Skip to content

chore: bump pinned CodeQL CLI to v2.26.1 and release v0.7.0#188

Open
security-lab-bot[bot] wants to merge 2 commits into
mainfrom
chore/update-codeql-cli-2.26.1
Open

chore: bump pinned CodeQL CLI to v2.26.1 and release v0.7.0#188
security-lab-bot[bot] wants to merge 2 commits into
mainfrom
chore/update-codeql-cli-2.26.1

Conversation

@security-lab-bot

Copy link
Copy Markdown
Contributor

Automated CLI version bump, requested via the "Update CodeQL CLI Version"
workflow (workflow_dispatch, codeql_version: 2.26.1, release_bump: minor).

This PR:

  • Updates .codeqlversion to 2.26.1.

  • Pins every codeql/<lang>-all / codeql/<lang>-queries dependency across all
    qlpack.yml files to the exact version shipped in the official CodeQL Bundle
    for this CLI release (see .github/scripts/pin-codeql-library-versions.sh) -
    this keeps codeql pack upgrade from jumping those libraries to
    registry-latest instead of the version this CLI actually ships/tests against.

  • Runs codeql pack upgrade <dir> for every pack directory to refresh its
    codeql-pack.lock.yml against the new CLI and pinned library versions.

  • Also bumps the repo release version (minor, via the same
    patch-release-me step update-release.yml uses) to 0.7.0,
    propagating it to every pack's own version: field, configs/*.yml
    references, and cross-pack -libs pins.

Merging this PR triggers the real batch publish - publish.yml's
auto-trigger fires on any push to main that changes .release.yml, which this
PR does. No separate "CodeQL Update Release" run is needed. That run's summary
job will create the matching GitHub Release as a full release
(release_prerelease: false).

Remaining steps (see CONTRIBUTING.md's "Updating the pinned CodeQL CLI/library
version" section):

  • Check CI on this PR - fix any compilation/test errors caused by upstream
    API changes. This is usually the hardest part; consider delegating it to a
    Copilot coding agent session pointed at this PR/branch.
  • Review and merge - this alone will trigger the real batch publish.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Bumps the repository’s pinned CodeQL CLI to 2.26.1 and performs a coordinated minor release bump to v0.7.0, updating per-language pack versions, CodeQL standard library pins, and refreshing codeql-pack.lock.yml files to match the new CLI/bundle.

Changes:

  • Update the pinned CodeQL CLI version (.codeqlversion) to 2.26.1.
  • Bump repo + pack versions to 0.7.0 (propagated across language packs).
  • Refresh CodeQL pack dependency pins and regenerated lockfiles across multiple languages (Ruby, Python, JavaScript, Java, Go, C#, C++).
Show a summary per file
File Description
.codeqlversion Bump pinned CodeQL CLI version to 2.26.1.
.release.yml Bump repo release version to 0.7.0.
ruby/test/qlpack.yml Update Ruby test pack’s CodeQL dependency pins.
ruby/test/codeql-pack.lock.yml Refresh Ruby test pack lockfile for new CLI/deps.
ruby/src/qlpack.yml Bump Ruby queries pack version and CodeQL dependency pin.
ruby/src/codeql-pack.lock.yml Refresh Ruby queries pack lockfile for new CLI/deps.
ruby/lib/qlpack.yml Bump Ruby libs pack version and CodeQL dependency pin.
ruby/lib/codeql-pack.lock.yml Refresh Ruby libs pack lockfile for new CLI/deps.
python/test/qlpack.yml Update Python test pack’s CodeQL dependency pins.
python/test/codeql-pack.lock.yml Refresh Python test pack lockfile for new CLI/deps.
python/src/qlpack.yml Bump Python queries pack version and CodeQL dependency pin.
python/src/codeql-pack.lock.yml Refresh Python queries pack lockfile for new CLI/deps.
python/lib/qlpack.yml Bump Python libs pack version and CodeQL dependency pin.
python/lib/codeql-pack.lock.yml Refresh Python libs pack lockfile for new CLI/deps.
python/ext/qlpack.yml Bump Python extensions pack version and extension target pin.
javascript/test/qlpack.yml Update JavaScript test pack’s CodeQL dependency pin.
javascript/test/codeql-pack.lock.yml Refresh JavaScript test pack lockfile for new CLI/deps.
javascript/src/qlpack.yml Bump JavaScript queries pack version and CodeQL dependency pin.
javascript/src/codeql-pack.lock.yml Refresh JavaScript queries pack lockfile for new CLI/deps.
javascript/lib/qlpack.yml Bump JavaScript libs pack version and CodeQL dependency pin.
javascript/lib/codeql-pack.lock.yml Refresh JavaScript libs pack lockfile for new CLI/deps.
java/test/qlpack.yml Update Java test pack’s CodeQL dependency pin.
java/test/codeql-pack.lock.yml Refresh Java test pack lockfile for new CLI/deps.
java/src/qlpack.yml Bump Java queries pack version and CodeQL dependency pin.
java/src/codeql-pack.lock.yml Refresh Java queries pack lockfile for new CLI/deps.
java/lib/qlpack.yml Bump Java libs pack version and CodeQL dependency pin.
java/lib/codeql-pack.lock.yml Refresh Java libs pack lockfile for new CLI/deps.
java/ext/qlpack.yml Bump Java extensions pack version and extension target pin.
java/ext-library-sources/qlpack.yml Bump Java library-sources pack version and extension target pin.
go/test/qlpack.yml Update Go test pack’s CodeQL dependency pin.
go/test/codeql-pack.lock.yml Refresh Go test pack lockfile for new CLI/deps.
go/src/qlpack.yml Bump Go queries pack version and CodeQL dependency pin.
go/src/codeql-pack.lock.yml Refresh Go queries pack lockfile for new CLI/deps.
go/lib/qlpack.yml Bump Go libs pack version and CodeQL dependency pin.
go/lib/codeql-pack.lock.yml Refresh Go libs pack lockfile for new CLI/deps.
go/ext/qlpack.yml Bump Go extensions pack version and extension target pin.
csharp/test/qlpack.yml Update C# test pack’s CodeQL dependency pins.
csharp/test/codeql-pack.lock.yml Refresh C# test pack lockfile for new CLI/deps.
csharp/src/qlpack.yml Bump C# queries pack version and CodeQL dependency pins.
csharp/src/codeql-pack.lock.yml Refresh C# queries pack lockfile for new CLI/deps.
csharp/lib/qlpack.yml Bump C# libs pack version and CodeQL dependency pin.
csharp/lib/codeql-pack.lock.yml Refresh C# libs pack lockfile for new CLI/deps.
csharp/ext/qlpack.yml Bump C# extensions pack version and extension target pin.
csharp/ext-library-sources/qlpack.yml Bump C# library-sources pack version and extension target pin.
cpp/test/qlpack.yml Update C++ test pack’s CodeQL dependency pins.
cpp/test/codeql-pack.lock.yml Refresh C++ test pack lockfile for new CLI/deps.
cpp/src/qlpack.yml Bump C++ queries pack version and CodeQL dependency pins.
cpp/src/codeql-pack.lock.yml Refresh C++ queries pack lockfile for new CLI/deps.
cpp/lib/qlpack.yml Bump C++ libs pack version and CodeQL dependency pin.
cpp/lib/codeql-pack.lock.yml Refresh C++ libs pack lockfile for new CLI/deps.

Review details

  • Files reviewed: 50/50 changed files
  • Comments generated: 0
  • Review effort level: Low

@felickz

felickz commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>

Copilot AI commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

@copilot

Fix ci https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/actions/runs/29958163332/job/89052377731?pr=188
...

Fixed in 8402d92. The only CI failure was compile-and-test (python), caused by two pre-existing deprecated getAFlowNode() calls in python/lib/ghsl/DefaultPasswordDB.qll and python/lib/ghsl/InsecurelyStoredPassword.qll. They weren't newly deprecated in 2.26 (not in that changelog), but pr-compile.sh runs a full --warnings=error recompile whenever a PR touches lib/, which this PR's python/lib/qlpack.yml bump does, so they surfaced here for the first time. Replaced both with ControlFlowNode.getNode() per the predicate's own deprecation guidance. Verified locally with the pinned 2.26.1 CLI: codeql query compile --warnings=error on python/ now exits clean, and all 15 python codeql test run tests pass, including the two directly affected.

Copilot AI requested a review from felickz July 23, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants