{{ message }}
Post-release preparation for codeql-cli-2.25.6#21912
Merged
Merged
Conversation
Release preparation for version 2.25.6
Revert "Release preparation for version 2.25.6"
Release preparation for version 2.25.6
henrymercer
approved these changes
May 29, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
This PR performs post-release housekeeping for CodeQL CLI 2.25.6 by recording released change notes, updating changelogs, and advancing qlpack development versions for the next release cycle.
Changes:
- Bumps qlpack versions and
lastReleaseVersionmetadata across language and shared packs. - Moves unreleased change notes into
change-notes/released/*files and updates top-level changelogs. - Removes now-consumed unreleased change-note files.
Show a summary per file
Copilot's findings
Comments suppressed due to low confidence (2)
python/ql/lib/change-notes/released/7.1.2.md:5
- The phrase "less fewer positive results" is grammatically incorrect and appears to be missing "false"; this should say "fewer false positive results" to match the intended release-note wording.
actions/ql/lib/change-notes/released/0.4.37.md:5 - "include regexes" should be "including regexes" here because this clause is giving examples of the newly recognized checks.
- Files reviewed: 175/175 changed files
- Comments generated: 4
|
|
||
| ### Minor Analysis Improvements | ||
|
|
||
| * The sensitive data heuristics used to identify code that handles passwords and private data have been improved. Most of the changes permit more variations of established patterns, thereby finding more sensitive data. Queries that use the sensitive data library (for example `py/clear-text-logging-sensitive-data`) may find more correct results and less fewer positive results after these changes. |
|
|
||
| ### Bug Fixes | ||
|
|
||
| * Adjusted (minor) help file descriptions for queries: `actions/untrusted-checkout/critical`, `actions/untrusted-checkout/high`, `actions/untrusted-checkout/medium`. Clarified wording on in minor point, added one more listed resource and added one more recommendation for things to check. |
|
|
||
| ### Bug Fixes | ||
|
|
||
| * Adjusted (minor) help file descriptions for queries: `actions/untrusted-checkout/critical`, `actions/untrusted-checkout/high`, `actions/untrusted-checkout/medium`. Clarified wording on in minor point, added one more listed resource and added one more recommendation for things to check. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This PR merges back all of the changes from the release of codeql-cli-2.25.6. And it bumps the version version strings in semmle-code in preparation for the next release of 2.25.7.