Commit Graph

10316 Commits

Author SHA1 Message Date
Henry Mercer
e13c3dc834 Only clean up a toolcache on the workspace filesystem
Some runner images keep the toolcache on a different volume to the workspace, so deleting the tools there frees up disk space that the analysis cannot use, and costs a later step that wanted them in the toolcache a download. Windows runners are laid out this way, with the toolcache on `C:` and the workspace on `D:`.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 11:00:56 +01:00
Henry Mercer
1331773b9a Address Copilot review feedback
Run the cleanup even when the download will not be cached in the toolcache, since the toolcache shares a filesystem with the directory we extract to, so freeing it helps either way, and report an error other than the toolcache being absent as a failure rather than as an empty toolcache.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:26:09 +01:00
Henry Mercer
2681b03bd6 Add a changelog note
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:18:43 +01:00
Henry Mercer
a7a90f3ffb Enable toolcache cleanup in the multi-language PR check
The check installs the tools from a URL, so most versions in its matrix are downloaded rather than found in the toolcache, which is when the cleanup runs, and it then builds and analyses seven languages, so a bundle we damaged on the way in would show up.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:12:11 +01:00
Henry Mercer
4a0b22ec25 Delete unused CodeQL bundles from the toolcache before downloading
When we download a bundle the toolcache often already holds a different one that the job will not use, and on GitHub-hosted runners it shares a filesystem with the workspace, so it takes space away from the analysis. Empty the toolcache before downloading, which also frees space for the archive during extraction, and which is safe because getting as far as a download means the tools were not resolved from the toolcache. Skip this once a step has obtained the tools, since a later step may run a path it was given, and gate it on the runner being GitHub-hosted and on a feature flag that is off by default.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:12:10 +01:00
Henry Mercer
762a5ed7f7 Add a helper to delete the CodeQL tools from the toolcache
`deleteToolcacheBundles` removes `$RUNNER_TOOL_CACHE/CodeQL` and reports which versions were there. It refuses to follow a symlinked CodeQL directory so that it can only ever delete paths that are really inside the toolcache, and reports failures rather than throwing. Not called yet.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:12:10 +01:00
Henry Mercer
ceb85f25b5 Distinguish GitHub-hosted runners from ones that look hosted
`isHostedRunner` infers hostedness from the runner name and the toolcache path, so it also matches self-hosted runners that are configured to resemble hosted ones. Rename it to `looksLikeHostedRunner` so callers can see they are getting a heuristic, and add `isGitHubHostedRunner`, which reads the `RUNNER_ENVIRONMENT` value the Actions service reports. The existing callers keep the heuristic, so there is no behaviour change.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-04 10:12:09 +01:00
Michael B. Gale
5914b031b1 Merge pull request #4111 from github/dependabot/github_actions/dot-github/workflows/actions/setup-java-6.0.0
Bump actions/setup-java from 5.7.0 to 6.0.0 in /.github/workflows
2026-09-03 16:50:30 +00:00
Michael B. Gale
102499482f Merge pull request #4119 from github/dependabot/npm_and_yarn/npm-minor-21ac56865f
Bump the npm-minor group across 1 directory with 2 updates
2026-09-03 16:22:14 +00:00
Michael B. Gale
9401a335a3 Merge pull request #4118 from github/dependabot/npm_and_yarn/browserslist-4.28.8
Bump browserslist from 4.24.2 to 4.28.8
2026-09-03 16:21:07 +00:00
Michael B. Gale
3ee8a9398b Merge branch 'main' into dependabot/npm_and_yarn/browserslist-4.28.8 2026-09-03 17:03:16 +01:00
Michael B. Gale
25da1b1495 Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-21ac56865f 2026-09-03 17:00:00 +01:00
Michael B. Gale
9509fd0822 Merge pull request #4120 from github/dependabot/npm_and_yarn/eslint-plugin-jsdoc-64.2.1
Bump eslint-plugin-jsdoc from 62.9.0 to 64.2.1
2026-09-03 15:58:16 +00:00
Michael B. Gale
20ec60c2d9 Merge branch 'main' into dependabot/npm_and_yarn/eslint-plugin-jsdoc-64.2.1 2026-09-03 15:12:29 +01:00
Paolo Tranquilli
4cccb3aa86 Merge pull request #4072 from github/redsun82-linux-arm64-support
Add support for Linux Arm64 runners
2026-09-03 13:58:15 +00:00
github-actions[bot]
b724a86493 Rebuild 2026-09-02 17:56:48 +00:00
dependabot[bot]
2a03009e3f Bump eslint-plugin-jsdoc from 62.9.0 to 64.2.1
Bumps [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) from 62.9.0 to 64.2.1.
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v62.9.0...v64.2.1)

---
updated-dependencies:
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 17:55:01 +00:00
dependabot[bot]
da21771e2e Bump the npm-minor group across 1 directory with 2 updates
Bumps the npm-minor group with 2 updates in the / directory: [js-yaml](https://github.com/nodeca/js-yaml) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint).


Updates `js-yaml` from 5.3.0 to 5.4.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.3.0...5.4.0)

Updates `typescript-eslint` from 8.67.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: typescript-eslint
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 17:54:50 +00:00
dependabot[bot]
bb36f8049c Bump browserslist from 4.24.2 to 4.28.8
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.24.2 to 4.28.8.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](https://github.com/browserslist/browserslist/compare/4.24.2...4.28.8)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 13:55:34 +00:00
Michael B. Gale
276e2ce25d Merge pull request #4117 from github/mbg/deps/1sep
Update dependencies
2026-09-02 13:39:31 +00:00
Michael B. Gale
ccd5275aa4 Merge branch 'main' into dependabot/github_actions/dot-github/workflows/actions/setup-java-6.0.0 2026-09-02 14:36:24 +01:00
Mario Campos
a0c73122a6 Merge pull request #4096 from github/mario-campos/use-json-module
Use `json` module for JSON validation in `output-cache`
2026-09-01 15:17:48 +00:00
Michael B. Gale
50e244824e Update dependencies 2026-09-01 12:16:07 +01:00
Paolo Tranquilli
025009006c Address review comments
- Stub process.platform/arch in the supported-platform test and loop
  over all supported pairs (including linux/arm64) so it no longer
  depends on the host
- Run the default queries in the Linux Arm64 PR check so the databases
  are finalized end-to-end

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: fb7e2d12-6620-4a67-9c1c-4e82f4a5e8d9
2026-08-28 17:28:29 +02:00
Mario Campos
6f530319d8 Merge pull request #4113 from github/mario-campos/add-changenote-script
Create `changetool` script for validating change-notes
2026-08-27 18:09:46 +00:00
Mario Campos
f049ecb9ce Delete unused Node.js flag --experimental-test-module-mocks
Co-authored-by: Henry Mercer <henrymercer@github.com>
2026-08-27 11:22:56 -05:00
Henry Mercer
0963041ab4 Merge pull request #4090 from github/dependabot/npm_and_yarn/octokit/plugin-paginate-rest-15.0.0
Bump @octokit/plugin-paginate-rest from 14.0.0 to 15.0.0
2026-08-27 10:45:55 +00:00
github-actions[bot]
1a8ddd7325 Rebuild 2026-08-27 10:32:49 +00:00
Henry Mercer
abc579a511 Merge pull request #4112 from github/dependabot/npm_and_yarn/npm-minor-62a3d68ea9
Bump the npm-minor group across 1 directory with 2 updates
2026-08-27 10:28:51 +00:00
dependabot[bot]
4d1d53ec73 Bump @octokit/plugin-paginate-rest from 14.0.0 to 15.0.0
Bumps [@octokit/plugin-paginate-rest](https://github.com/octokit/plugin-paginate-rest.js) from 14.0.0 to 15.0.0.
- [Release notes](https://github.com/octokit/plugin-paginate-rest.js/releases)
- [Commits](https://github.com/octokit/plugin-paginate-rest.js/compare/v14.0.0...v15.0.0)

---
updated-dependencies:
- dependency-name: "@octokit/plugin-paginate-rest"
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-27 10:08:06 +00:00
Henry Mercer
6d4d5dfcd6 Merge pull request #4089 from github/dependabot/npm_and_yarn/octokit/types-17.0.0
Bump @octokit/types from 16.0.0 to 17.0.0
2026-08-27 09:37:27 +00:00
Paolo Tranquilli
7acc225a21 Merge pull request #4110 from github/redsun82-release-merge-instructions
Document merge-commit requirement for release PRs
2026-08-27 08:26:42 +00:00
Paolo Tranquilli
76ba03be44 Merge branch 'main' into redsun82-release-merge-instructions 2026-08-27 10:10:14 +02:00
Paolo Tranquilli
6441b26a49 Merge remote-tracking branch 'origin/main' into redsun82-linux-arm64-support 2026-08-27 10:09:22 +02:00
Mario Campos
cacb7b37ed Delete unused script/changetool NPM scripts 2026-08-26 23:39:11 -05:00
Mario Campos
e2cd31e32e Refactor tsconfig.json to extend base configuration and simplify options 2026-08-26 23:32:24 -05:00
Mario Campos
be555cf0a3 Extend scripts/changetool as a NPM workspace 2026-08-26 23:25:06 -05:00
Mario Campos
0447ab23b5 Enhance changenote validation to support nested bullet lists 2026-08-26 23:06:47 -05:00
Mario Campos
50ec5a5c18 Use Object.hasOwn instead of in operator
Apparently, the `in` operator will check inherited properties too.
2026-08-26 22:23:00 -05:00
Mario Campos
5aea817801 Replace Array.prototype.every() with for loop
`.every()` short-circuits on the first `false`
2026-08-26 22:20:25 -05:00
Mario Campos
580da893f6 Handle file errors as false 2026-08-26 22:15:34 -05:00
Mario Campos
426c10420b Create changetool script for validating change-notes 2026-08-26 17:13:40 -05:00
github-actions[bot]
dc5bc53050 Rebuild 2026-08-26 18:07:30 +00:00
github-actions[bot]
d75af13705 Rebuild 2026-08-26 18:03:17 +00:00
dependabot[bot]
0006c77502 Bump the npm-minor group across 1 directory with 2 updates
Bumps the npm-minor group with 2 updates in the / directory: [js-yaml](https://github.com/nodeca/js-yaml) and [uuid](https://github.com/uuidjs/uuid).


Updates `js-yaml` from 5.2.3 to 5.3.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.3...5.3.0)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](https://github.com/uuidjs/uuid/compare/v14.0.1...v14.0.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-26 18:01:20 +00:00
dependabot[bot]
ec1bd1999f Bump actions/setup-java from 5.7.0 to 6.0.0 in /.github/workflows
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](b6effb05e4...dd06d9cba3)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-26 17:59:42 +00:00
Henry Mercer
4d40c93072 Merge pull request #4108 from github/mergeback/v4.37.9-to-main-cdf488f5
Mergeback v4.37.9 refs/heads/releases/v4 into main
2026-08-26 17:19:52 +00:00
Henry Mercer
3e93618b99 Merge pull request #4105 from github/henrymercer/tools-download-telemetry
Improve CodeQL tools download time telemetry
2026-08-26 17:01:23 +00:00
Paolo Tranquilli
42c2ea9ef7 Document merge-commit requirement for release PRs
Release, mergeback, and backport PRs must be merged with a merge commit
so the branch linkage the release automation depends on is preserved
(the mergeback tags the release using the merge commit of the
"Merge main into releases/vN" PR, so squashing or rebasing breaks
tagging).

Add a path-scoped Copilot instructions file scoped to the files that
reliably change in these PRs (CHANGELOG.md, src/defaults.json,
lib/defaults.json, src/api-compatibility.json), and add an explicit note
to the Releasing runbook in CONTRIBUTING.md so the rule is enforced
regardless of who merges.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0dae6e42-7fc6-4fb1-b1ea-15dc17e402a2
2026-08-26 17:13:12 +02:00
github-actions[bot]
f37565646f Rebuild 2026-08-26 14:41:38 +00:00