Sourced from gunicorn's releases.
gunicorn 26.1.0
New Features
- Glob patterns in
reload_extra_files: entries containing*,?or[are treated as patterns, soui/*/config.jsonwatches every view's config without listing them one by one. Patterns are re-expanded on every reload check rather than once at startup, so a file created later starts being watched without restarting gunicorn, and**recurses. A pattern matching nothing warns instead of failing, since with live expansion it may match later (#1643, #3662).Security
- Dependency floors raised past known advisories: every declared floor was checked against the advisory database.
tornado,h2,setuptoolsandpymdown-extensionspermitted vulnerable versions and now require the first clean release;pytestandhttpxwere unpinned and now carry floors. Thetornadoexample pinnedtornado<6, which was both the source of several advisories and older than the>=6.5.0the tornado worker needs, so the example could not run as pinned.Bug Fixes
SIGHUP did not reload the logger configuration:
Arbiter.reload()re-read the configuration file but kept using the logger built at startup, calling onlyreopen_files()on its existing handlers. Changes tologconfig,logconfig_dict,logconfig_jsonandloglevelwere ignored until a full restart, which in containers meant replacing the pod. The existing logger now re-runs its setup on reload, so new handlers, formats and levels take effect while the process identity and its listeners are preserved, and re-running the setup no longer stacks duplicate syslog handlers. An invalid log configuration on reload is not fatal either: the error is reported on stderr, the previous working configuration is restored and the master keeps running with it (#3353).Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked body with
0 CRLF CRLF, the second CRLF being the mandatory empty trailer section.ChunkedReader.parse_chunk_size()swallowed theNoMoreDataraised while scanning for it, so a body cut short right after the last chunk line was treated as complete instead of rejected. It now raisesChunkMissingTerminator(#3382, #3685).
--spewcrashed on dynamically generated code: the trace hook indexed the 2-tuple returned byinspect.getsourcelines()by line number rather than indexing the list of lines, so a frame with no__file__raisedAttributeError: 'int' object has no attribute 'rstrip'on line 1 and
... (truncated)
71b59a7
Merge pull request #3698
from benoitc/fix/docker-health-check-readerror48287de
test: catch every transport error in the docker health check3110e8c
Merge pull request #3696
from benoitc/docs/roadmapcc56c41
Merge pull request #3693
from benoitc/release/26.1.05cf1f16
docs: surface the roadmap on the site home page7e35f72
docs: add FastCGI to the roadmap and point items at Ideas18ddc58
docs: drop the framework and reverse-proxy non-goals from the
roadmap1ecae56
docs: add a roadmap and make the chat easy to findca412e3
docs: sync the Latest changelog page with 26.1.0640936f
docs: note the dependency security work in 26.1.0Sourced from apprise's releases.
Release v1.13.0
What's Changed
This update clears out our backlog of resolved bugs and introduces a few new services. While it’s a standard maintenance release, we want to give a massive shoutout to our community. The level of support we've received for this update is truly incredible; there were more commits/PRs from you than there were from me and that has never happend before :slightly_smiling_face: . Your contributions are deeply appreciated! Seriously!
Note: ⚠️ This will be the last version of Apprise v1.x. Future releases will be under Apprise v2.x. This means: Developers, please make sure you pin your
projects.tomlorrequirements.txttoapprise >=1.0.0, <2.0.0. v2.x will be awesome, but it will introduce breaking changes your software may need to adapt to. I will still continue supporting the v1.x branch should security issues arise for at year or two, but eventually v2.x would be the way to go.:mega: New Notification Services:
- Added Pinglet Support by
@TheGlenn88in caronc/apprise#1680- Add Trigv notification support by
@hchouhanin caronc/apprise#1671- Added Pingram (formerly NotificationApi) by
@lipusalin caronc/apprise#1665:lady_beetle: Bugfixes
- Preserve x/y coordinate of 0 in dbus/glib url() (round-trip crash on x=0) by
@gaoflowin caronc/apprise#1663- Allow RFC 3986 path characters that are safe to leave unencoded by
@Sanjays2402in caronc/apprise#1673- small bugfix in splunk entity_id handling on url in caronc/apprise#1688
- Fix Microsoft Workflows CU-routed webhooks by
@Sanjays2402in caronc/apprise#1676- Return None from parse_url() on malformed authority content (#1693) by
@youdie006in caronc/apprise#1694- fix issue causing in memory email attachments to fail by
@kevinfeyrerin caronc/apprise#1696:bulb: Features
- Improved handling matrix message splitting in caronc/apprise#1687
- feat(bark): add AES-GCM encryption by
@IceCodeNewin caronc/apprise#1684- fix(docs): CLI file attachments feature by
@egvimoin caronc/apprise#1678- Support for Telegram rich message support in caronc/apprise#1690
:heart: Life-Cycle Support
- Fix grammar and tiny errors in README.md by
@notrudyyyin caronc/apprise#1674- docs: quote pip extras install examples by
@nyxst4ckin caronc/apprise#1679- Decomissioned legacy service NotificationApi by
@lipusalin caronc/apprise#1665- Fixed warnings emitted while running test suite in caronc/apprise#1689
- Proxy documentation added to man page in caronc/apprise#1691
- Updated github-action references to latest in caronc/apprise#1692
- Add Italian translation by
@albanobattistellain caronc/apprise#1670New Contributors
@gaoflowmade their first contribution in caronc/apprise#1663@TheGlenn88made their first contribution in caronc/apprise#1680@egvimomade their first contribution in caronc/apprise#1678@nyxst4ckmade their first contribution in caronc/apprise#1679@notrudyyymade their first contribution in caronc/apprise#1674@hchouhanmade their first contribution in caronc/apprise#1671@IceCodeNewmade their first contribution in caronc/apprise#1684@Sanjays2402made their first contribution in caronc/apprise#1673@lipusalmade their first contribution in caronc/apprise#1665@albanobattistellamade their first contribution in caronc/apprise#1670@youdie006made their first contribution in caronc/apprise#1694@kevinfeyrermade their first contribution in caronc/apprise#1696Installation
Apprise is available on PyPI through pip:
... (truncated)
cf17bc9
bumped version to v1.13.0c41f802
in-memory email attachments no longer fail (#1696)6ebddd3
Return None from parse_url() on malformed authority content (#1694)6b8cb13
Add Italian translation (#1670)468d26f
Updated github-action plugins to latest supported versions (#1692)73c8512
Support for Telegram rich message support (#1690)fac5056
fixed issue causing time based xmpp tests to randomly fail2c48a87
Proxy documentation added to man page (#1691)094073a
relaxed and improved on unit-tests time restrictionscc2dffb
Fixed warnings emitted while running test suite (#1689)Sourced from seleniumbase's releases.
4.52.1 - Fix timeout issue with executing scripts
Fix timeout issue with executing scripts
- Fix timeout issue with executing scripts in Selenium Mode --> (See the next commit where the fix was moved to a
finallyblock)- Improve the earlier commit that fixes the script timeout issue --> (A method that changed the default timeout wasn't resetting it back afterward) --> This resolves seleniumbase/SeleniumBase#4467
- Update examples --> (Updates some examples after changes were made on the site being tested)
What's Changed
- Fix timeout issue with executing scripts by
@mdmintzin seleniumbase/SeleniumBase#4468Full Changelog: https://github.com/seleniumbase/SeleniumBase/compare/v4.52.0...v4.52.1
4.52.0 - CDP Mode: Patch 129
CDP Mode: Patch 129
- Update CDP Mode
- Improve output from driver downloads
- Drop support for Python 3.9
- Refresh Python dependencies
- Add scraping examples
Resolutions:
- This resolves seleniumbase/SeleniumBase#4461
- This resolves seleniumbase/SeleniumBase#4462
- This resolves seleniumbase/SeleniumBase#4463
- This resolves seleniumbase/SeleniumBase#4464
- This resolves seleniumbase/SeleniumBase#4465
What's Changed
- CDP Mode: Patch 129 by
@mdmintzin seleniumbase/SeleniumBase#4466Full Changelog: https://github.com/seleniumbase/SeleniumBase/compare/v4.51.12...v4.52.0
c71edd5
Merge pull request #4468
from seleniumbase/fix-timeout-issue-with-executing-s...a5e37fd
Improve the earlier commit that fixes the script timeout issuecd7b894
Version 4.52.137ace07
Update examplese55bcc7
Fix timeout issue with executing scripts in Selenium modeb2207cb
Merge pull request #4466
from seleniumbase/cdp-mode-patch-1290be0f56
Version 4.52.044e9d85
Update the ReadMe99327cc
Add scraping examples0b7cc37
Refresh Python dependenciesSourced from prek's releases.
0.4.14
Release Notes
Released on 2026-08-17.
Enhancements
- Support check-yaml unsafe mode (#2546)
Performance
- Reuse allocations in common filters (#2548)
Bug fixes
- Accept non-finite floats in check-yaml (#2545)
- Allow comment-heavy YAML in check-yaml (#2554)
- Sanitize captured terminal output before replay (#2552)
Contributors
Install prek 0.4.14
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.14/prek-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.14/prek-installer.ps1 | iex"Install prebuilt binaries via Homebrew
brew install prekDownload prek 0.4.14
File Platform Checksum prek-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum prek-x86_64-apple-darwin.tar.gz Intel macOS checksum prek-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
... (truncated)
Sourced from prek's changelog.
0.4.14
Released on 2026-08-17.
Enhancements
- Support check-yaml unsafe mode (#2546)
Performance
- Reuse allocations in common filters (#2548)
Bug fixes
- Accept non-finite floats in check-yaml (#2545)
- Allow comment-heavy YAML in check-yaml (#2554)
- Sanitize captured terminal output before replay (#2552)
Contributors
432eeb0
Bump version to 0.4.14 (#2571)6b6d429
Update Rust crate ignore to v0.4.33 (#2564)27d0cf8
Update prek hooks (#2555)aaf407b
Update Rust crate aws-lc-rs to v1.18.0 (#2569)3ddddfd
Update Rust crate xml to v1.4.0 (#2570)fc90ec6
Update Rust crate similar to v3.1.2 (#2567)50e60d4
Update Rust crate thiserror to v2.0.20 (#2568)70a4c06
Update Rust crate liblzma to v0.4.8 (#2565)7b8dcaa
Update Rust crate globset to v0.4.20 (#2563)3e075d3
Update Rust crate clap_complete to v4.6.9 (#2562)Sourced from ruff's releases.
0.16.4
Release Notes
Released on 2026-08-20.
Preview features
- [
flake8-use-pathlib] Add autofix forPTH116(#26460)- [
refurb] Restrictdelete-full-sliceto lists (FURB131) (#27711)- [
refurb] SkipFURB101andFURB103when theopenargument is a file descriptor (#27643)Bug fixes
- Fix
InvalidInstructionon Windows CPUs that do not supportPOPCNT(#27803)- [
pyflakes] Emit semantic syntax errors in string type definitions asF722(#27835)- [
pylint] Allowos._exitimports inimport-private-name(PLC2701) (#27738)Rule changes
- [syntax-errors] Align mixed t-string/bytes error message with CPython 3.14 (#27766)
- [
ruff] Addctypes.LittleEndianStructureand related types to existing exception (RUF012) (#27753)- [syntax-errors] Detect duplicate keyword arguments (#17804)
- [syntax-errors] Detect parameters declared
nonlocal(#27628)Server
- Offer display-only fixes and mark safe fixes preferred (#27807)
- Support pull diagnostics for notebook cells (#27779)
Documentation
Other changes
- Fix s390x stacker assembly in release builds (#27776)
- Guarantee minimum stack size when parsing a module, standalone expression, and suites (#25464)
- Reduce configuration deserialization code size (#27924)
- Check packed AST index bounds (#27849)
Contributors
... (truncated)
Sourced from ruff's changelog.
0.16.4
Released on 2026-08-20.
Preview features
- [
flake8-use-pathlib] Add autofix forPTH116(#26460)- [
refurb] Restrictdelete-full-sliceto lists (FURB131) (#27711)- [
refurb] SkipFURB101andFURB103when theopenargument is a file descriptor (#27643)Bug fixes
- Fix
InvalidInstructionon Windows CPUs that do not supportPOPCNT(#27803)- [
pyflakes] Emit semantic syntax errors in string type definitions asF722(#27835)- [
pylint] Allowos._exitimports inimport-private-name(PLC2701) (#27738)Rule changes
- [syntax-errors] Align mixed t-string/bytes error message with CPython 3.14 (#27766)
- [
ruff] Addctypes.LittleEndianStructureand related types to existing exception (RUF012) (#27753)- [syntax-errors] Detect duplicate keyword arguments (#17804)
- [syntax-errors] Detect parameters declared
nonlocal(#27628)Server
- Offer display-only fixes and mark safe fixes preferred (#27807)
- Support pull diagnostics for notebook cells (#27779)
Documentation
Other changes
- Fix s390x stacker assembly in release builds (#27776)
- Guarantee minimum stack size when parsing a module, standalone expression, and suites (#25464)
- Reduce configuration deserialization code size (#27924)
- Check packed AST index bounds (#27849)
Contributors
... (truncated)
11c76bf
Bump 0.16.4 (#27937)d53c8c5
Isolate playground builds from deployment credentials (#27839)cab001e
Disable uv preview for releases and pre-commit hooks (#27939)f8d575f
[ty] Clarify writing guidance for human readers (#27912)ca45fae
Set --preview and --default-index for the
uv-lock hook (#27935)4827bf7
Export UV_DEFAULT_INDEX in release.sh (#27934)d1087a4
[ty] Handle assignment expressions in string annotations (#27921)680cce4
[ty] Optimize inherited recursive protocol comparisons (#27922)974d3cb
Upgrade ecosystem-analyzer and mypy_primer to the latest upstream pins
(#27932)b169b40
Install cargo tools locked (#27929)Sourced from docker/setup-buildx-action's releases.
v4.3.0
- Bump
@docker/actions-toolkitfrom 0.92.0 to 0.95.0 in docker/setup-buildx-action#595- Bump brace-expansion from 1.1.13 to 1.1.18 in docker/setup-buildx-action#600
- Bump js-yaml from 5.2.0 to 5.3.0 in docker/setup-buildx-action#585
- Bump postcss from 8.5.10 to 8.5.25 in docker/setup-buildx-action#598
- Bump undici from 6.27.0 to 6.28.0 in docker/setup-buildx-action#601
Full Changelog: https://github.com/docker/setup-buildx-action/compare/v4.2.0...v4.3.0
37fe631
Merge pull request #595
from docker/dependabot/npm_and_yarn/docker/actions-to...b5c4f91
[dependabot skip] chore: update generated content3e93b63
build(deps): bump @docker/actions-toolkit from 0.92.0 to
0.95.0e527031
Merge pull request #600
from docker/dependabot/npm_and_yarn/brace-expansion-1...c68814b
[dependabot skip] chore: update generated content3f891b0
build(deps): bump brace-expansion from 1.1.13 to 1.1.18787db26
Merge pull request #585
from docker/dependabot/npm_and_yarn/js-yaml-5.2.1f779368
[dependabot skip] chore: update generated content7d5e604
build(deps): bump js-yaml from 5.2.0 to 5.3.0292c2fb
Merge pull request #590
from docker/dependabot/github_actions/actions/setup-n...Sourced from astral-sh/setup-uv's releases.
v10.0.1 🌈 Tolerate transient manifest timeouts
Changes
Thank you
@arguile- for making this action more resilient.🐛 Bug fixes
🧰 Maintenance
- chore: update known checksums for 0.12.4 @github-actions[bot] (#1017)
📚 Documentation
- docs: update version references to v10.0.0 @github-actions[bot] (#1014)
v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features
Changes
Another breaking release, directly after v9.0.0 but we think the added security justifies that.
Extra security by default
If you use the default
enable-cache: autothis will now DISABLE THE CACHE to protect against cache poisoning for the following events:
pull_request_targetworkflow_runreleaseYou can read the full reasoning in astral-sh/setup-uv#984
version: latest-known- name: Install the latest version of uv known to setup-uv uses: astral-sh/setup-uv@v10.0.0 with: version: "latest-known"This will now install the latest version with a checksum that is known by this action. The known
uvchecksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.Read python version from
.tool-versions- name: Install uv based on the version defined in .tool-versions and also set python uses: astral-sh/setup-uv@v10.0.0 with: version-file: "pyproject.toml" </tr></table>
... (truncated)
20cfd1b
chore: update known checksums for 0.12.4 (#1017)d73a0ca
Tolerate transient manifest timeouts (#1016)ae3b92d
docs: update version references to v10.0.0 (#1014)ae62891
chore(deps): roll up Dependabot updates (#1013)f9cdb47
Reject paths in .tool-versions (#1007)4f6036f
Require pull requests for Dependabot rollups (#1005)8d6402c
chore(deps): roll up Dependabot updates (#1004)46f427b
Read Python version from .tool-versions (#996)8ed89c5
ci: pin Alpine container image (#995)8473c7f
chore(deps): roll up Dependabot updates (#994)Sourced from github/codeql-action/init's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #40704.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the
initAction instead of falling back to downloading the bundle before extracting it. #40614.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037- Update default CodeQL bundle version to 2.26.2. #4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023- The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
... (truncated)
ff2f1c6
Merge pull request #4093
from github/update-v4.37.7-be7a3dbb8951a133
Update changelog for v4.37.7be7a3db
Merge pull request #4087
from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334
Merge pull request #4086
from github/mbg/thread-action-state-to-codeqlb4d8a54
Rebuildab5db25
Bump the npm-minor group across 1 directory with 8 updates38055a3
Drop logger from databaseInitCluster in
interface1f87aed
Merge pull request #4085
from github/update-bundle/codeql-bundle-v2.26.3dc1b98a
Make logger available to getCodeQLForCmd6f0220e
Merge pull request #4084
from github/navntoft/bump-undiciSourced from github/codeql-action/autobuild's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #40704.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the
initAction instead of falling back to downloading the bundle before extracting it. #40614.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037- Update default CodeQL bundle version to 2.26.2. #4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023- The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
... (truncated)
ff2f1c6
Merge pull request #4093
from github/update-v4.37.7-be7a3dbb8951a133
Update changelog for v4.37.7be7a3db
Merge pull request #4087
from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334
Merge pull request #4086
from github/mbg/thread-action-state-to-codeqlb4d8a54
Rebuildab5db25
Bump the npm-minor group across 1 directory with 8 updates38055a3
Drop logger from databaseInitCluster in
interface1f87aed
Merge pull request #4085
from github/update-bundle/codeql-bundle-v2.26.3dc1b98a
Make logger available to getCodeQLForCmd6f0220e
Merge pull request #4084
from github/navntoft/bump-undiciSourced from github/codeql-action/analyze's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
- Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #40704.37.5 - 03 Aug 2026
- Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the
initAction instead of falling back to downloading the bundle before extracting it. #40614.37.4 - 29 Jul 2026
- This version of the CodeQL Action adds support for the
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037- Update default CodeQL bundle version to 2.26.2. #4051
4.37.3 - 22 Jul 2026
No user facing changes.
4.37.2 - 21 Jul 2026
- The new address format for the
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023- The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
... (truncated)
ff2f1c6
Merge pull request #4093
from github/update-v4.37.7-be7a3dbb8951a133
Update changelog for v4.37.7be7a3db
Merge pull request #4087
from github/dependabot/npm_and_yarn/npm-minor-0aa561...9310334
Merge pull request #4086
from github/mbg/thread-action-state-to-codeqlb4d8a54
Rebuildab5db25
Bump the npm-minor group across 1 directory with 8 updates38055a3
Drop logger from databaseInitCluster in
interface1f87aed
Merge pull request #4085
from github/update-bundle/codeql-bundle-v2.26.3dc1b98a
Make logger available to getCodeQLForCmd6f0220e
Merge pull request #4084
from github/navntoft/bump-undiciSourced from astral-sh/uv's releases.
0.12.5
Release Notes
Released on 2026-08-14.
Python
- Add CPython 3.10.21, 3.11.16, and 3.12.14 (#21138)
- Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#21134)
Enhancements
- Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#21130)
Preview features
- Allow
--indexand--default-indexto select configured package indexes by name with theindex-by-namepreview feature (#17455)- Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#21131)
- Fall back to logical file sizes when using
cache-physical-spaceon filesystems that do not support physical-space accounting (#21133)Bug fixes
- Resolve relative package index paths in PEP 723 scripts against the script directory (#21097)
Install uv 0.12.5
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.ps1 | iex"Download uv 0.12.5
File Platform Checksum uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum uv-x86_64-apple-darwin.tar.gz Intel macOS checksum uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum uv-i686-pc-windows-msvc.zip x86 Windows checksum uv-x86_64-pc-windows-msvc.zip x64 Windows checksum uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
... (truncated)
Sourced from astral-sh/uv's changelog.
0.12.5
Released on 2026-08-14.
Python
- Add CPython 3.10.21, 3.11.16, and 3.12.14 (#21138)
- Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#21134)
Enhancements
- Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#21130)
Preview features
- Allow
--indexand--default-indexto select configured package indexes by name with theindex-by-namepreview feature (#17455)- Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#21131)
- Fall back to logical file sizes when using
cache-physical-spaceon filesystems that do not support physical-space accounting (#21133)Bug fixes
- Resolve relative package index paths in PEP 723 scripts against the script directory (#21097)
0.12.4
Released on 2026-08-13.
Enhancements
- Prefer post-quantum key exchange and enable opt-in TLS diagnostics (#21054)
- Accept whitespace before versions in noncompliant wildcard comparisons such as
Requires-Python: >= 3.5.*(#21012)- Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content (#20944)
- Omit source-span carets from diagnostics for empty PEP 508 requirements (#21094)
Preview features
- Add
uv check --no-install-projectand respectUV_NO_INSTALL_PROJECTto install dependencies without building or installing the project (#21085)- Make the ty subprocess invoked by
uv checkhonor uv's color and progress settings, including quiet mode (#21086)Performance
- Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges (#20804)
- Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly (#21041)
Bug fixes
- Use windowed
pythonw.exelaunchers for virtual environments created from managed Python minor-version links (#19235)- Allow
uv lockto proceed when.venvis an unusable project environment (#21068)- Respect
fork-strategywhen ordering forks created fromenvironmentsor existing lockfileresolution-markers(#21000)- Preserve consecutive wildcard Python minor-version exclusions such as
!=3.11.*, !=3.12.*inuv.lock(#21045)
... (truncated)
210d1f6
Bump version to 0.12.5 (#21140)802a916
Sync latest Python releases: 3.10.21, 3.11.16, 3.12.14 (#21138)a6904bb
Order equal-priority Python installations by key (#21134)728a70d
Improve automated fixes for related bug manifestations (#21102)b82b038
Include hashes in cyclonedx exports (#21131)8011778
Simplify editable requirement errors and hints (#21130)dca33f5
Fall back to logical cache accounting on unsupported filesystems (#21133)3a76e49
Get rid of Lock::with_manifest, make
Lock::from_resolution take the manif...7e6caa4
Support referencing indexes by name via --index and
--default-index (#17455)298dda4
Fix relative indexes in PEP 723 scripts (#21097)Sourced from knip's releases.
Release 6.32.2
- Support
oxfmt.config.mts(#1933) (795900191dc75eec8d1e717b866bf57e1e2912cc) - thanks@joealden!- Support
oxlint.config.mts(#1934) (531e2dc7c1d8bf31babea0068c34391182ec2d50) - thanks@joealden!- Fix Supported
lint-stagedConfigs (#1935) (f9c755e414ed10baa4d01af8ddac6d04cb8d5617) - thanks@joealden!- Update dependencies (95f7c529f918dd9e1a84f92c68d064738977b825)
- Update sentry snapshot (ea7929fcbd6b323c8bdd9252ac57017feeb29ecf)