Skip to content

.github/workflows/codescan.yml: use codeql-action v3 - #4640

Merged
tdonohue merged 1 commit into
DSpace:mainfrom
alanorth:codeql-action-v3
Aug 20, 2025
Merged

.github/workflows/codescan.yml: use codeql-action v3#4640
tdonohue merged 1 commit into
DSpace:mainfrom
alanorth:codeql-action-v3

Conversation

@alanorth

@alanorth alanorth commented Aug 17, 2025

Copy link
Copy Markdown
Contributor

Description

CodeQL Action v2 was deprecated in January, 2024 (!) after the release of v3. It has been showing warnings in the CI logs since January, 2025.

See: https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/

Instructions for Reviewers

Please add a more detailed description of the changes made by your PR. At a minimum, providing a bulleted list of changes in your PR is helpful to reviewers.

List of changes in this PR:

  • First, update codeql-action references from v2 to v3

Include guidance for how to test or review your PR. This may include: steps to reproduce a bug, screenshots or description of a new feature, or reasons behind specific changes.

Make sure code scanning task in CI works.

Checklist

This checklist provides a reminder of what we are going to look for when reviewing your PR. You do not need to complete this checklist prior creating your PR (draft PRs are always welcome).
However, reviewers may request that you complete any actions in this list if you have not done so. If you are unsure about an item in the checklist, don't hesitate to ask. We're here to help!

  • My PR is created against the main branch of code (unless it is a backport or is fixing an issue specific to an older branch).
  • My PR is small in size (e.g. less than 1,000 lines of code, not including comments & specs/tests), or I have provided reasons as to why that's not possible.
  • My PR passes ESLint validation using npm run lint
  • My PR doesn't introduce circular dependencies (verified via npm run check-circ-deps)
  • My PR includes TypeDoc comments for all new (or modified) public methods and classes. It also includes TypeDoc for large or complex private methods.
  • My PR passes all specs/tests and includes new/updated specs or tests based on the Code Testing Guide.
  • My PR aligns with Accessibility guidelines if it makes changes to the user interface.
  • My PR uses i18n (internationalization) keys instead of hardcoded English text, to allow for translations.
  • My PR includes details on how to test it. I've provided clear instructions to reviewers on how to successfully test this fix or feature.
  • If my PR includes new libraries/dependencies (in package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation.
  • If my PR includes new features or configurations, I've provided basic technical documentation in the PR itself.
  • If my PR fixes an issue ticket, I've linked them together.

@alanorth alanorth added this to the 10.0 milestone Aug 17, 2025
@alanorth alanorth added dependencies Pull requests that update a dependency file 1 APPROVAL pull request only requires a single approval to merge port to dspace-7_x port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release labels Aug 17, 2025
@tdonohue
tdonohue self-requested a review August 20, 2025 21:07

@tdonohue tdonohue left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Thanks @alanorth ! Looks good to me.

@github-project-automation github-project-automation Bot moved this to 👍 Reviewer Approved in DSpace 10.0 Release Aug 20, 2025
@tdonohue
tdonohue merged commit 59e477a into DSpace:main Aug 20, 2025
13 checks passed
@github-project-automation github-project-automation Bot moved this from 👍 Reviewer Approved to ✅ Done in DSpace 10.0 Release Aug 20, 2025
@dspace-bot

Copy link
Copy Markdown
Contributor

Successfully created backport PR for dspace-7_x:

@dspace-bot

Copy link
Copy Markdown
Contributor

Successfully created backport PR for dspace-8_x:

@dspace-bot

Copy link
Copy Markdown
Contributor

Successfully created backport PR for dspace-9_x:

@tdonohue tdonohue removed port to dspace-7_x port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release labels Aug 20, 2025
4science-it pushed a commit to 4Science/dspace-angular that referenced this pull request Jul 1, 2026
Task/dspace cris 2025 02 x/DSC-2887

Approved-by: Andrea Barbasso
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 APPROVAL pull request only requires a single approval to merge dependencies Pull requests that update a dependency file

Projects

No open projects
Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

3 participants