Releases: github/codeql-cli-binaries
v2.10.1
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
New features
- Improved error message from
codeql database analyze
when a query is missing@id
or@kind
query metadata.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
This release is compatible with the CodeQL language packs from github/codeql@codeql-cli/v2.10.1
.
(The Windows and all-platform release assets were updated on 2022-08-15 to correct missing digital signatures in the original release assets.)
v2.10.0
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
Breaking changes
- The
--format=stats
option ofcodeql generate log-summary
has been renamed to--format=overall
. It now produces a richer JSON object that, in addition to the previous statistics about the run (which can be found in thestats
property) also records the most expensive predicates in the evaluation run.
Potentially breaking changes
-
The
codeql resolve ml-model
command now requires one or more query specifications as command line arguments in order to determine the set of starting packs from which to initiate the resolution process. -
The
buildMetadata
inside of compiled CodeQL packs no longer contains acreationTime
property. -
The
codeql pack download
command, when used with the--dir
option, now downloads requested packs in directories corresponding to their version numbers.
New features
- You can now include diagnostic messages in the summary produced by the
--print-diagnostics-summary
option of thecodeql database interpret-results
andcodeql database analyze
commands by running these commands at high verbosity levels.
Bugs fixed
-
Fixed a bug where
codeql pack download
, when used with the--dir
option, would not download a pack that is in the global package cache. -
Fixed a bug where some versions of a CodeQL package could not be downloaded if there are more than 100 versions of this package in the package registry.
-
Fixed a bug where the
--also-match
option forcodeql resolve files
andcodeql database index-files
does not work with relative paths. -
Fixed a bug that caused
codeql query decompile
to ignore the--output
option when producing bytecode output (--kind=bytecode
), writing only tostdout
.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
(The Windows and all-platform release assets were updated on 2022-08-15 to correct missing digital signatures in the original release assets.)
v2.9.4
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
New features
- Users of CodeQL Packaging Beta can now optionally authenticate to Container registries on GitHub Enterprise Server (GHES) versions 3.6 and later using standard input instead of the
CODEQL_REGISTRIES_AUTH
environment variable. To authenticate via standard input, pass--registries-auth-stdin
. The value you provide will override the value of theCODEQL_REGISTRIES_AUTH
environment variable.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
(The Windows and all-platform release assets were updated on 2022-08-15 to correct missing digital signatures in the original release assets.)
v2.9.3
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
New features
- Users can now use CodeQL Packaging Beta to publish and download CodeQL packs on GitHub Enterprise Server (GHES) versions 3.6 and later.
Bugs Fixed
-
Fixed a bug where precompiled CodeQL packages in the CodeQL bundle were being recompiled if they were in a read-only directory.
-
Fixed a bug where new versions of the VS Code extension wouldn't run two queries in parallel against one database.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.9.2
- The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
Features removed
- The table printed by
codeql database analyze
to summarize the results of metric queries that were part of the analysis now reports a single row per metric name independently of the verbosity level of the command. Previously, at higher verbosity levels, this table would contain multiple rows for metric names with multiple values.
New features
-
The tables produced by
codeql database analyze
summarizing the results of any diagnostic and metric queries that were run now exclude the results of queries taggedtelemetry
. -
Uploading SARIF results using the
codeql github upload-results
command now has a timeout of 5 minutes. -
Downloading CodeQL packs using the
codeql pack download
,codeql pack install
and related commands now have a timeout of 5 minutes and will retry 3 times before failing. Similar behavior has been added to thecodeql pack publish
command. -
The
codeql generate log-summary
command will now print progress updates tostderr
.
Bugs fixed
- Fixed a bug that could make it unpredictable whether the QL compiler reports problems about query metadata tags, and thereby make
codeql test run
fail spuriously in some cases.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.9.1
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.9.0
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
New features
-
codeql database create
now supports the--[no-]-count-lines
option, which was previously only available withcodeql database init
. -
codeql resolve files
andcodeql database index-files
has a new--also-match
option, which allows users to specify glob patterns that are applied in conjunction with the existing--include
option.
New language features
- This release introduces experimental support for parameterized QL modules. This language feature is still subject to change and should not be used in production yet.
Bugs fixed
-
Fixed a bug that would prevent resolution of a query suite in a published CodeQL query pack that has a reference to the pack itself.
-
Fixed inaccurate documentation of what the
--include-extension
option tocodeql resolve files
andcodeql database index-files
does. The actual behavior is unchanged.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.8.5
-
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.30) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.30 instance, you need to create them with release 2.7.6.
-
There are no user-facing changes in this release.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.8.4
- The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.29) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.29 instance, you need to create them with release 2.6.3.
Bugs fixed
-
Fixed an error where running out of memory during query evaluation would cause
codeql
to exit with status 34 instead of the 99 that is documented for this condition. -
Fixed a bug in our handling of Clang's header maps, which caused missing files for Xcode-based projects on macOS (e.g. WebKit).
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.
v2.8.3
-
This release of CodeQL (and all future ones) will not include the CodeQL runner, which is now deprecated. For more information, and instructions on how to migrate to using the CodeQL CLI, see CodeQL runner deprecation.
-
The bundled extractors are updated to match the versions currently used on LGTM.com. These are newer than the last release (1.29) of LGTM Enterprise. If you plan to upload databases to an LGTM Enterprise 1.29 instance, you need to create them with release 2.6.3.
New features
- Executable binaries for Windows are now digitally signed by a GitHub certificate.
Other changes
- The evaluator logs produced by
--evaluator-log
now default to the maximum verbosity level and will therefore contain more information (and, accordingly, grow larger). The verbosity level can still be configured with--evaluator-log-level
. In particular,--evaluator-log-level=1
will restore the previous default behavior.
For more information about the changes included in this release, see the CodeQL CLI changelog.
You can download either the codeql-PLATFORM.zip
for your platform, or the generic codeql.zip
which contains binaries for all supported platforms. Please ignore the additional "source code" downloads below the .zip
artifacts.