Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 1, 2025

Bumps github/codeql-action from 4.31.4 to 4.31.5.

Release notes

Sourced from github/codeql-action's releases.

v4.31.5

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #3321

See the full CHANGELOG.md for more information.

Changelog

Sourced from github/codeql-action's changelog.

4.31.5 - 24 Nov 2025

  • Update default CodeQL bundle version to 2.23.6. #3321
Commits
  • fdbfb4d Merge pull request #3322 from github/update-v4.31.5-ec2ee575c
  • 81f6d64 Update changelog for v4.31.5
  • ec2ee57 Merge pull request #3321 from github/update-bundle/codeql-bundle-v2.23.6
  • ecc8787 Add changelog note
  • 1d2a238 Update default bundle to codeql-bundle-v2.23.6
  • ce729e4 Merge pull request #3315 from github/henrymercer/dead-code-elimination
  • ac359aa Add return type
  • 112cd07 Merge branch 'main' into henrymercer/dead-code-elimination
  • 0b43179 Merge pull request #3306 from github/dependabot/npm_and_yarn/types/sinon-21.0.0
  • e818008 Merge pull request #3305 from github/dependabot/npm_and_yarn/eslint/compat-2.0.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.31.4 to 4.31.5.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.31.4...v4.31.5)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.31.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Dec 1, 2025
@dependabot dependabot bot requested a review from a team as a code owner December 1, 2025 08:50
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Dec 1, 2025
@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/alpine:3.22.2 (alpine 3.22.2)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/traefik_openssl:v3 (alpine 3.22.2)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/nginx:1.29.3 (alpine 3.22.2)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/photon:latest (alpine 3.22.2)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.2 (ubuntu 24.04)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.5 (ubuntu 24.04)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.1 (ubuntu 24.04)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.4 (ubuntu 24.04)

No vulnerabilities found.

@github-actions
Copy link

github-actions bot commented Dec 1, 2025

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.3 (ubuntu 24.04)

No vulnerabilities found.

@sjinks sjinks self-assigned this Dec 3, 2025
@sjinks sjinks merged commit 66954d7 into master Dec 3, 2025
25 checks passed
@sjinks sjinks deleted the dependabot/github_actions/dot-github/actions/build-docker-image/github/codeql-action-4.31.5 branch December 3, 2025 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants