Sourced from actions/setup-java's releases.
v5.6.0
What's Changed
- Backport to v5: Add Maven compiler problem matcher for javac diagnostics by
@brunoborgesin actions/setup-java#1087- feat: expose cache-primary-key output (#597) [v5 backport] by
@brunoborgesin actions/setup-java#1089- dist: Cover Tencent Kona JDK 25 (#1108) [v5 backport] by
@brunoborgesin actions/setup-java#1110- Backport #1111: Preserve Maven toolchains across repeated setup-java runs (#1099) by
@brunoborgesin actions/setup-java#1113- Backport #1097/#1098 to v5: cache Maven and Gradle wrapper distributions separately by
@brunoborgesin actions/setup-java#1122Full Changelog: https://github.com/actions/setup-java/compare/v5...v5.6.0
03ad4de
Backport #1097/#1098:
cache Maven and Gradle wrapper distributions separately...d229d2e
Backport #1111:
Preserve Maven toolchains across repeated setup-java runs (#1...bbf0f69
dist: Cover Tencent Kona JDK 25 (#1110)513edc4
feat: expose cache-primary-key output (#597)
[v5 backport] (#1089)62df799
Add Maven compiler problem matcher for javac diagnostics (#1087)176156a
chore: bump version to 5.6.0 for v5 release linebf7b8de
build: rebuild dist for backported changes (#1079,
#1083,
#1084)0173e6d
Infer distribution from asdf .tool-versions vendor prefix (#1084)f45cd82
Rename jdkFile input to jdk-file with deprecated alias (#1083)e2863ad
Map Zulu x86 architecture to i686 for Azul Metadata API (#1079)Sourced from fluxcd/flux2/action's releases.
v2.9.2
Highlights
Flux v2.9.2 is a patch release. The main fix addresses a regression introduced in v2.9.1 where a Kustomization with
openapi.pathpointing to a URL failed to reconcile withfailed to read OpenAPI schema. This release also corrects several CRD field descriptions that contained inaccurate or leaked content. Users are encouraged to upgrade for the best experience.ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
- Fix a regression where a Kustomization with
openapi.pathpointing to a URL failed to reconcile withfailed to read OpenAPI schema(kustomize-controller)- Fix the
HelmChartCRD description for.status.url, which pointed users atBucketStatus.Artifactinstead ofHelmChartStatus.Artifact(source-controller)- Fix the
ImageRepositoryCRD description for.status.observedExclusionList, which referred tospec.lastScanResultinstead ofstatus.lastScanResult(image-reflector-controller)- Fix the
ImageUpdateAutomationCRD description for.status.observedSourceRevision, which had a stray Go struct declaration leaking into it (image-automation-controller)Improvements:
- Update fluxcd/pkg dependencies
Components changelog
- source-controller v1.9.3
- kustomize-controller v1.9.3
- helm-controller v1.6.2
- notification-controller v1.9.2
- image-reflector-controller v1.2.3
- image-automation-controller v1.2.3
- source-watcher v2.2.2
CLI changelog
- Update fluxcd/pkg dependencies by
@fluxcdbotin fluxcd/flux2#5984- Update fluxcd/pkg dependencies by
@fluxcdbotin fluxcd/flux2#5990- Update toolkit components by
@fluxcdbotin fluxcd/flux2#5994Full Changelog: https://github.com/fluxcd/flux2/compare/v2.9.1...v2.9.2
6a650db
Merge pull request #5994
from fluxcd/update-components-release/v2.9.x00b9632
Update toolkit componentsdc8430c
Merge pull request #5990
from fluxcd/update-pkg-deps/release/v2.9.xc21de82
Update fluxcd/pkg dependenciesfa3c7b8
Merge pull request #5984
from fluxcd/update-pkg-deps/release/v2.9.xde86a51
Update fluxcd/pkg dependenciesSourced from github/codeql-action/upload-sarif's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
Sourced from github/codeql-action/upload-sarif's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from github/codeql-action/init's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
Sourced from github/codeql-action/init's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from github/codeql-action/analyze's releases.
v4.37.0
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973
Sourced from github/codeql-action/analyze's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
4.37.1 - 16 Jul 2026
- Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
- Update default CodeQL bundle version to 2.26.1. #4019
4.37.0 - 08 Jul 2026
- Update default CodeQL bundle version to 2.26.0. #3995
- In addition to the existing input format, the
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #39734.36.3 - 01 Jul 2026
No user facing changes.
4.36.2 - 04 Jun 2026
- Cache CodeQL CLI version information across Actions steps. #3943
- Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
- Update default CodeQL bundle version to 2.25.6. #3948
4.36.1 - 02 Jun 2026
No user facing changes.
4.36.0 - 22 May 2026
- Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #3894
- Add support for SHA-256 Git object IDs. #3893
- Update default CodeQL bundle version to 2.25.5. #3926
4.35.5 - 15 May 2026
- We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #3899
- For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #3791
- If multiple inputs are provided for the GitHub-internal
analysis-kindsinput, onlycode-scanningwill be enabled. Theanalysis-kindsinput is experimental, for GitHub-internal use only, and may change without notice at any time. #3892- Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #3880
4.35.4 - 07 May 2026
4.35.3 - 01 May 2026
... (truncated)
99df26d
Merge pull request #3996
from github/update-v4.37.0-c7c896d7131c2707
Add changenote for #397372df218
Update changelog for v4.37.0c7c896d
Merge pull request #3995
from github/update-bundle/codeql-bundle-v2.26.03f34ff0
Add changelog note43bec09
Update default bundle to codeql-bundle-v2.26.0f58f0d1
Merge pull request #3973
from github/mbg/repo-props/config-file-shorthands7dc37cb
Merge remote-tracking branch 'origin/main' into
mbg/repo-props/config-file-sh...8e22350
Thread ActionState to initConfig69c9e8c
Mark some status-report imports as type-only
to avoid circular dependenciesSourced from actions/stale's releases.
v10.4.0
What's Changed
Bug Fix
- Fixed
only-issue-typesvalidation by@trueberrylessin actions/stale#1338Dependency Updates
- Bump undici to 6.27.0 via override, clean up stale license files, and version to 10.4.0. by
@dependabotin actions/stale#1342New Contributors
@trueberrylessmade their first contribution in actions/stale#1338Full Changelog: https://github.com/actions/stale/compare/v10.3.0...v10.4.0
1e223db
Bump undici to 6.27.0 via override, clean up stale license files, and
version...9461cb1
fix: only-issue-types does not affect PRs (#1338)