33188,
      "new_path": "commits.json"
    }
  ]
}
