Skip to content

Post-release preparation for codeql-cli-2.25.6#21912

Merged
henrymercer merged 7 commits into
mainfrom
post-release-prep/codeql-cli-2.25.6
May 29, 2026
Merged

Post-release preparation for codeql-cli-2.25.6#21912
henrymercer merged 7 commits into
mainfrom
post-release-prep/codeql-cli-2.25.6

Conversation

@codeql-ci
Copy link
Copy Markdown
Collaborator

This PR merges back all of the changes from the release of codeql-cli-2.25.6. And it bumps the version version strings in semmle-code in preparation for the next release of 2.25.7.

@henrymercer henrymercer marked this pull request as ready for review May 29, 2026 13:05
Copilot AI review requested due to automatic review settings May 29, 2026 13:05
@henrymercer henrymercer requested review from a team as code owners May 29, 2026 13:05
@henrymercer henrymercer requested review from a team as code owners May 29, 2026 13:05
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR performs post-release housekeeping for CodeQL CLI 2.25.6 by recording released change notes, updating changelogs, and advancing qlpack development versions for the next release cycle.

Changes:

  • Bumps qlpack versions and lastReleaseVersion metadata across language and shared packs.
  • Moves unreleased change notes into change-notes/released/* files and updates top-level changelogs.
  • Removes now-consumed unreleased change-note files.
Show a summary per file
File Description
swift/ql/src/qlpack.yml Bumps Swift queries dev version.
swift/ql/src/codeql-pack.release.yml Records Swift queries last release.
swift/ql/src/CHANGELOG.md Adds Swift queries 1.3.4 entry.
swift/ql/src/change-notes/released/1.3.4.md Adds released Swift queries notes.
swift/ql/lib/qlpack.yml Bumps Swift library dev version.
swift/ql/lib/codeql-pack.release.yml Records Swift library last release.
swift/ql/lib/CHANGELOG.md Adds Swift library 6.7.0 notes.
swift/ql/lib/change-notes/released/6.7.0.md Converts Swift library notes to released format.
swift/ql/lib/change-notes/2026-05-19-swift-6.3.2.md Removes consumed Swift unreleased note.
shared/yaml/qlpack.yml Bumps YAML pack dev version.
shared/yaml/codeql-pack.release.yml Records YAML last release.
shared/yaml/CHANGELOG.md Adds YAML changelog entry.
shared/yaml/change-notes/released/1.0.51.md Adds released YAML notes.
shared/xml/qlpack.yml Bumps XML pack dev version.
shared/xml/codeql-pack.release.yml Records XML last release.
shared/xml/CHANGELOG.md Adds XML changelog entry.
shared/xml/change-notes/released/1.0.51.md Adds released XML notes.
shared/util/qlpack.yml Bumps util pack dev version.
shared/util/codeql-pack.release.yml Records util last release.
shared/util/CHANGELOG.md Adds util changelog entry.
shared/util/change-notes/released/2.0.38.md Adds released util notes.
shared/typos/qlpack.yml Bumps typos pack dev version.
shared/typos/codeql-pack.release.yml Records typos last release.
shared/typos/CHANGELOG.md Adds typos changelog entry.
shared/typos/change-notes/released/1.0.51.md Adds released typos notes.
shared/typetracking/qlpack.yml Bumps typetracking dev version.
shared/typetracking/codeql-pack.release.yml Records typetracking last release.
shared/typetracking/CHANGELOG.md Adds typetracking changelog entry.
shared/typetracking/change-notes/released/2.0.35.md Adds released typetracking notes.
shared/typeinference/qlpack.yml Bumps typeinference dev version.
shared/typeinference/codeql-pack.release.yml Records typeinference last release.
shared/typeinference/CHANGELOG.md Adds typeinference changelog entry.
shared/typeinference/change-notes/released/0.0.32.md Adds released typeinference notes.
shared/typeflow/qlpack.yml Bumps typeflow dev version.
shared/typeflow/codeql-pack.release.yml Records typeflow last release.
shared/typeflow/CHANGELOG.md Adds typeflow changelog entry.
shared/typeflow/change-notes/released/1.0.51.md Adds released typeflow notes.
shared/tutorial/qlpack.yml Bumps tutorial dev version.
shared/tutorial/codeql-pack.release.yml Records tutorial last release.
shared/tutorial/CHANGELOG.md Adds tutorial changelog entry.
shared/tutorial/change-notes/released/1.0.51.md Adds released tutorial notes.
shared/threat-models/qlpack.yml Bumps threat-models dev version.
shared/threat-models/codeql-pack.release.yml Records threat-models last release.
shared/threat-models/CHANGELOG.md Adds threat-models changelog entry.
shared/threat-models/change-notes/released/1.0.51.md Adds released threat-models notes.
shared/ssa/qlpack.yml Bumps SSA dev version.
shared/ssa/codeql-pack.release.yml Records SSA last release.
shared/ssa/CHANGELOG.md Adds SSA changelog entry.
shared/ssa/change-notes/released/2.0.27.md Adds released SSA notes.
shared/regex/qlpack.yml Bumps regex dev version.
shared/regex/codeql-pack.release.yml Records regex last release.
shared/regex/CHANGELOG.md Adds regex changelog entry.
shared/regex/change-notes/released/1.0.51.md Adds released regex notes.
shared/rangeanalysis/qlpack.yml Bumps rangeanalysis dev version.
shared/rangeanalysis/codeql-pack.release.yml Records rangeanalysis last release.
shared/rangeanalysis/CHANGELOG.md Adds rangeanalysis changelog entry.
shared/rangeanalysis/change-notes/released/1.0.51.md Adds released rangeanalysis notes.
shared/quantum/qlpack.yml Bumps quantum dev version.
shared/quantum/codeql-pack.release.yml Records quantum last release.
shared/quantum/CHANGELOG.md Adds quantum changelog entry.
shared/quantum/change-notes/released/0.0.29.md Adds released quantum notes.
shared/mad/qlpack.yml Bumps MaD dev version.
shared/mad/codeql-pack.release.yml Records MaD last release.
shared/mad/CHANGELOG.md Adds MaD changelog entry.
shared/mad/change-notes/released/1.0.51.md Adds released MaD notes.
shared/dataflow/qlpack.yml Bumps dataflow dev version.
shared/dataflow/codeql-pack.release.yml Records dataflow last release.
shared/dataflow/CHANGELOG.md Adds dataflow changelog entry.
shared/dataflow/change-notes/released/2.1.7.md Adds released dataflow notes.
shared/controlflow/qlpack.yml Bumps controlflow dev version.
shared/controlflow/codeql-pack.release.yml Records controlflow last release.
shared/controlflow/CHANGELOG.md Adds controlflow changelog entry.
shared/controlflow/change-notes/released/2.0.35.md Adds released controlflow notes.
shared/concepts/qlpack.yml Bumps concepts dev version.
shared/concepts/codeql-pack.release.yml Records concepts last release.
shared/concepts/CHANGELOG.md Adds concepts changelog entry.
shared/concepts/change-notes/released/0.0.25.md Adds released concepts notes.
rust/ql/src/qlpack.yml Bumps Rust queries dev version.
rust/ql/src/codeql-pack.release.yml Records Rust queries last release.
rust/ql/src/CHANGELOG.md Adds Rust queries changelog entry.
rust/ql/src/change-notes/released/0.1.36.md Adds released Rust queries notes.
rust/ql/lib/qlpack.yml Bumps Rust library dev version.
rust/ql/lib/codeql-pack.release.yml Records Rust library last release.
rust/ql/lib/CHANGELOG.md Adds Rust library changelog entry.
rust/ql/lib/change-notes/released/0.2.15.md Converts Rust library notes to released format.
ruby/ql/src/qlpack.yml Bumps Ruby queries dev version.
ruby/ql/src/codeql-pack.release.yml Records Ruby queries last release.
ruby/ql/src/CHANGELOG.md Adds Ruby queries changelog entry.
ruby/ql/src/change-notes/released/1.6.4.md Adds released Ruby queries notes.
ruby/ql/lib/qlpack.yml Bumps Ruby library dev version.
ruby/ql/lib/codeql-pack.release.yml Records Ruby library last release.
ruby/ql/lib/CHANGELOG.md Adds Ruby library changelog entry.
ruby/ql/lib/change-notes/released/5.2.2.md Adds released Ruby library notes.
python/ql/src/qlpack.yml Bumps Python queries dev version.
python/ql/src/codeql-pack.release.yml Records Python queries last release.
python/ql/src/CHANGELOG.md Adds Python queries changelog entry.
python/ql/src/change-notes/released/1.8.4.md Adds released Python queries notes.
python/ql/lib/qlpack.yml Bumps Python library dev version.
python/ql/lib/codeql-pack.release.yml Records Python library last release.
python/ql/lib/CHANGELOG.md Adds Python library notes.
python/ql/lib/change-notes/released/7.1.2.md Converts Python library notes to released format.
misc/suite-helpers/qlpack.yml Bumps suite-helpers dev version.
misc/suite-helpers/codeql-pack.release.yml Records suite-helpers last release.
misc/suite-helpers/CHANGELOG.md Adds suite-helpers changelog entry.
misc/suite-helpers/change-notes/released/1.0.51.md Adds released suite-helpers notes.
javascript/ql/src/qlpack.yml Bumps JavaScript queries dev version.
javascript/ql/src/codeql-pack.release.yml Records JavaScript queries last release.
javascript/ql/src/CHANGELOG.md Adds JavaScript queries changelog entry.
javascript/ql/src/change-notes/released/2.3.11.md Adds released JavaScript queries notes.
javascript/ql/lib/qlpack.yml Bumps JavaScript library dev version.
javascript/ql/lib/codeql-pack.release.yml Records JavaScript library last release.
javascript/ql/lib/CHANGELOG.md Adds JavaScript library notes.
javascript/ql/lib/change-notes/released/2.7.2.md Converts JavaScript library notes to released format.
java/ql/src/qlpack.yml Bumps Java queries dev version.
java/ql/src/codeql-pack.release.yml Records Java queries last release.
java/ql/src/CHANGELOG.md Adds Java queries changelog entry.
java/ql/src/change-notes/released/1.11.4.md Adds released Java queries notes.
java/ql/lib/qlpack.yml Bumps Java library dev version.
java/ql/lib/codeql-pack.release.yml Records Java library last release.
java/ql/lib/CHANGELOG.md Adds Java library notes.
java/ql/lib/change-notes/released/9.1.2.md Converts Java library notes to released format.
go/ql/src/qlpack.yml Bumps Go queries dev version.
go/ql/src/codeql-pack.release.yml Records Go queries last release.
go/ql/src/CHANGELOG.md Adds Go queries changelog entry.
go/ql/src/change-notes/released/1.6.4.md Adds released Go queries notes.
go/ql/lib/qlpack.yml Bumps Go library dev version.
go/ql/lib/codeql-pack.release.yml Records Go library last release.
go/ql/lib/CHANGELOG.md Adds Go library changelog entry.
go/ql/lib/change-notes/released/7.1.2.md Adds released Go library notes.
go/ql/consistency-queries/qlpack.yml Bumps Go consistency queries dev version.
go/ql/consistency-queries/codeql-pack.release.yml Records Go consistency last release.
go/ql/consistency-queries/CHANGELOG.md Adds Go consistency changelog entry.
go/ql/consistency-queries/change-notes/released/1.0.51.md Adds released Go consistency notes.
csharp/ql/src/qlpack.yml Bumps C# queries dev version.
csharp/ql/src/codeql-pack.release.yml Records C# queries last release.
csharp/ql/src/CHANGELOG.md Adds C# queries changelog entry.
csharp/ql/src/change-notes/released/1.7.4.md Adds released C# queries notes.
csharp/ql/lib/qlpack.yml Bumps C# library dev version.
csharp/ql/lib/codeql-pack.release.yml Records C# library last release.
csharp/ql/lib/CHANGELOG.md Adds C# library notes.
csharp/ql/lib/change-notes/released/6.0.2.md Converts C# library notes to released format.
csharp/ql/lib/change-notes/2026-05-12-user-increment-decrement.md Removes consumed C# unreleased note.
csharp/ql/campaigns/Solorigate/src/qlpack.yml Bumps Solorigate queries dev version.
csharp/ql/campaigns/Solorigate/src/codeql-pack.release.yml Records Solorigate queries last release.
csharp/ql/campaigns/Solorigate/src/CHANGELOG.md Adds Solorigate queries changelog entry.
csharp/ql/campaigns/Solorigate/src/change-notes/released/1.7.68.md Adds released Solorigate queries notes.
csharp/ql/campaigns/Solorigate/lib/qlpack.yml Bumps Solorigate library dev version.
csharp/ql/campaigns/Solorigate/lib/codeql-pack.release.yml Records Solorigate library last release.
csharp/ql/campaigns/Solorigate/lib/CHANGELOG.md Adds Solorigate library changelog entry.
csharp/ql/campaigns/Solorigate/lib/change-notes/released/1.7.68.md Adds released Solorigate library notes.
cpp/ql/src/qlpack.yml Bumps C/C++ queries dev version.
cpp/ql/src/codeql-pack.release.yml Records C/C++ queries last release.
cpp/ql/src/CHANGELOG.md Adds C/C++ queries changelog entry.
cpp/ql/src/change-notes/released/1.6.4.md Adds released C/C++ queries notes.
cpp/ql/lib/qlpack.yml Bumps C/C++ library dev version.
cpp/ql/lib/codeql-pack.release.yml Records C/C++ library last release.
cpp/ql/lib/CHANGELOG.md Adds C/C++ library 10.2.0 notes.
cpp/ql/lib/change-notes/released/10.2.0.md Adds released C/C++ library notes.
cpp/ql/lib/change-notes/2026-05-21-generated-from.md Removes consumed C/C++ unreleased note.
cpp/ql/lib/change-notes/2026-05-18-alias-type.md Removes consumed C/C++ unreleased note.
cpp/ql/lib/change-notes/2026-05-16-alias-template.md Removes consumed C/C++ unreleased note.
cpp/ql/lib/change-notes/2026-05-15-secure-scanf.md Removes consumed C/C++ unreleased note.
actions/ql/src/qlpack.yml Bumps Actions queries dev version.
actions/ql/src/codeql-pack.release.yml Records Actions queries last release.
actions/ql/src/CHANGELOG.md Adds Actions queries 0.6.29 notes.
actions/ql/src/change-notes/released/0.6.29.md Adds released Actions queries notes.
actions/ql/src/change-notes/2026-05-14-further-iteration-untrusted-checkout-improvements-metadata.md Removes consumed Actions unreleased note.
actions/ql/src/change-notes/2026-05-14-further-iteration-untrusted-checkout-improvements-helpfile.md Removes consumed Actions unreleased note.
actions/ql/src/change-notes/2026-05-14-further-iteration-untrusted-checkout-improvements-alert.md Removes consumed Actions unreleased note.
actions/ql/src/change-notes/2026-05-12-sha256-pinned-actions.md Removes consumed Actions unreleased note.
actions/ql/src/change-notes/2026-05-05-untrusted-checkout-high.md Removes consumed Actions unreleased note.
actions/ql/lib/qlpack.yml Bumps Actions library dev version.
actions/ql/lib/codeql-pack.release.yml Records Actions library last release.
actions/ql/lib/CHANGELOG.md Adds Actions library notes.
actions/ql/lib/change-notes/released/0.4.37.md Converts Actions library notes to released format.

Copilot's findings

Comments suppressed due to low confidence (2)

python/ql/lib/change-notes/released/7.1.2.md:5

  • The phrase "less fewer positive results" is grammatically incorrect and appears to be missing "false"; this should say "fewer false positive results" to match the intended release-note wording.
    actions/ql/lib/change-notes/released/0.4.37.md:5
  • "include regexes" should be "including regexes" here because this clause is giving examples of the newly recognized checks.
  • Files reviewed: 175/175 changed files
  • Comments generated: 4


### Minor Analysis Improvements

* The sensitive data heuristics used to identify code that handles passwords and private data have been improved. Most of the changes permit more variations of established patterns, thereby finding more sensitive data. Queries that use the sensitive data library (for example `py/clear-text-logging-sensitive-data`) may find more correct results and less fewer positive results after these changes.

### Bug Fixes

* Adjusted (minor) help file descriptions for queries: `actions/untrusted-checkout/critical`, `actions/untrusted-checkout/high`, `actions/untrusted-checkout/medium`. Clarified wording on in minor point, added one more listed resource and added one more recommendation for things to check.

### Bug Fixes

* Adjusted (minor) help file descriptions for queries: `actions/untrusted-checkout/critical`, `actions/untrusted-checkout/high`, `actions/untrusted-checkout/medium`. Clarified wording on in minor point, added one more listed resource and added one more recommendation for things to check.

### Minor Analysis Improvements

* The GitHub Actions analysis now recognizes more Bash regex checks that restrict a value to alphanumeric characters, include regexes like `^[0-9a-zA-Z]{40}([0-9a-zA-Z]{24})?$` which check for a sha1 or sha256 hash. This may reduce false positive results where command output is validated with grouped or optional alphanumeric patterns before being used.
@henrymercer henrymercer merged commit a16f1c5 into main May 29, 2026
131 checks passed
@henrymercer henrymercer deleted the post-release-prep/codeql-cli-2.25.6 branch May 29, 2026 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants