From 490c103e5a0209cf36ce807c446aa0ea4dab7181 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Thu, 19 Sep 2024 09:53:32 +0000
Subject: [PATCH] Bump github/codeql-action from 3.26.7 to 3.26.8 (#896)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.26.7 to 3.26.8.
Commits
294a9d9
Merge pull request #2490 from github/update-v3.26.8-64431c66d
00b3604
Update changelog for v3.26.8
64431c6
Merge pull request #2483 from github/update-bundle/codeql-bundle-v2.19.0
e0e2d75
Merge branch 'main' into update-bundle/codeql-bundle-v2.19.0
cb28816
Merge pull request #2487 from rvermeulen/rvermeulen/uri-errors-as-warnings
498c508
Rebuild JavaScript files
a1a585f
Merge branch 'main' into rvermeulen/uri-errors-as-warnings
34666c1
Merge pull request #2488 from github/henrymercer/debug-artifacts-better-logging
6e24973
Improve logging for combined SARIF debug artifact
d0a3cf2
Improve logging for debug artifacts
- Additional commits viewable in compare view
Most Recent Ignore Conditions Applied to This Pull Request
| Dependency Name | Ignore Conditions |
| --- | --- |
| github/codeql-action | [< 2.3.5, > 2.3.4] |
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=3.26.7&new-version=3.26.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
---
.github/workflows/scorecards-analysis.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml
index eac1a13c18..6dd9a60f1f 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -51,6 +51,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
- uses: github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d
+ uses: github/codeql-action/upload-sarif@294a9d92911152fe08befb9ec03e240add280cb3
with:
sarif_file: results.sarif