)]}'
{
  "log": [
    {
      "commit": "bfd26b275278028d5d726d5bed02ce438cebda85",
      "tree": "7d92915a47aa15c5d98db6ce224e4dab5389f115",
      "parents": [
        "e0df197dc7a25d4428a6f32a2dd6e5dbd525378d"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Sep 21 21:09:09 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 21 21:09:09 2026"
      },
      "message": "[GH Actions] Rebuild for all unlabeled actions (#6900)\n\nWe will now rerun the GH actions for every unlabel event. Previously,\nremoving a label other than \u0027kokoro:run\u0027 caused the action to be\nconsidered \"skipped\". This blocked merging because some of those actions\nare required, and GitHub does not fall back to a previous successful\nrun.\n\nWe continue running the actions on \"unlabeled\" so that autoroll can\nrun the tests when the Kokoro bot starts.\n\nI do not believe this will lead to excessive usage because we generally\ndo not use labels for GitHub Actions. This issue was found because a new\nKokoro label was recently added: `kokoro:rebuild`."
    },
    {
      "commit": "e0df197dc7a25d4428a6f32a2dd6e5dbd525378d",
      "tree": "c93d261400e48269890d891becfd9bfcee505537",
      "parents": [
        "2907cbbc344b5f550567d8c11b7e872000352aec"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Sep 21 16:13:36 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 21 16:13:36 2026"
      },
      "message": "[Kokoro] Use git 2.53 on linux (#6891)\n\nThe GN builds fail because depot tools uses a feature that has a bug in\ngit 2.43 (the default on ubuntu 24.04). To avoid this, we need to use a\nlater version of git."
    },
    {
      "commit": "2907cbbc344b5f550567d8c11b7e872000352aec",
      "tree": "8e290fdd70472d2ccd5425970c2e9402bb1b9a9c",
      "parents": [
        "af4f54c8d4deb15e6aa532c5c1a56fffbb6daaea"
      ],
      "author": {
        "name": "Hernan Ponce de Leon",
        "email": "zeta96@gmail.com",
        "time": "Mon Sep 21 15:54:51 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 21 15:54:51 2026"
      },
      "message": "spirv-fuzz: Restrict atomic loads and stores to scalar types (#6889)\n\nEnsure that OpAtomicLoad and OpAtomicStore are only generated for\npointers to integer or floating-point scalar types.\n\nFixes #6888.\n\nAssisted-by: Codex"
    },
    {
      "commit": "af4f54c8d4deb15e6aa532c5c1a56fffbb6daaea",
      "tree": "a684d323e5152aad90ed8ad23c983973ec916bde",
      "parents": [
        "ba9a9e32160e2500ce1e48cc563a8fedaf596e6e"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Sep 21 13:42:00 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 21 13:42:00 2026"
      },
      "message": "roll deps (#6892)\n\n- **Roll external/googletest/ f840327b0..4267679b6 (1 commit)**\n- **Roll external/abseil_cpp/ 3a80a7794..73d268830 (1 commit)**\n- **Roll external/spirv-headers/ 04fd3caa1..2f88364fb (1 commit)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "ba9a9e32160e2500ce1e48cc563a8fedaf596e6e",
      "tree": "9efb82f9bddb172231c18b5f4ecaa75ba2f862ab",
      "parents": [
        "8a75baff9c9ebe40f36b06a04075c33d92452204"
      ],
      "author": {
        "name": "Hernan Ponce de Leon",
        "email": "zeta96@gmail.com",
        "time": "Fri Sep 18 16:12:55 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 18 16:12:55 2026"
      },
      "message": "spirv-fuzz: Handle composites without static index bounds (#6890)\n\nFuzzerPassAddAccessChains requires a static bound to generate valid\nindices. Check this through fuzzerutil before descending into a\ncomposite, avoiding an assertion for runtime arrays.\n\nFixes #6886\nAssisted-by: Codex"
    },
    {
      "commit": "8a75baff9c9ebe40f36b06a04075c33d92452204",
      "tree": "5d7f138f4b5adfdf36a8e47f0793ad13cefa467a",
      "parents": [
        "50e18d46f4940829aea89f41babe324e65ab70de"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Sep 18 01:58:23 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 18 01:58:23 2026"
      },
      "message": "build(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.38.0 in the github-actions group across 1 directory (#6845)\n\nBumps the github-actions group with 1 update in the / directory:\n[github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\nUpdates `github/codeql-action/upload-sarif` from 4.37.6 to 4.38.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.38.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused\nCodeQL bundles from the toolcache before downloading a different bundle,\nwhich frees up disk space for the analysis. We expect to roll this\nchange out to everyone in September. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible\nwith Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e\nCodeQL bundle when available. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.37.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.37.8\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003ev4.37.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.38.0 - 09 Sept 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOn GitHub-hosted runners, the CodeQL Action now deletes unused\nCodeQL bundles from the toolcache before downloading a different bundle,\nwhich frees up disk space for the analysis. We expect to roll this\nchange out to everyone in September. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4124\"\u003e#4124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action now supports CodeQL releases that are compatible\nwith Linux Arm64 and downloads the native \u003ccode\u003elinux-arm64\u003c/code\u003e\nCodeQL bundle when available. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4072\"\u003e#4072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0\"\u003e2.27.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4129\"\u003e#4129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.9 - 26 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4\"\u003e2.26.4\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4106\"\u003e#4106\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.8 - 21 Aug 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.7 - 13 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3\"\u003e2.26.3\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4085\"\u003e#4085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format\nthat was introduced in CodeQL Action 4.37.0 / 3.37.0 to\n\u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested\npath that is used elsewhere. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of\nthe CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead\nof falling back to downloading the bundle before extracting it. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the\n\u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to\nbe specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository\nproperty\u003c/a\u003e. This feature will gradually be rolled out following the\nrelease of this version. Once rolled out, this allows for the CodeQL CLI\nversion that is used in GitHub-managed workflows, such as Default Setup,\nto be set to a custom value. For example, customers who run into issues\nwith rate limits when a new CodeQL CLI version is released can set the\nvalue to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version\nthat is available in the runner toolcache. For Advanced Setup workflows,\nthe value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition\nalways takes precedence unless the value of the repository property\nstarts with \u003ccode\u003e!\u003c/code\u003e. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that\nwas introduced in CodeQL Action 4.37.0 is now enabled by default. In\naddition to the format described there, the \u003ccode\u003eremote\u003d\u003c/code\u003e prefix\ncan now be used to explicitly indicate that the input refers to a remote\nfile. All previous input formats continue to be accepted as well. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action can now make use of \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003econfigured\nprivate registries\u003c/a\u003e in Default Setup to retrieve CodeQL configuration\nfiles from remote repositories that require authentication. This will\nallow customers to store their CodeQL configuration in a single\nrepository that can then be referenced by Default Setup workflows in\nother repositories. We expect to roll this and other, related changes\nout to everyone in July. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4007\"\u003e#4007\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.1 - 16 Jul 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003e\u003ccode\u003eb96794f\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4131\"\u003e#4131\u003c/a\u003e\nfrom github/update-v4.38.0-7e08580a9\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef\"\u003e\u003ccode\u003e02d5093\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.38.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6\"\u003e\u003ccode\u003e7e08580\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4130\"\u003e#4130\u003c/a\u003e\nfrom github/henrymercer/workflow-runner-sizing\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698\"\u003e\u003ccode\u003ebfcc52b\u003c/code\u003e\u003c/a\u003e\nRun slow macOS checks on larger runners\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4\"\u003e\u003ccode\u003e8c251e7\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4129\"\u003e#4129\u003c/a\u003e\nfrom github/update-bundle/codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1\"\u003e\u003ccode\u003e0b7ca40\u003c/code\u003e\u003c/a\u003e\nAdd changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505\"\u003e\u003ccode\u003e40484b3\u003c/code\u003e\u003c/a\u003e\nUpdate default bundle to codeql-bundle-v2.27.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df\"\u003e\u003ccode\u003e977e6ce\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4124\"\u003e#4124\u003c/a\u003e\nfrom github/henrymercer/toolcache-bundle-cleanup\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc\"\u003e\u003ccode\u003e40a6b38\u003c/code\u003e\u003c/a\u003e\nAddress toolcache cleanup review feedback\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252\"\u003e\u003ccode\u003edeece8f\u003c/code\u003e\u003c/a\u003e\nApply suggestion from \u003ca\nhref\u003d\"https://github.com/henrymercer\"\u003e\u003ccode\u003e@​henrymercer\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...b96794f015dfd88f77b49b1c93e0fa7110f94c63\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "50e18d46f4940829aea89f41babe324e65ab70de",
      "tree": "16fd48be4c273d831112406759e314d39bc26ce5",
      "parents": [
        "25318da789b94854908a15b4c718145e4e63fc87"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Sep 17 15:07:50 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 17 15:07:50 2026"
      },
      "message": "roll deps (#6842)\n\n- **Roll external/abseil_cpp/ ba427a3dd..9655f546c (3 commits)**\n- **Roll external/spirv-headers/ f0bf307f7..0d25db97c (1 commit)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "25318da789b94854908a15b4c718145e4e63fc87",
      "tree": "759059e6b9da4f789e28815e12242a7e2cb5d0e4",
      "parents": [
        "9abb194732777e849290dbd35e874bf3b91ba17e"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Tue Sep 15 18:58:30 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 15 18:58:30 2026"
      },
      "message": "spirv-opt: Run tests with lower max id bound (#6881)\n\nAfter running a pass, if the pass generated new IDs, re-run the pass for\neach intermediate ID bound between the original and optimized bound to\nguarantee an ID overflow. This verifies that the pass handles ID\noverflow gracefully and does not crash.\n\nThis does not necessarily cover all code paths, but should cover most.\n\nAdds SetTestIdOverflow() to PassTest to allow test suites (such as\nCanonicalizeIdsTest) to opt out of the ID overflow testing.\n\nPerformance impact on test_opt (3,772 unit tests):\n- Baseline runtime: 1m 21.1s (80.8s)\n- With ID overflow tests: 1m 35.6s (95.4s)\n- Overhead: +14.5s (~18% increase)"
    },
    {
      "commit": "9abb194732777e849290dbd35e874bf3b91ba17e",
      "tree": "8d00c6e272a7641d037909a58221abf3908eb8c0",
      "parents": [
        "d6f63db7031c181c146963206da772445704d5a0"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Sep 14 20:22:59 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 14 20:22:59 2026"
      },
      "message": "spirv-opt: Fix memory leaks on ID overflow (#6887)\n\nSeveral passes clone a basic block or an instruction into a raw pointer\nand only transfer ownership to the module later. When ID allocation\nfails part way through, these passes bail out before ownership is\ntransferred, and the clone is leaked. The solution is to take ownership\nimmediately.\n\nThese leaks are found in the presubmits for #6881."
    },
    {
      "commit": "d6f63db7031c181c146963206da772445704d5a0",
      "tree": "bfce83bc3d2fd8562466dc98b58cb9c406d435e3",
      "parents": [
        "562ff5b020f594f29c39d6117da67b0fbced70d8"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sat Sep 12 22:39:37 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Sep 12 22:39:37 2026"
      },
      "message": "spirv-val: Add RT Volatile memory model checks (#6868)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6587\n\n\u003cimg width\u003d\"1042\" height\u003d\"306\" alt\u003d\"image\"\nsrc\u003d\"https://github.com/user-attachments/assets/fb71faa0-ac36-4193-84f5-14a6649bc8df\"\n/\u003e"
    },
    {
      "commit": "562ff5b020f594f29c39d6117da67b0fbced70d8",
      "tree": "93e01f1a1ecd58fd01ba5b14878dae966506f5fd",
      "parents": [
        "17139e0998fbbf3f4afc73eed763551aba01f498"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Sep 11 19:24:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 11 19:24:07 2026"
      },
      "message": "spirv-val: Update test to use SPV_EXT_cooperative_matrix_maintenance1 (#6884)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6850"
    },
    {
      "commit": "17139e0998fbbf3f4afc73eed763551aba01f498",
      "tree": "0f189d7d9a974745ccc91ddb610345ffc889dea5",
      "parents": [
        "4bbc4f1ea60d0907c9ee3f9597539bfec1b04d24"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Sep 11 19:03:19 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 11 19:03:19 2026"
      },
      "message": "spirv-opt: Refactor SinglePassRunAndCheck to use SinglePassRunAndDisassemble (#6880)\n\nSimplifies SinglePassRunAndCheck by calling SinglePassRunAndDisassemble,\nremoving duplicated validation and disassembly logic, and replaces\nOptimizeToBinary with RunPassAndGetBinary to separate module compilation\nfrom pass execution."
    },
    {
      "commit": "4bbc4f1ea60d0907c9ee3f9597539bfec1b04d24",
      "tree": "bd78cf64911e6e26a446d7a6b7237e04ff48e50b",
      "parents": [
        "6b2b3971ec9058745929dd2f3a44e8c3ae32b661"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Sep 10 14:18:16 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 10 14:18:16 2026"
      },
      "message": "spirv-opt: Harden passes against ID overflow (#6877)\n\nHarden GraphicsRobustAccessPass, IfConversion, Inliner, and\nInterfaceVariableScalarReplacement against ID overflow."
    },
    {
      "commit": "6b2b3971ec9058745929dd2f3a44e8c3ae32b661",
      "tree": "18fad8d10c114bda1ebe1b77246e57332871e034",
      "parents": [
        "ef96ed763b43b59b33b31b362f09a02b729fa1c9"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Sep 10 13:56:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 10 13:56:15 2026"
      },
      "message": "spirv-opt: Harden passes against ID overflow (#6878)\n\nHarden LegalizeMultidimArrayPass, SSARewritePass, ReduceLoadSize,\nReplaceDescArrayAccessUsingVarIndex, ReplaceInvalidOpcodePass,\nScalarReplacementPass, SplitCombinedImageSamplerPass,\nUpgradeMemoryModel,\nand VectorDCE against ID overflow."
    },
    {
      "commit": "ef96ed763b43b59b33b31b362f09a02b729fa1c9",
      "tree": "d78c1456cdbdd6342b42dc13a8e790411acd05e5",
      "parents": [
        "e265f557e3db20843c6d135d2b9eeb51ecc79d73"
      ],
      "author": {
        "name": "Natalie Chouinard",
        "email": "sudonatalie@google.com",
        "time": "Thu Sep 10 13:28:18 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 10 13:28:18 2026"
      },
      "message": "Prepare release v2026.4.rc2 (#6874)\n\nUpdate release to include changes in #6870, #6872 and #6873."
    },
    {
      "commit": "e265f557e3db20843c6d135d2b9eeb51ecc79d73",
      "tree": "7f71fdd5a06561051d58c1bd425741b1f220d1b0",
      "parents": [
        "5262baed1ceceb131175be564547d2b11a76be84"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Sep 09 19:33:26 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 09 19:33:26 2026"
      },
      "message": "spirv-opt: Harden FixStorageClass and constant folding against ID overflow (#6876)\n\n- In FixStorageClass, check for zero/failure when getting pointer types\nand prevent infinite loop in PropagateStorageClass when type\nmodification fails.\n  Propagates Status::Failure on ID overflow.\n- In ConstantManager, safely handle null Constant pointers.\n- In const_folding_rules and fold, check for nullptr when retrieving\n  defining instructions or creating folded constants on ID overflow."
    },
    {
      "commit": "5262baed1ceceb131175be564547d2b11a76be84",
      "tree": "734e34b372366415a36e6980f25c068930fb9ee5",
      "parents": [
        "39d22ec0037d153fccca2108bb0d34c157db8c0f"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Sep 09 18:56:00 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 09 18:56:00 2026"
      },
      "message": "spirv-val: Abort Message Type are concrete types (#6873)\n\n(hopefully) final check for\nhttps://github.khronos.org/SPIRV-Registry/extensions/KHR/SPV_KHR_abort.html\n\ncc @r-potter"
    },
    {
      "commit": "39d22ec0037d153fccca2108bb0d34c157db8c0f",
      "tree": "c00b249a6d67512cc782a3d4facec4a067ef35e1",
      "parents": [
        "14521db96e91200a0ef7cc50e6df331e71282a6b"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Sep 09 13:45:40 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 09 13:45:40 2026"
      },
      "message": "spirv-val: Add UTFEncodedKHR validation (#6872)\n\nadds `UTFEncodedKHR` validation for\nhttps://github.khronos.org/SPIRV-Registry/extensions/KHR/SPV_KHR_constant_data.html\n\ncc @r-potter"
    },
    {
      "commit": "14521db96e91200a0ef7cc50e6df331e71282a6b",
      "tree": "29a3e9597126eb81fe09532aef8d60dfc5c9a8b1",
      "parents": [
        "5f83e08bf58de13fe8189fa3df3b24f7be0b48ee"
      ],
      "author": {
        "name": "Ralph Potter",
        "email": "r.potter@samsung.com",
        "time": "Tue Sep 08 23:41:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 23:41:15 2026"
      },
      "message": "Validate ArrayStride on OpConstantDataKHR result types (#6870)\n\nThe SPV_KHR_constant_data Data literals are tightly packed, so the\nextension requires that Result Type must not be decorated with\nArrayStride, which would contradict how the constant is encoded. Add\nthat check to ValidateConstantData().\n\nAlso dispatch OpSpecConstantDataKHR to ValidateConstantData(). The\nextension applies the same result type and Data size rules to both\nconstant-creation instructions, but only OpConstantDataKHR was being\nvalidated.\n\nCo-authored-by: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "5f83e08bf58de13fe8189fa3df3b24f7be0b48ee",
      "tree": "81eb3d5286e3a1eddc0c44e2e673b98e3d634443",
      "parents": [
        "3d202fc86e6738b1deaab2e9c5afec5eae7ce450"
      ],
      "author": {
        "name": "Natalie Chouinard",
        "email": "sudonatalie@google.com",
        "time": "Tue Sep 08 18:33:45 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 18:33:45 2026"
      },
      "message": "Prepare release v2026.4 (#6871)"
    },
    {
      "commit": "3d202fc86e6738b1deaab2e9c5afec5eae7ce450",
      "tree": "a9677f625cde75c08716fbf7309e1a07577e6aed",
      "parents": [
        "685919f35dfbb8c2b50bf61412349a48d9fc6a37"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Sep 08 17:53:30 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 17:53:30 2026"
      },
      "message": "spirv-val: Invocation Repack Instructions (#6867)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6736"
    },
    {
      "commit": "685919f35dfbb8c2b50bf61412349a48d9fc6a37",
      "tree": "5a5e208641080f7ba6916bc113be721d30888fc9",
      "parents": [
        "281d08662be5e96a2b0eff7214dfeb118c85da03"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Sep 07 14:21:55 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 07 14:21:55 2026"
      },
      "message": "spirv-val: Validate DebugPrintf (#6861)\n\nFrom https://github.com/KhronosGroup/glslang/pull/4404 seems like we\nnever added any validation for the `DebugPrintf` extended instruction\n\n(copied other PR how to add the various build command so hopefully that\npart works, CI will tell me I guess if not)"
    },
    {
      "commit": "281d08662be5e96a2b0eff7214dfeb118c85da03",
      "tree": "4199010a006a3e6e61c902f5d4437a26dddab8e4",
      "parents": [
        "907d104d2b7197b0207b7889671b149e1d1bc8ab"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Sep 07 14:21:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 07 14:21:15 2026"
      },
      "message": "spirv-val: Label VUID 08724 (#6865)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6593"
    },
    {
      "commit": "907d104d2b7197b0207b7889671b149e1d1bc8ab",
      "tree": "7bc79713ad4d760eddd930c9040438e4ced8da79",
      "parents": [
        "fd9bc85c546219b61b04556695c17f4ac3a4192a"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Sep 04 15:38:21 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 04 15:38:21 2026"
      },
      "message": "spirv-opt: Harden EliminateDeadMembers and FixFuncCallArguments against ID overflow (#6863)\n\nHardens EliminateDeadMembersPass and FixFuncCallArgumentsPass against ID\noverflow:\n- In EliminateDeadMembersPass, returns Pass::Status from\nUpdateAccessChain and\nRemoveDeadMembers. Checks for null when creating uint constant in\nUpdateAccessChain,\nand uses WhileEachInst in RemoveDeadMembers to terminate early on error.\n- In FixFuncCallArgumentsPass, checks for null when creating variables\nand\nload/store instructions in ReplaceAccessChainFuncCallArguments and\npropagates\nfailure status. Also updates Process() to use func.WhileEachInst to\nterminate\n  early on failure.\n\n---\n\n\u003csub\u003eStack created with \u003ca\nhref\u003d\"https://github.com/github/gh-stack\"\u003eGitHub Stacks CLI\u003c/a\u003e • \u003ca\nhref\u003d\"https://gh.io/stacks-feedback\"\u003eGive Feedback 💬\u003c/a\u003e\u003c/sub\u003e"
    },
    {
      "commit": "fd9bc85c546219b61b04556695c17f4ac3a4192a",
      "tree": "270e73d61cf866c04611f8c08b643dbae6c4b947",
      "parents": [
        "0db14571ad2dccdbcbec4f05e57a820e3a15c815"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Sep 04 01:09:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 04 01:09:10 2026"
      },
      "message": "spirv-opt: Add WhileEachInst to Module, InstructionList, and Graph (#6862)\n\nAdds WhileEachInst (const and non-const overloads) to:\n- InstructionList\n- Graph\n- Module\n\nAllows iterating through all instructions and terminating early when the\ncallback returns false. Adds unit tests to verify early termination.\n\nAlso:\n- Re-implements ForEachInst in terms of WhileEachInst across Module,\n  InstructionList, and Graph to reduce code duplication.\n- Unifies the section traversal order in Module::WhileEachInstImpl and\nadds a\n  static_assert to verify matching constness between ModuleT and InstT.\n- Includes trailing_dbg_line_info_ in both const and non-const\niteration."
    },
    {
      "commit": "0db14571ad2dccdbcbec4f05e57a820e3a15c815",
      "tree": "a9438822415f319fe3f4327bc20906dbb7f545e5",
      "parents": [
        "8f573649bca4158325f394a9c4951a6eb5de8f7f"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Sep 02 18:53:56 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 18:53:56 2026"
      },
      "message": "spirv-val: Aborts are always packed as scalar (#6859)\n\n@alan-baker sorry to make you bounce around, but @r-potter went to go\nfix the GLSL in https://github.com/KhronosGroup/glslang/pull/4398 and\ndiscussed with Tobias that it should be always scalar"
    },
    {
      "commit": "8f573649bca4158325f394a9c4951a6eb5de8f7f",
      "tree": "32149745db7fd394ad524ba84f899f51047f7168",
      "parents": [
        "3a2f6ea08f17f149908a17ff9ba6cba4791d7f96"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Tue Sep 01 13:16:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 01 13:16:29 2026"
      },
      "message": "spirv-opt: Harden EliminateDeadFunctionsPass and IRContext against ID overflow (#6857)\n\nModifies EliminateDeadFunctionsPass and\nIRContext::KillOperandFromDebugInstructions\nto handle ID overflow when GetDebugInfoNone returns nullptr, avoiding\nnull dereference.\nPropagates Status::Failure in EliminateDeadFunctionsPass."
    },
    {
      "commit": "3a2f6ea08f17f149908a17ff9ba6cba4791d7f96",
      "tree": "2ea49e4639ef1ab3a510c49436c3fb3a620b2ac2",
      "parents": [
        "1ec625b4c087921a06afd3befb807fea6f57c674"
      ],
      "author": {
        "name": "Jeremy Howard",
        "email": "j@howard.fm",
        "time": "Mon Aug 31 19:05:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 19:05:07 2026"
      },
      "message": "bazel: load C++ rules from rules_cc (#6848)\n\nWe’re building [xmojo](https://github.com/AnswerDotAI/xmojo), an\nin-process ORC-based Mojo environment for terminal and Jupyter\nfrontends. It includes a WebGPU compiler backend that lowers Mojo\nkernels through LLVM’s SPIR-V target and uses SPIRV-Tools to produce\nWebGPU-compatible modules.\n\nFor example:\n\n```mojo\ndef kernel(\n    output: Pointer[\n        Int32, MutAnyOrigin, address_space\u003dAddressSpace(11)\n    ],\n):\n    output[unsafe_offset\u003d0] \u003d 42\n```\n\nis compiled to SPIR-V, loaded by Dawn, and executed on Metal.\n\nLLVM currently leaves resource-binding names as dead `i8` data in the\nemitted module. Dawn rejects the resulting `Int8` capability, so xmojo\nuses SPIRV-Tools for dead-code elimination and validation before passing\nthe module to WebGPU.\n\nxmojo builds against Modular’s Bazel 10 workspace and includes\nSPIRV-Tools as an external repository. Although SPIRV-Tools already\ndeclares `rules_cc`, its `BUILD.bazel` still relies on the removed\nnative C++ rules, so analysis stops at its first `cc_library`:\n\n```text\nThis rule has been removed from Bazel. Please add a `load()` statement for it.\n```\n\nThis PR loads `cc_binary`, `cc_library`, and `cc_test` from the existing\n`rules_cc` dependency. With that change, `spirv_tools_opt` builds\nsuccessfully and xmojo’s generated kernel executes through Dawn on\nMetal."
    },
    {
      "commit": "1ec625b4c087921a06afd3befb807fea6f57c674",
      "tree": "19f2a0dfbf6628f999e806ee718c500184a1a726",
      "parents": [
        "d693d2289e69f47135918089ab8038a929e43661"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Aug 31 18:42:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 18:42:07 2026"
      },
      "message": "spirv-opt: Harden EliminateDeadIOComponentsPass and ConstantManager against ID overflow (#6858)\n\nModifies ConstantManager::GetUIntConstId and GetNullConstId to check for\nnull\nwhen GetDefiningInstruction returns nullptr on ID overflow.\nModifies EliminateDeadIOComponentsPass to check for ID overflow and\npropagate\nStatus::Failure."
    },
    {
      "commit": "d693d2289e69f47135918089ab8038a929e43661",
      "tree": "9ae90fad5c10a341f402697c213957b293da1638",
      "parents": [
        "b40380bfa431d028fb7ca8eb375e4d21ea98a70e"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Aug 31 14:51:55 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:51:55 2026"
      },
      "message": "spirv-opt: Harden DeadBranchElimPass against ID overflow (#6852)\n\nModifies DeadBranchElimPass to gracefully handle ID overflow events\nwhen generating OpUndef instructions in FixPhiNodesInLiveBlocks.\nPropagates Status::Failure instead of using invalid ID 0."
    },
    {
      "commit": "b40380bfa431d028fb7ca8eb375e4d21ea98a70e",
      "tree": "9a5735b1caeb5ccfce225b47525de2e0911e6101",
      "parents": [
        "f42fd8d3751349c11bdf9450bd4b249b8b1278df"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Aug 28 16:00:46 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 28 16:00:46 2026"
      },
      "message": "spirv-val: Add Offset Input VUID 12509 (#6855)\n\nadds ` VUID-StandaloneSpirv-Offset-12509` which was added in 1.4.361\nspec"
    },
    {
      "commit": "f42fd8d3751349c11bdf9450bd4b249b8b1278df",
      "tree": "bfb08426a4c3a9dd39c60c08a3899bd37df1dbf7",
      "parents": [
        "d7ca4efbbe36709fc49e1a102cdbe1d970d5eb7e"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Aug 28 13:00:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 28 13:00:28 2026"
      },
      "message": "spirv-opt: Harden ADCE and DebugInfoManager against ID overflow (#6851)\n\nModifies ADCE and DebugInfoManager helper functions to gracefully\nhandle ID overflow events (when TakeNextIdBound() returns 0).\nPropagates Status::Failure instead of asserting or continuing with\ninvalid IDs."
    },
    {
      "commit": "d7ca4efbbe36709fc49e1a102cdbe1d970d5eb7e",
      "tree": "41c88db6b6710fd8aaae7d8c9b77923c281d7173",
      "parents": [
        "ecea80f176e17a7afbea8c626b5adc6b5a4cbefb"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Aug 27 20:44:24 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 20:44:24 2026"
      },
      "message": "spirv-val: Check for Offset in Input/Output (#6835)\n\nadds one of the missing VUs from\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6594\n\nInspired by\nhttps://gitlab.khronos.org/vulkan/vulkan/-/merge_requests/8427 and\nhttps://gitlab.khronos.org/vulkan/vulkan/-/merge_requests/8466\n\n---------\n\nCo-authored-by: alan-baker \u003calanbaker@google.com\u003e"
    },
    {
      "commit": "ecea80f176e17a7afbea8c626b5adc6b5a4cbefb",
      "tree": "5ae1b528b8657df2daea913e36e91cddc874dc9b",
      "parents": [
        "b964f44901ad6396d3b46307ef1ce66eaef3bb83"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Aug 27 20:35:02 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 20:35:02 2026"
      },
      "message": "spirv-val: Validate ShaderAbort explicit layout (#6854)\n\nFor https://github.com/KhronosGroup/glslang/issues/4369 and\nhttps://github.com/KhronosGroup/Vulkan-ValidationLayers/issues/12298\n\n`OpAbortKHR` was not validating the `Message Type` and glslang has been\ngenerating invalid SPIR-V"
    },
    {
      "commit": "b964f44901ad6396d3b46307ef1ce66eaef3bb83",
      "tree": "c026dd46cd722710623bc55cc8dac5d1dc5fcd44",
      "parents": [
        "47c74f488bad1136559f382ce99e8e52d7a392cd"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Aug 25 17:51:14 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 17:51:14 2026"
      },
      "message": "spirv-val: Add Explicit Alignment VUIDs (#6853)\n\nThese VUs use to only be caught in VVL but now they are caught in\n`spirv-val` when we pass in the alignment, but without the VUID, the\nerror message is a bit more confusing (when you get it from VVL)"
    },
    {
      "commit": "47c74f488bad1136559f382ce99e8e52d7a392cd",
      "tree": "b65957374dbf3df0cb73fd16fcebbc7e05c47065",
      "parents": [
        "e39e5c5838bc4b4162c349f2a2e5f163efe5432f"
      ],
      "author": {
        "name": "Marcos Maronas",
        "email": "mmaronas@amd.com",
        "time": "Wed Aug 19 23:10:19 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 19 23:10:19 2026"
      },
      "message": "[val] Allow OpExtInstWithForwardRefsKHR in generic non-semantic sets (#6847)\n\nPrior to this patch, `OpExtInstWithForwardRefsKHR` was only accepting\nforward refs for `DebugInfo` extended sets. Now, it gains the ability to\nallow forward refs for other generic non-semantic sets.\n\nThree new tests were added:\n1. Test that `OpExtInstWithForwardRefsKHR` using an instruction from a\ngeneric (non-DebugInfo) NonSemantic set can use a forward ref.\n2. Same than 1. but using `OpExtInst` rather than\n`OpExtInstWithForwardRefsKHR`. Tests that forward refs are only allowed\nwith the correct opcode.\n3. Test that `OpExtInstWithForwardRefsKHR` using an instruction from a\n*semantic* extended set doesn\u0027t allow forward ref."
    },
    {
      "commit": "e39e5c5838bc4b4162c349f2a2e5f163efe5432f",
      "tree": "14e54810018e8c217500769052a157d54882358b",
      "parents": [
        "f836fe458fde5aa3dd65624e47f311a3498ddbb2"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Aug 14 23:08:08 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 23:08:08 2026"
      },
      "message": "Update version number examples in README.md (#6830)\n\n2016 -\u003e 2026"
    },
    {
      "commit": "f836fe458fde5aa3dd65624e47f311a3498ddbb2",
      "tree": "54570acff24395fb11234c449eb1c46fc69d6b2b",
      "parents": [
        "faf7807722d321873f7263cc57a5a7641252a2b3"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Aug 14 17:16:01 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 17:16:01 2026"
      },
      "message": "spirv-val: Validate OpSourceContinued order (#6840)\n\nnothing validated if `OpSourceContinued` was there without the\n`OpSource` before it"
    },
    {
      "commit": "faf7807722d321873f7263cc57a5a7641252a2b3",
      "tree": "82db7082138acd5edbeefc97924fd07489be66eb",
      "parents": [
        "d176a1a408e79718c490f06c156e6321d6e34874"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Aug 14 16:59:40 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 16:59:40 2026"
      },
      "message": "bazel: avoid implicit __init__.py creation (#6841)\n\nEliminates warnings about \"diabolical\" behaviour:\n\nThis diabolic behavior is deprecated and will be disabled by default in\na\n  future release.\n  See https://github.com/bazel-contrib/rules_python/issues/2945"
    },
    {
      "commit": "d176a1a408e79718c490f06c156e6321d6e34874",
      "tree": "1383986439d4a59a130806de627c2a81114b01f7",
      "parents": [
        "239a5a8dc9c2e756e523c7190c7007d32be7909d"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Fri Aug 14 16:17:05 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 16:17:05 2026"
      },
      "message": "[opt] Pass to convert to untyped pointers (#6714)\n\nConverts typed pointers instructions to their untyped versions:\n* OpTypePointer -\u003e OpTypeUntypedPointerKHR\n* OpVariable -\u003e OpUntypedVariableKHR\n* OpAccessChain -\u003e OpUntypedAccessChainKHR\n* OpInBoundsAccessChain -\u003e OpUntypedInBoundsAccessChainKHR\n* OpPtrAccessChain -\u003e OpUntypedPtrAccessChainKHR\n* OpInBoundsPtrAccessChain -\u003e OpUntypedInBoundsPtrAccessChainKHR\n* OpCopyMemory\n  * this is decomposed into loads and stores\n* Updates stride in cooperative matrix load/store\n\nSupported storage classes:\n* StorageBuffer\n* Uniform\n* PushConstant\n* PhysicalStorageBuffer\n* Workgroup (if workgroup memory explicit layout is enabled)\n\nFuture work:\n* Add an option to convert to workgroup memory explicit layout\n* Support UniformConstant for OpUntypedImageTexelPointerEXT"
    },
    {
      "commit": "239a5a8dc9c2e756e523c7190c7007d32be7909d",
      "tree": "eaf7bc8e03794004fec8e2e2d4e5f82b5c06d08e",
      "parents": [
        "bc4c8fd1b13f30dad42f4521af2ca312b1e3d9b3"
      ],
      "author": {
        "name": "carrerasdarren-cell",
        "email": "carrerasdarren@gmail.com",
        "time": "Fri Aug 14 15:21:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 15:21:10 2026"
      },
      "message": "binary: Initialize parsed operand FP encoding (#6834)\n\n## Problem\n\nWhen `fp_encoding` was added to `spv_parsed_operand_t`,\n`Parser::parseOperand` did not give the field a default value.\nStandalone literal-float operands therefore pass an indeterminate enum\nto `EmitNumericLiteral`, causing the MemorySanitizer finding in\n[OSS-Fuzz issue 423059200](https://issues.oss-fuzz.com/issues/423059200)\nand nondeterministic disassembly.\n\nThe public testcase reaches this path through `OpDecorate ...\nFPMaxErrorDecorationINTEL \u003cLiteralFloat\u003e`. With compiler stack-pattern\ninitialization, the float was omitted from the output; with zero\ninitialization, it was printed.\n\n## Fix\n\nInitialize every parsed operand with `SPV_FP_ENCODING_UNKNOWN` before\noperand-specific parsing. Extend the parser-test equality and\ndiagnostics to cover this field, and add a regression test for the\nstandalone literal-float decoration path.\n\n## Verification\n\n- Exact OSS-Fuzz testcase disassembles with its float operand under\n`-ftrivial-auto-var-init\u003dpattern`.\n- `BinaryParseTest.LiteralFloatOperandHasUnknownEncoding` passes.\n- All 6,418 `test_spirv_unit_tests` cases pass under stack-pattern\ninitialization."
    },
    {
      "commit": "bc4c8fd1b13f30dad42f4521af2ca312b1e3d9b3",
      "tree": "7e7fc551a90777d161b159bba4760d6660a15305",
      "parents": [
        "bb9d0b1b97bd3548128f87d180194e912df4d5df"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Aug 14 13:30:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 13:30:28 2026"
      },
      "message": "roll deps (#6839)\n\n- **Roll external/googletest/ 02e50550c..49495eacf (3 commits)**\n- **Roll external/abseil_cpp/ ee41bbdf1..ba427a3dd (5 commits)**\n- **Roll external/effcee/ 4d92bbdbe..f8e8a1648 (1 commit)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "bb9d0b1b97bd3548128f87d180194e912df4d5df",
      "tree": "59d1c7583e6e5ad709bdea02b0f0a2345b45bb54",
      "parents": [
        "29174bd16335bb1404466ee59dad4fc7bf51efb3"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Aug 13 15:29:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 13 15:29:15 2026"
      },
      "message": "roll deps (#6838)\n\n- **Roll external/googletest/ a25f43576..963dd8ea1 (37 commits)**\n- **Roll external/abseil_cpp/ c34b14912..43e07c386 (66 commits)**\n- **Roll external/spirv-headers/ 27009dcae..942fe4b98 (1 commit)**\n- **Roll external/mimalloc/ 76d3f8a93..fc1e2acbc (873 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "29174bd16335bb1404466ee59dad4fc7bf51efb3",
      "tree": "bf1bf40a6ae5265c9617e3160f8699c533960cc5",
      "parents": [
        "6471552696cf766063670315a7124cb1792e6774"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Aug 12 14:01:44 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 14:01:44 2026"
      },
      "message": "Roll deps (#6836)\n\nUpdates the DEPS. Absail depends on gloop@20260708.rc1, which requires\nbazel v8. We move up to Bazel 8 at the same time.\n\nThe move to Bazel 8 required some other changes in the bazel build\nfiles. I believe it is skipping WORKSPACE by default now exposing some\nerror.\n\nThere was also a conflict in the version of abseil used by RE2 and\nGoogletest. This is fixed by forcing both the use the checkouted\nversion, which we should have been doing anyway.\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "6471552696cf766063670315a7124cb1792e6774",
      "tree": "9d1f6aa28f0088b1ac4494c594ee75ea54b2e91e",
      "parents": [
        "ab07f9412ae631af816909b6b8440896da5d6f11"
      ],
      "author": {
        "name": "Natalie Chouinard",
        "email": "sudonatalie@google.com",
        "time": "Wed Aug 12 12:58:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 12:58:07 2026"
      },
      "message": "Start v2026.4 release (#6837)\n\nUpdate CHANGES to start the next dev release."
    },
    {
      "commit": "ab07f9412ae631af816909b6b8440896da5d6f11",
      "tree": "bcd085713aa99c7eb715c9a3228111cd3c3fbd95",
      "parents": [
        "ebe980a5e54f2dd52b3b4b23ff433a1843d58040"
      ],
      "author": {
        "name": "Marijn Suijten",
        "email": "marijn@traverseresearch.nl",
        "time": "Mon Aug 10 16:43:57 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 10 16:43:57 2026"
      },
      "message": "Optimize `SPV_KHR_opacity_micromap` (#6833)\n\nJust like https://github.com/KhronosGroup/SPIRV-Tools/pull/6571 this\nallows optimization shaders containing `SPV_KHR_opacity_micromap`,\nrequired to strip dead and invalid SPIR-V ops that DXC otherwise emits."
    },
    {
      "commit": "ebe980a5e54f2dd52b3b4b23ff433a1843d58040",
      "tree": "29c7586b9391309f66bfb04514557a3b53b71633",
      "parents": [
        "e5a073d76b4db86bd6ec8ffa82a05994982d75f8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Aug 10 15:21:39 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 10 15:21:39 2026"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 4 updates (#6823)\n\nBumps the github-actions group with 4 updates in the / directory:\n[actions/checkout](https://github.com/actions/checkout),\n[lukka/get-cmake](https://github.com/lukka/get-cmake),\n[ossf/scorecard-action](https://github.com/ossf/scorecard-action) and\n[github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\nUpdates `actions/checkout` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/releases\"\u003eactions/checkout\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eskip running unsafe pr check if input is default by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2518\"\u003eactions/checkout#2518\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etrim only ascii whitespace for branch by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2521\"\u003eactions/checkout#2521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape values passed to --unset by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2530\"\u003eactions/checkout#2530\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/checkout/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/blob/main/CHANGELOG.md\"\u003eactions/checkout\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip running unsafe pr check if input is default by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2518\"\u003eactions/checkout#2518\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrim only ascii whitespace for branch by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2521\"\u003eactions/checkout#2521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEscape values passed to --unset by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2530\"\u003eactions/checkout#2530\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock checking out fork PR for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePersist creds to a separate file by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2286\"\u003eactions/checkout#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README to include Node.js 24 support details and requirements\nby \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2248\"\u003eactions/checkout#2248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v5 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2301\"\u003eactions/checkout#2301\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions checkout to use node 24 by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2226\"\u003eactions/checkout#2226\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v4 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2305\"\u003eactions/checkout#2305\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README.md by \u003ca\nhref\u003d\"https://github.com/motss\"\u003e\u003ccode\u003e@​motss\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1971\"\u003eactions/checkout#1971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd internal repos for checking out multiple repositories by \u003ca\nhref\u003d\"https://github.com/mouismail\"\u003e\u003ccode\u003e@​mouismail\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1977\"\u003eactions/checkout#1977\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation update - add recommended permissions to Readme by \u003ca\nhref\u003d\"https://github.com/benwells\"\u003e\u003ccode\u003e@​benwells\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2043\"\u003eactions/checkout#2043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdjust positioning of user email note and permissions heading by \u003ca\nhref\u003d\"https://github.com/joshmgross\"\u003e\u003ccode\u003e@​joshmgross\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2044\"\u003eactions/checkout#2044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca\nhref\u003d\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2194\"\u003eactions/checkout#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate CODEOWNERS for actions by \u003ca\nhref\u003d\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2224\"\u003eactions/checkout#2224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate package dependencies by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2236\"\u003eactions/checkout#2236\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eurl-helper.ts\u003c/code\u003e now leverages well-known environment\nvariables by \u003ca href\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1941\"\u003eactions/checkout#1941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand unit test coverage for \u003ccode\u003eisGhes\u003c/code\u003e by \u003ca\nhref\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1946\"\u003eactions/checkout#1946\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCheck out other refs/* by commit if provided, fall back to ref by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1924\"\u003eactions/checkout#1924\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003e\u003ccode\u003e3d3c42e\u003c/code\u003e\u003c/a\u003e\nprep v7.0.1 release (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2531\"\u003e#2531\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07\"\u003e\u003ccode\u003e2880268\u003c/code\u003e\u003c/a\u003e\nescape values passed to --unset (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2530\"\u003e#2530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1\"\u003e\u003ccode\u003e12cd223\u003c/code\u003e\u003c/a\u003e\ntrim only ascii whitespace for branch (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2521\"\u003e#2521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541\"\u003e\u003ccode\u003e62661c4\u003c/code\u003e\u003c/a\u003e\nskip running unsafe pr check if input is default (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2518\"\u003e#2518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f\"\u003e\u003ccode\u003ee8d4307\u003c/code\u003e\u003c/a\u003e\nBump the minor-actions-dependencies group with 2 updates (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2499\"\u003e#2499\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87\"\u003e\u003ccode\u003e631c942\u003c/code\u003e\u003c/a\u003e\neslint 9 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2474\"\u003e#2474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e\"\u003e\u003ccode\u003e4f1f4ae\u003c/code\u003e\u003c/a\u003e\nBump actions/upload-artifact from 4 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2476\"\u003e#2476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92\"\u003e\u003ccode\u003eba09753\u003c/code\u003e\u003c/a\u003e\nBump actions/checkout from 6 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2488\"\u003e#2488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22\"\u003e\u003ccode\u003eb9e0990\u003c/code\u003e\u003c/a\u003e\nBump docker/login-action from 3.3.0 to 4.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2479\"\u003e#2479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2\"\u003e\u003ccode\u003ee8cb398\u003c/code\u003e\u003c/a\u003e\nBump docker/build-push-action from 6.5.0 to 7.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2478\"\u003e#2478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lukka/get-cmake` from 4.4.0 to 4.4.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/releases\"\u003elukka/get-cmake\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eCMake v4.4.2\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003eget-cmake\u003c/code\u003e action downloads and caches CMake and\nNinja on your workflows. Versions can be specified using \u003ca\nhref\u003d\"https://docs.npmjs.com/about-semantic-versioning\"\u003esemantic\nversioning ranges\u003c/a\u003e using \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L13\"\u003e\u003ccode\u003ecmakeVersion\u003c/code\u003e\u003c/a\u003e\nand \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L16\"\u003e\u003ccode\u003eninjaVersion\u003c/code\u003e\u003c/a\u003e\ninputs.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elatest\u003c/code\u003e is now using CMake version \u003ccode\u003ev4.4.2\u003c/code\u003e,\nuse this one-liner e.g.:\n\u003ccode\u003euses: lukka/get-cmake@latest\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eEnjoy!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/fffaaafeea488556c2c12dad60690008bc1caacb\"\u003e\u003ccode\u003efffaaaf\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/4a7d025fc60f00db0c7b44ebf783d19b52444830\"\u003e\u003ccode\u003e4a7d025\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/06fec8f1da5f120990504a9da3e9891d71fb89ac\"\u003e\u003ccode\u003e06fec8f\u003c/code\u003e\u003c/a\u003e\nBump actions/checkout from 5 to 7\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/e6906078ebd1ccb8ce51ab4626ac46a1b5a517e3...fffaaafeea488556c2c12dad60690008bc1caacb\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ossf/scorecard-action` from 2.4.3 to 2.4.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/releases\"\u003eossf/scorecard-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.4.4\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cp\u003eThis update bumps the Scorecard version to the v5.5.0 release. For a\ncomplete list of changes, please refer to the \u003ca\nhref\u003d\"https://github.com/ossf/scorecard/releases/tag/v5.4.0\"\u003eScorecard\nv5.4.0 release notes\u003c/a\u003e and the \u003ca\nhref\u003d\"https://github.com/ossf/scorecard/releases/tag/v5.5.0\"\u003eScorecard\nv5.5.0 release notes\u003c/a\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003elog POST failures instead of failing entire action by \u003ca\nhref\u003d\"https://github.com/spencerschrock\"\u003e\u003ccode\u003e@​spencerschrock\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/pull/1625\"\u003eossf/scorecard-action#1625\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/compare/v2.4.3...v2.4.4\"\u003ehttps://github.com/ossf/scorecard-action/compare/v2.4.3...v2.4.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/2d1146689b8cda280b9bc96326124645441f03bc\"\u003e\u003ccode\u003e2d11466\u003c/code\u003e\u003c/a\u003e\nBump action tag for v2.4.4 release (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1688\"\u003e#1688\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/1bd3285473b114fb77ed934c4ba0aea31aa0f866\"\u003e\u003ccode\u003e1bd3285\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump the docker-images group across 1 directory with 2\nupdates (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/913edce4c1ce57261797e2ddcb74e493d9ce9700\"\u003e\u003ccode\u003e913edce\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump github.com/containerd/containerd from 1.7.32 to 1.7.33\n(\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1671\"\u003e#1671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/0957b8f1c327cafd868bd6bdb7e441c016628783\"\u003e\u003ccode\u003e0957b8f\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump golang.org/x/net from 0.56.0 to 0.57.0 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1680\"\u003e#1680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/f0061eb3ff8c4d311e47276c8bcc96e96ed5dc32\"\u003e\u003ccode\u003ef0061eb\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump google.golang.org/grpc from 1.81.1 to 1.82.1 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1687\"\u003e#1687\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/20ee7324026c52f8d0c4b372a7bf382a01b72ff9\"\u003e\u003ccode\u003e20ee732\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.4 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1685\"\u003e#1685\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/9f295ef01b1f77f15b1647c790db825d9577a441\"\u003e\u003ccode\u003e9f295ef\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump the github-actions group with 6 updates (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/69bf556cea38c0fbe034b2ce923253eca7c4d651\"\u003e\u003ccode\u003e69bf556\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1681\"\u003e#1681\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/94e8b9600123b21167ebf56077904fc6ca421a95\"\u003e\u003ccode\u003e94e8b96\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump github.com/sigstore/rekor from 1.5.0 to 1.5.2 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1673\"\u003e#1673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/commit/c7a1b37bbc88c32d53056d9071ce2ba0df381dfb\"\u003e\u003ccode\u003ec7a1b37\u003c/code\u003e\u003c/a\u003e\n:seedling: Bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6 (\u003ca\nhref\u003d\"https://redirect.github.com/ossf/scorecard-action/issues/1675\"\u003e#1675\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/ossf/scorecard-action/compare/4eaacf0543bb3f2c246792bd56e8cdeffafb205a...2d1146689b8cda280b9bc96326124645441f03bc\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/upload-sarif` from 4.37.1 to 4.37.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.37.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format\nthat was introduced in CodeQL Action 4.37.0 / 3.37.0 to\n\u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested\npath that is used elsewhere. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.37.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of\nthe CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead\nof falling back to downloading the bundle before extracting it. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.37.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the\n\u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to\nbe specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository\nproperty\u003c/a\u003e. This feature will gradually be rolled out following the\nrelease of this version. Once rolled out, this allows for the CodeQL CLI\nversion that is used in GitHub-managed workflows, such as Default Setup,\nto be set to a custom value. For example, customers who run into issues\nwith rate limits when a new CodeQL CLI version is released can set the\nvalue to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version\nthat is available in the runner toolcache. For Advanced Setup workflows,\nthe value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition\nalways takes precedence unless the value of the repository property\nstarts with \u003ccode\u003e!\u003c/code\u003e. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.37.3\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003ev4.37.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that\nwas introduced in CodeQL Action 4.37.0 is now enabled by default. In\naddition to the format described there, the \u003ccode\u003eremote\u003d\u003c/code\u003e prefix\ncan now be used to explicitly indicate that the input refers to a remote\nfile. All previous input formats continue to be accepted as well. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action can now make use of \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003econfigured\nprivate registries\u003c/a\u003e in Default Setup to retrieve CodeQL configuration\nfiles from remote repositories that require authentication. This will\nallow customers to store their CodeQL configuration in a single\nrepository that can then be referenced by Default Setup workflows in\nother repositories. We expect to roll this and other, related changes\nout to everyone in July. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4007\"\u003e#4007\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.6 - 04 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged the default filepath for the new remote file address format\nthat was introduced in CodeQL Action 4.37.0 / 3.37.0 to\n\u003ccode\u003e.github/codeql-config.yml\u003c/code\u003e to align it with the suggested\npath that is used elsewhere. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4070\"\u003e#4070\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.5 - 03 Aug 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where a network error while streaming the download of\nthe CodeQL bundle could terminate the \u003ccode\u003einit\u003c/code\u003e Action instead\nof falling back to downloading the bundle before extracting it. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4061\"\u003e#4061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.4 - 29 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis version of the CodeQL Action adds support for the\n\u003ccode\u003etools\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e step to\nbe specified using a \u003ccode\u003egithub-codeql-tools\u003c/code\u003e \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003erepository\nproperty\u003c/a\u003e. This feature will gradually be rolled out following the\nrelease of this version. Once rolled out, this allows for the CodeQL CLI\nversion that is used in GitHub-managed workflows, such as Default Setup,\nto be set to a custom value. For example, customers who run into issues\nwith rate limits when a new CodeQL CLI version is released can set the\nvalue to \u003ccode\u003etoolcache\u003c/code\u003e to always use the CodeQL CLI version\nthat is available in the runner toolcache. For Advanced Setup workflows,\nthe value provided for \u003ccode\u003etools\u003c/code\u003e in the workflow definition\nalways takes precedence unless the value of the repository property\nstarts with \u003ccode\u003e!\u003c/code\u003e. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4037\"\u003e#4037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2\"\u003e2.26.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4051\"\u003e#4051\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.3 - 22 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.2 - 21 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe new address format for the \u003ccode\u003econfig-file\u003c/code\u003e input that\nwas introduced in CodeQL Action 4.37.0 is now enabled by default. In\naddition to the format described there, the \u003ccode\u003eremote\u003d\u003c/code\u003e prefix\ncan now be used to explicitly indicate that the input refers to a remote\nfile. All previous input formats continue to be accepted as well. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4023\"\u003e#4023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe CodeQL Action can now make use of \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003econfigured\nprivate registries\u003c/a\u003e in Default Setup to retrieve CodeQL configuration\nfiles from remote repositories that require authentication. This will\nallow customers to store their CodeQL configuration in a single\nrepository that can then be referenced by Default Setup workflows in\nother repositories. We expect to roll this and other, related changes\nout to everyone in July. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4007\"\u003e#4007\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.1 - 16 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUpcoming breaking change\u003c/em\u003e: Add a deprecation warning for\ncustomers using CodeQL version 2.20.6 and earlier. These versions of\nCodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise\nServer 3.16, and will be unsupported by the next minor release of the\nCodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3956\"\u003e#3956\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1\"\u003e2.26.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4019\"\u003e#4019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.0 - 08 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0\"\u003e2.26.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3995\"\u003e#3995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIn addition to the existing input format, the\n\u003ccode\u003econfig-file\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e\nstep will soon support a new \u003ccode\u003e[owner/]repo[@ref][:path]\u003c/code\u003e\nformat. All components except the repository name are optional. If\nomitted, \u003ccode\u003eowner\u003c/code\u003e defaults to the same owner as the repository\nthe analysis is running for, \u003ccode\u003eref\u003c/code\u003e to \u003ccode\u003emain\u003c/code\u003e, and\n\u003ccode\u003epath\u003c/code\u003e to \u003ccode\u003e.github/codeql-action.yaml\u003c/code\u003e. Support\nfor this format ships in this version of the CodeQL Action, but will\nonly be enabled over the coming weeks. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3973\"\u003e#3973\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.36.3 - 01 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.36.2 - 04 Jun 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCache CodeQL CLI version information across Actions steps. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3943\"\u003e#3943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduce requests while waiting for analysis processing by using\nexponential backoff when polling SARIF processing status. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3937\"\u003e#3937\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6\"\u003e2.25.6\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3948\"\u003e#3948\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/5595ccaf912efad79be6eef63a5619ff05969be3\"\u003e\u003ccode\u003e5595cca\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4071\"\u003e#4071\u003c/a\u003e\nfrom github/update-v4.37.6-6a9359a1b\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/ec9c75796a7f2cee5af0c5ffa0b81dc3bb58754b\"\u003e\u003ccode\u003eec9c757\u003c/code\u003e\u003c/a\u003e\nAdd change note for PR 4070\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/45c8742e17cbd668814137f95e605d925b8722a2\"\u003e\u003ccode\u003e45c8742\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.37.6\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/6a9359a1bd054c53cae7bb737bd8d796cfbf3014\"\u003e\u003ccode\u003e6a9359a\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4070\"\u003e#4070\u003c/a\u003e\nfrom github/mbg/remote-address/change-file-default\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/065cdc0394d424981db720df63ebc570e41b775f\"\u003e\u003ccode\u003e065cdc0\u003c/code\u003e\u003c/a\u003e\nChange \u003ccode\u003eDEFAULT_CONFIG_FILE_NAME\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f99dd5aeee9cf92e92d0c700cb0aa7afd7bbf431\"\u003e\u003ccode\u003ef99dd5a\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4066\"\u003e#4066\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/js-yaml-5.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/1804b211a343d69a6584d26fb3a68a8fe6ca39d4\"\u003e\u003ccode\u003e1804b21\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4068\"\u003e#4068\u003c/a\u003e\nfrom github/mergeback/v4.37.5-to-main-d1ba80a1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3020a2f46286abb1704269b22ada83bd0e81c64f\"\u003e\u003ccode\u003e3020a2f\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/93c3a5a40b7affbf8ea6a480767ed0db8e8d3c5c\"\u003e\u003ccode\u003e93c3a5a\u003c/code\u003e\u003c/a\u003e\nUpdate changelog and version after v4.37.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/d1ba80a13dd99fba24a470575428917156a28b43\"\u003e\u003ccode\u003ed1ba80a\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4067\"\u003e#4067\u003c/a\u003e\nfrom github/update-v4.37.5-1cd4d01d5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/7188fc363630916deb702c7fdcf4e481b751f97a...5595ccaf912efad79be6eef63a5619ff05969be3\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "e5a073d76b4db86bd6ec8ffa82a05994982d75f8",
      "tree": "538a9067cdb198d485d4ab7795e54ae0b9076881",
      "parents": [
        "388f5af1a6d4a4df4ab9bf69a1817255952e6ef1"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Aug 10 14:28:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 10 14:28:10 2026"
      },
      "message": "roll: Move mimalloc to main3 (#6832)\n\nUpstream mimalloc now uses main3 as the default branch. Updating our\nscripts to track that branch when doing rolls."
    },
    {
      "commit": "388f5af1a6d4a4df4ab9bf69a1817255952e6ef1",
      "tree": "2f716b6e6ded19957bddaf593658f93be1006585",
      "parents": [
        "28d05cf1a2591e05565d03435216cb6c19da0c43"
      ],
      "author": {
        "name": "Cosima Neidahl",
        "email": "opna2608@protonmail.com",
        "time": "Fri Aug 07 17:52:30 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 07 17:52:30 2026"
      },
      "message": "Use ASSERT_STREQ for testing ExtractSourceFromModule results (#6600)\n\nIn case of a mismatch,\n[`ASSERT_STREQ`](https://google.github.io/googletest/reference/assertions.html#EXPECT_STREQ)\nactually prints both strings. Example:\n\n```\n/build/source/test/tools/objdump/extract_source_test.cpp:223: Failure Expected equality of these values:\n  resStr.c_str()\n    Which is: \"diovmoc etup}{)(\"\n  \"void compute(){}\"\n```\n\n---\n\nThis makes it easier to see that SPIRV-Tools has a similar issue as\nhttps://github.com/KhronosGroup/glslang/issues/4145, where parsing on\nbig-endian gives either seemingly no/incomplete results, or results\nwhere strings are partially reversed."
    },
    {
      "commit": "28d05cf1a2591e05565d03435216cb6c19da0c43",
      "tree": "6d6ed795d6a0c0878ddc5c5d4d3a733be5e12757",
      "parents": [
        "5b5a25231a3543559b4f2cb27fe725a08b76b5d0"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Aug 07 17:34:34 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 07 17:34:34 2026"
      },
      "message": "kokoro: fix linux-gcc-gn build (#6831)\n\n- fix creation of deep build dir\n- Generalize the chown in the wrapper script to cover all dirs\n      that might be generated during the build."
    },
    {
      "commit": "5b5a25231a3543559b4f2cb27fe725a08b76b5d0",
      "tree": "d4a9d46289b4b6a7aeabe85e6c88bd699d9aec75",
      "parents": [
        "f589ef005c49f6f19c8e78eb5269104ba293beb4"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Thu Aug 06 22:03:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 06 22:03:29 2026"
      },
      "message": "kokoro: set up a linux-gcc-gn build (#6829)\n\nUpdate .gitignore to ignore files generated during local GN builds\n\nUpdate DEPS, GN scripting, standalone gclient client file\n\nSupport manually testing the linux kokoro scripts with podman.\n- In kokoro/scripts/linux/build-docker.sh: Only set up the artifacts\nvolume mapping when the corresponding Kokoro environment variable is\nset. Otherwise podman will fail to launch the container.\n\ngit-sync-deps: understand enhanced DEPS file\n    \n    - Add --prefix argument to filter the subdirs we care about.\n      SPIRV-Tools Cmake builds will only want --prefix\u003dexternal\n    - Warn that git-sync-deps will not checkout cipd or gcs dependencies\n      Warn insted of erroring so that it\u0027s harmless to *not* supply\n      the --prefix option\n   \n\nIssue: #2810"
    },
    {
      "commit": "f589ef005c49f6f19c8e78eb5269104ba293beb4",
      "tree": "06f8dbd2c150a75c5eca4c4884858556e72a32ff",
      "parents": [
        "98098e9b977d7b3af73822a86f86447c8360eb50"
      ],
      "author": {
        "name": "Jeff Bolz",
        "email": "jbolz@nvidia.com",
        "time": "Wed Aug 05 20:10:24 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 20:10:24 2026"
      },
      "message": "Validate SPV_EXT_cooperative_matrix_maintenance1 (#6825)\n\n\n\nExtension spec: https://github.com/KhronosGroup/SPIRV-Registry/pull/443\nSPIRV-Headers: https://github.com/KhronosGroup/SPIRV-Headers/pull/621"
    },
    {
      "commit": "98098e9b977d7b3af73822a86f86447c8360eb50",
      "tree": "a0e5fbc7841e69ad8e52b4c7f1a3a9a597f26c56",
      "parents": [
        "1c336172641682bab6e066767d09fdff1d826467"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Aug 05 20:09:22 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 20:09:22 2026"
      },
      "message": "opt: Filter duplicate decorations during serialization (#6828)\n\nAdd a mechanism to filter out duplicate decorations when writing the\nSPIR-V module back to binary in Module::ToBinary. This prevents\nvalidation\nerrors when optimization passes (like loop unrolling) duplicate\ndecorated\ninstructions.\n\nThe filtering uses a hash set of serialized instructions to identify and\nskip duplicates.\n\nA new parameter `filter_duplicates` is added to `Module::ToBinary` to\nallow disabling this behavior, which is used during the optimizer\u0027s\nintegrity check to prevent false positive assertion failures.\n\nAdded unit test in `module_test.cpp` to verify the behavior.\n\nAssisted by: Antigravity\n\nFixes: https://github.com/microsoft/DirectXShaderCompiler/issues/8609"
    },
    {
      "commit": "1c336172641682bab6e066767d09fdff1d826467",
      "tree": "10817ebf67a280968e7ff0fde72dcb1e7e3122a9",
      "parents": [
        "d993bcfafa3c6dd9c0ba0560ae1456a62fd78e07"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Aug 05 18:11:27 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:11:27 2026"
      },
      "message": "opt: Fix invalid OpSelect folding in spirv-opt (#6827)\n\nMergeBinaryOpSelect rule was folding binary operations with select\ninstructions even when the result was a vector and the condition was\nscalar, which is only valid in SPIR-V 1.4+. This change restricts\nthis folding in SPIR-V versions prior to 1.4.\n\nAssisted by: Antigravity\n\nFixes https://github.com/microsoft/DirectXShaderCompiler/issues/8603"
    },
    {
      "commit": "d993bcfafa3c6dd9c0ba0560ae1456a62fd78e07",
      "tree": "88c59871e88a347c9ed42bc21225c0d8e26ff118",
      "parents": [
        "a9cdf5bdd25d516294b5c25502b67e6116ed7eb5"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Aug 03 15:44:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 03 15:44:28 2026"
      },
      "message": "spirv-val: Add extra Heap ArrayStride test (#6818)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6739"
    },
    {
      "commit": "a9cdf5bdd25d516294b5c25502b67e6116ed7eb5",
      "tree": "cb12c4a2ee601552e307a7099d4ce1c692047f72",
      "parents": [
        "72bb45a352737ed691eb46b773a4685a63b4e047"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Thu Jul 30 22:32:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 30 22:32:12 2026"
      },
      "message": "Tighten relaxed layout alignments (#6819)\n\nFixes #6817\n\n* Relaxed block layout only applies to vectors directly in the struct\nand not through matrices nor arrays\n\nTested against CTS, no unexpected failures."
    },
    {
      "commit": "72bb45a352737ed691eb46b773a4685a63b4e047",
      "tree": "2293e5fcec9840a0d58a55a3077c96bfc0e044d9",
      "parents": [
        "5f62f05f5f1dac09f81af9f207e7ab6c82b3722e"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Thu Jul 30 20:38:34 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 30 20:38:34 2026"
      },
      "message": "[val] Fix crash evaluating \u003e64-bit integer constants in EvalConstantVal{Uint,Int}64 (#6816)"
    },
    {
      "commit": "5f62f05f5f1dac09f81af9f207e7ab6c82b3722e",
      "tree": "730d9d0924d3e312dff83f400ed33e74a9fb01e0",
      "parents": [
        "4d6dad6f8bf6ce5f12cf57d198b2fb817be7fb68"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Tue Jul 28 20:48:42 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 20:48:42 2026"
      },
      "message": "[val] Restrict Workgroup scope to OpGroupNonUniformRotateKHR only (#6811)\n\nOther non-uniform group operations were incorrectly allowed to use\nWorkgroup execution scope in the general SPIR-V rule check, only\nOpGroupNonUniformRotateKHR permits it\n\nAlso fix the matching Vulkan execution scope check, which was missing\nthe same exclusion"
    },
    {
      "commit": "4d6dad6f8bf6ce5f12cf57d198b2fb817be7fb68",
      "tree": "bc1d47743371b7bf996bc8cbeefc5861aac5e630",
      "parents": [
        "a665e21f3061f34064b39937cf00fe8d8769f4ef"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Tue Jul 28 19:39:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 19:39:10 2026"
      },
      "message": "[val] Explicit layout refactor (#6792)\n\nFixes #6780\n\n* Combine layout checks into a single pass to share logic\n  * checks both required explicit layouts and invalid layouts\n  * remove checks from validate_decorations.cpp\n* Introduce enums for layout modes and requirements\n* Centralize which instructions are examined for layouts\n* Add options to specify descriptor sizes to the validator (buffer,\nsampler, image, and tensor)"
    },
    {
      "commit": "a665e21f3061f34064b39937cf00fe8d8769f4ef",
      "tree": "d89db20fefe141eb08682d5cf807ee6584c156f6",
      "parents": [
        "3c96171c74ed289804c925b171b5234c73d5fdd0"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Jul 22 18:52:59 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 18:52:59 2026"
      },
      "message": "utils: Supress GCC array-bound warning (#6807)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6805\n\nWe do this same-ish thing in `source/utils/hex_floats.h` \n\nI looked, there was no changes to `timer.h` or `pass_manager.cpp` so not\nsure what this suddenly is happening, seems to just be something the\nlatest GCC is catching"
    },
    {
      "commit": "3c96171c74ed289804c925b171b5234c73d5fdd0",
      "tree": "01a340eb160bc6c525ee219ab06b3924c2840034",
      "parents": [
        "0d6fd73ca73830ccab5fa1f00ed5ed40124e2c55"
      ],
      "author": {
        "name": "Lurie97",
        "email": "109333972+Lurie97@users.noreply.github.com",
        "time": "Wed Jul 22 11:07:14 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 11:07:14 2026"
      },
      "message": "linker: detect duplicate exported definitions without imports (#6750)\n\nThe duplicate-export check in GetImportExportPairs() only triggers when\niterating over imports. If no module imports a symbol, the linker never\nlooks up the export table for that name, so multiple modules can each\nexport the same function and spvtools::Link() silently accepts them\ninstead of reporting a One Definition Rule violation.\n\nAdd a standalone pass over the exports map before the import-matching\nloop to reject links where the same symbol name is exported by more than\none module. This correctly handles LinkOnceODR symbols because they are\nalready deduplicated into a single export entry by the preceding\nlinkonce processing.\n\nFixes the piglit clLinkProgram test where two modules each define\nget_number() with Export linkage but neither imports it.\n\nSigned-off-by: jiajia Qian \u003cjiajia.qian@nxp.com\u003e"
    },
    {
      "commit": "0d6fd73ca73830ccab5fa1f00ed5ed40124e2c55",
      "tree": "48263520317e68d84346a3b71af0800ef622ae88",
      "parents": [
        "470d6931c170dafe9feb5a808f58df1f94779355"
      ],
      "author": {
        "name": "David Gilhooley",
        "email": "dgilhooley@google.com",
        "time": "Fri Jul 17 17:33:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 17:33:54 2026"
      },
      "message": "Fix build for LLVM\u0027s remove transitive includes (#6802)\n\nIn the latest LLVM roll this file requires the iterator header for\nstd::back_inserter\n\nI believe LLVM has recently removed transitive includes by default, see:\n\n\nhttps://github.com/llvm/llvm-project/commit/ce5b2e876494cb95f02d9f915081e2b8781e74d1"
    },
    {
      "commit": "470d6931c170dafe9feb5a808f58df1f94779355",
      "tree": "e3d8713ab0c0b47d7c193011526284b5185b4870",
      "parents": [
        "b0adb9bb1f24dfe5ad7d82a3b9890400cca2dd3f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 17 16:12:36 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 16:12:36 2026"
      },
      "message": "build(deps): bump the github-actions group with 2 updates (#6801)\n\nBumps the github-actions group with 2 updates:\n[lukka/get-cmake](https://github.com/lukka/get-cmake) and\n[github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\nUpdates `lukka/get-cmake` from 4.3.4 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/releases\"\u003elukka/get-cmake\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eCMake v4.4.0\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003eget-cmake\u003c/code\u003e action downloads and caches CMake and\nNinja on your workflows. Versions can be specified using \u003ca\nhref\u003d\"https://docs.npmjs.com/about-semantic-versioning\"\u003esemantic\nversioning ranges\u003c/a\u003e using \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L13\"\u003e\u003ccode\u003ecmakeVersion\u003c/code\u003e\u003c/a\u003e\nand \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L16\"\u003e\u003ccode\u003eninjaVersion\u003c/code\u003e\u003c/a\u003e\ninputs.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elatest\u003c/code\u003e is now using CMake version \u003ccode\u003ev4.4.0\u003c/code\u003e,\nuse this one-liner e.g.:\n\u003ccode\u003euses: lukka/get-cmake@latest\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eEnjoy!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/e6906078ebd1ccb8ce51ab4626ac46a1b5a517e3\"\u003e\u003ccode\u003ee690607\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/80ed063af494e28dd56b85fb7a630f2f8f55ceed\"\u003e\u003ccode\u003e80ed063\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-rc-v4.4.0-rc3\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/f5b8fbb4d77cec1acc5a5f9f0df4beffaf5d98d9...e6906078ebd1ccb8ce51ab4626ac46a1b5a517e3\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.37.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUpcoming breaking change\u003c/em\u003e: Add a deprecation warning for\ncustomers using CodeQL version 2.20.6 and earlier. These versions of\nCodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise\nServer 3.16, and will be unsupported by the next minor release of the\nCodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3956\"\u003e#3956\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1\"\u003e2.26.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4019\"\u003e#4019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.37.1 - 16 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUpcoming breaking change\u003c/em\u003e: Add a deprecation warning for\ncustomers using CodeQL version 2.20.6 and earlier. These versions of\nCodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise\nServer 3.16, and will be unsupported by the next minor release of the\nCodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3956\"\u003e#3956\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1\"\u003e2.26.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/4019\"\u003e#4019\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.0 - 08 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0\"\u003e2.26.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3995\"\u003e#3995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIn addition to the existing input format, the\n\u003ccode\u003econfig-file\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e\nstep will soon support a new \u003ccode\u003e[owner/]repo[@ref][:path]\u003c/code\u003e\nformat. All components except the repository name are optional. If\nomitted, \u003ccode\u003eowner\u003c/code\u003e defaults to the same owner as the repository\nthe analysis is running for, \u003ccode\u003eref\u003c/code\u003e to \u003ccode\u003emain\u003c/code\u003e, and\n\u003ccode\u003epath\u003c/code\u003e to \u003ccode\u003e.github/codeql-action.yaml\u003c/code\u003e. Support\nfor this format ships in this version of the CodeQL Action, but will\nonly be enabled over the coming weeks. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3973\"\u003e#3973\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.36.3 - 01 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.36.2 - 04 Jun 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCache CodeQL CLI version information across Actions steps. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3943\"\u003e#3943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduce requests while waiting for analysis processing by using\nexponential backoff when polling SARIF processing status. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3937\"\u003e#3937\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6\"\u003e2.25.6\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3948\"\u003e#3948\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.36.1 - 02 Jun 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.36.0 - 22 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eBreaking change\u003c/em\u003e: Bump the minimum required CodeQL bundle\nversion to 2.19.4. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3894\"\u003e#3894\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for SHA-256 Git object IDs. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3893\"\u003e#3893\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5\"\u003e2.25.5\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3926\"\u003e#3926\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.5 - 15 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eWe have improved how the JavaScript bundles for the CodeQL Action\nare generated to avoid duplication across bundles and reduce the size of\nthe repository by around 70%. This should have no effect on the runtime\nbehaviour of the CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3899\"\u003e#3899\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFor performance and accuracy reasons, \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e will now only be enabled on a pull request when\ndiff-informed analysis is also enabled for that run. If diff-informed\nanalysis is unavailable (for example, because the PR diff ranges could\nnot be computed), the action will fall back to a full analysis. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3791\"\u003e#3791\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIf multiple inputs are provided for the GitHub-internal\n\u003ccode\u003eanalysis-kinds\u003c/code\u003e input, only \u003ccode\u003ecode-scanning\u003c/code\u003e will\nbe enabled. The \u003ccode\u003eanalysis-kinds\u003c/code\u003e input is experimental, for\nGitHub-internal use only, and may change without notice at any time. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3892\"\u003e#3892\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which, when running a Code Scanning\nanalysis for a PR with \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e enabled, prefers CodeQL CLI versions that have\na cached overlay-base database for the configured languages. This speeds\nup analysis for a repository when there is not yet a cached overlay-base\ndatabase for the latest CLI version. We expect to roll this change out\nto everyone in May. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3880\"\u003e#3880\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.4 - 07 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.4\"\u003e2.25.4\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3881\"\u003e#3881\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.3 - 01 May 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/7188fc363630916deb702c7fdcf4e481b751f97a\"\u003e\u003ccode\u003e7188fc3\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4020\"\u003e#4020\u003c/a\u003e\nfrom github/update-v4.37.1-9e7c07009\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c8b5f69be686908c3dfd844428137d56fe80c936\"\u003e\u003ccode\u003ec8b5f69\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.37.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/9e7c070092090e89e8b3d62f977d4456e0732cd7\"\u003e\u003ccode\u003e9e7c070\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4014\"\u003e#4014\u003c/a\u003e\nfrom github/mbg/explicit-remote-prefix\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3492b7e9ab96e28b1d8b971345d30e929c6f8fee\"\u003e\u003ccode\u003e3492b7e\u003c/code\u003e\u003c/a\u003e\nChange \u003ccode\u003eREMOTE_PATH_PREFIX\u003c/code\u003e to \u003ccode\u003eremote\u003d\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3654baa924bc6456db54002581cb7c1c877548c4\"\u003e\u003ccode\u003e3654baa\u003c/code\u003e\u003c/a\u003e\nMerge remote-tracking branch \u0027origin/main\u0027 into\nmbg/explicit-remote-prefix\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/2d682ac05f1b3588aaff3814826bede39b9ba6bb\"\u003e\u003ccode\u003e2d682ac\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4017\"\u003e#4017\u003c/a\u003e\nfrom github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/23f6a50753a88efd9b7ae8687b29f6bdb65f6250\"\u003e\u003ccode\u003e23f6a50\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4009\"\u003e#4009\u003c/a\u003e\nfrom github/mbg/action-state/additions\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/1ee3c75d1988ab8621f01ebb165115c38d56df91\"\u003e\u003ccode\u003e1ee3c75\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4018\"\u003e#4018\u003c/a\u003e\nfrom github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/e053684dc500899b0b5520edc8549ac0f1ed730b\"\u003e\u003ccode\u003ee053684\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4015\"\u003e#4015\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/npm-minor-fd2e83...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/6803c5671d2f87a83ed96e151c441b1cb3bdc66a\"\u003e\u003ccode\u003e6803c56\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/4019\"\u003e#4019\u003c/a\u003e\nfrom github/update-bundle/codeql-bundle-v2.26.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...7188fc363630916deb702c7fdcf4e481b751f97a\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b0adb9bb1f24dfe5ad7d82a3b9890400cca2dd3f",
      "tree": "1774de765b08313263f59f81dc43ccb8c152ddb7",
      "parents": [
        "d34072656009319e6c39368121d6cba4a790b889"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Jul 17 15:30:23 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 15:30:23 2026"
      },
      "message": "Roll external/abseil_cpp/ cd1253229..c34b14912 (6 commits) (#6800)\n\nhttps://github.com/abseil/abseil-cpp/compare/cd1253229e7d...c34b1491291f\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "d34072656009319e6c39368121d6cba4a790b889",
      "tree": "97a4936cf351923aea5441ff023be7c4ee0a0d7d",
      "parents": [
        "70588424c5dee17893561734cfa470af115bcdd7"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Jul 16 17:59:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:59:35 2026"
      },
      "message": "opt: Fix invalid vector constant folding size (#6798)\n\nUse the actual vector component count instead of hardcoding 4\ncomponents when folding self-division of vectors in\nGetConstantUniformValue and FoldFMix.\n\nFixes #6794"
    },
    {
      "commit": "70588424c5dee17893561734cfa470af115bcdd7",
      "tree": "898dfebb9aa571afb51d5cf8fd31b10e65a6ef15",
      "parents": [
        "19b6261c8ed42da0f48c4aa6e92d0a6c0ff8b868"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Jul 16 17:09:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:09:12 2026"
      },
      "message": "Fix UAF in eliminate dead functions (#6799)\n\nDo not collect DebugLine instructions when collecting the non-semantic\ntree of instructions to kill."
    },
    {
      "commit": "19b6261c8ed42da0f48c4aa6e92d0a6c0ff8b868",
      "tree": "4c25f0478f8716e184be89ef482c0d3999b3102d",
      "parents": [
        "4f97d7dbadc0bd7344515042611c3fd4f381063e"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Jul 16 17:00:56 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:00:56 2026"
      },
      "message": "opt: Fix crash in strip-debug with non-semantic info (#6797)\n\nClears the DebugScope of all instructions during StripDebugInfoPass to\nprevent out-of-bounds assertions when writing back instructions that\nreference dead debug instructions.\n\nAlso resets the FeatureManager when OpExtInstImport is killed to\nmaintain\ncontext consistency if imports are removed by other passes.\n\nAdds a unit test to verify the fix.\n\nFixes #6796\n\nAssisted-by: Antigravity"
    },
    {
      "commit": "4f97d7dbadc0bd7344515042611c3fd4f381063e",
      "tree": "95a5d94d16182a3526700257921693987c242376",
      "parents": [
        "58dc0b3eb014f6ad4677177ef7ed03214e647d8b"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 12:49:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 12:49:10 2026"
      },
      "message": "roll deps (#6795)\n\n- **Roll external/abseil_cpp/ 49ea0f955..e6a287bfb (3 commits)**\n- **Roll external/mimalloc/ fef6b0dd7..76d3f8a93 (35 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "58dc0b3eb014f6ad4677177ef7ed03214e647d8b",
      "tree": "9d08a071651d4cf2ad742d201dd01f0f18d2c551",
      "parents": [
        "6ab70dc1940e8d1272cb497ccfa832aaacf6afe8"
      ],
      "author": {
        "name": "Wooyoung Kim",
        "email": "wooykim@qti.qualcomm.com",
        "time": "Tue Jul 14 21:23:14 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 21:23:14 2026"
      },
      "message": "Add the VUID-StandaloneSpirv-OpControlBarrierArriveEXT-13553 check (#6782)\n\nAdd the VUID-StandaloneSpirv-OpControlBarrierArriveEXT-13553 check\n(#6771)"
    },
    {
      "commit": "6ab70dc1940e8d1272cb497ccfa832aaacf6afe8",
      "tree": "7449878040db7e89126c46569d268736ccf91055",
      "parents": [
        "a153275e548fcbbcfcb5fababd5025108571364e"
      ],
      "author": {
        "name": "Steve Urquhart",
        "email": "53908460+SteveUrquhart@users.noreply.github.com",
        "time": "Tue Jul 14 20:54:06 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 20:54:06 2026"
      },
      "message": "opt: dissolve OpCopyLogical of OpCompositeConstruct in simplification (#6746)\n\nAs described in\nhttps://github.com/microsoft/DirectXShaderCompiler/issues/8382, this PR\nadds a new folding rule to deal with the new SPIR-V the optimizer is\nreceiving from dxc since\nhttps://github.com/microsoft/DirectXShaderCompiler/pull/7530. By\nrewriting\n```\n %0 \u003d OpCompositeConstruct %SrcStruct c0 c1 ... cN\n %1 \u003d OpCopyLogical        %DstStruct %0\n```\nas\n```\n %1 \u003d OpCompositeConstruct %DstStruct c0\u0027 c1\u0027 ... cN\u0027\n```\n...we can continue to legalize the technically-invalid\n```\n%cc \u003d OpCompositeConstruct %ResHolder_block %resourceVar\n```\n...which dxc has always emitted."
    },
    {
      "commit": "a153275e548fcbbcfcb5fababd5025108571364e",
      "tree": "bfe54edd31a49781ef3adb175fd078d41c297666",
      "parents": [
        "2ccac9471c670b6ad555814de0dd750261ddc8ae"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 16:00:11 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 16:00:11 2026"
      },
      "message": "roll deps (#6793)\n\n- **Roll external/googletest/ 8240fa7d6..f132c8931 (3 commits)**\n- **Roll external/abseil_cpp/ db1bdc86e..49ea0f955 (27 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "2ccac9471c670b6ad555814de0dd750261ddc8ae",
      "tree": "9b3954da01a95de1725dcff27038a40427b4f0f6",
      "parents": [
        "3058f80e65b2cdfdfce62134087881ab222a08fb"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Tue Jul 14 14:47:40 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 14:47:40 2026"
      },
      "message": "Authenticate git push in autoroll (#6790)\n\nSetting persist-credentials to false broke git push in autoroll\nworkflow.\nThis is fixed by authenticate git push using GITHUB_TOKEN. Other changes\nwere made to clean up some warnings.\n\nTAG\u003dagy"
    },
    {
      "commit": "3058f80e65b2cdfdfce62134087881ab222a08fb",
      "tree": "fe7336363a5e45173e3a130093e1552ebbb4a995",
      "parents": [
        "85f222ec591863853ea603ce190ea508c7255568"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Mon Jul 13 22:23:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 22:23:10 2026"
      },
      "message": "[val] Count AliasScopeINTELMask/NoAliasINTELMask memory access words (#6791)"
    },
    {
      "commit": "85f222ec591863853ea603ce190ea508c7255568",
      "tree": "971a639d7377f66945d4e60057ce910b06b0e115",
      "parents": [
        "48097f650a9e0f0437921debe2f396654c956cc7"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Jul 10 16:28:32 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 16:28:32 2026"
      },
      "message": "spirv-opt: Fix IRContext analysis handling (#6765)\n\n1. Add more cases where invalidating on analysis imply invalidating\nothers.\n2. Remove early return limiting the consistenty checks. Tests are added\n   to catch issues like this again.\n3. Extend IRContext::IsConsistent() to verify kAnalysisDominatorAnalysis\nand\n   kAnalysisStructuredCFG analyses.\n\nAssisted by Antigravity"
    },
    {
      "commit": "48097f650a9e0f0437921debe2f396654c956cc7",
      "tree": "23ac02bc9d67e9aa5a628db44f5217069ccdbd85",
      "parents": [
        "502666433f77439bece5b4c5c7e67bff90af2350"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 15:15:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 15:15:35 2026"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 2 updates (#6775)\n\nBumps the github-actions group with 2 updates in the / directory:\n[actions/cache](https://github.com/actions/cache) and\n[github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\nUpdates `actions/cache` from 6.0.0 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003eactions/cache\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.1.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/cache\u003c/code\u003e to v6.1.0 - handle read-only cache\naccess by \u003ca\nhref\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e@​jasongin\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1768\"\u003eactions/cache#1768\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/v6...v6.1.0\"\u003ehttps://github.com/actions/cache/compare/v6...v6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e\nwith the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e\nsection.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by\nupdating the \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e\nfile with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed\nand merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e\nuse the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you\nmade in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca\nhref\u003d\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version\nnumber.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags\nfor this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e6.1.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v6.1.0 to pick up \u003ca\nhref\u003d\"https://redirect.github.com/actions/toolkit/pull/2435\"\u003eactions/toolkit#2435\nHandle cache write error due to read-only token\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch redundant \u0026quot;Cache save failed\u0026quot; warning to debug log\nin save-only\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e6.0.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated \u003ccode\u003e@actions/cache\u003c/code\u003e to ^6.0.1,\n\u003ccode\u003e@actions/core\u003c/code\u003e to ^3.0.1, \u003ccode\u003e@actions/exec\u003c/code\u003e to\n^3.0.0, \u003ccode\u003e@actions/io\u003c/code\u003e to ^3.0.2\u003c/li\u003e\n\u003cli\u003eMigrated to ESM module system\u003c/li\u003e\n\u003cli\u003eUpgraded Jest to v30 and test infrastructure to be ESM\ncompatible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar\npatterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb\nprotection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca\nhref\u003d\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9\"\u003e\u003ccode\u003e55cc834\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1768\"\u003e#1768\u003c/a\u003e\nfrom jasongin/readonly-cache\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337\"\u003e\u003ccode\u003ed8cd72f\u003c/code\u003e\u003c/a\u003e\nBump \u003ccode\u003e@​actions/cache\u003c/code\u003e to v6.1.0 - handle cache write error\ndue to RO token\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/2c8a9bd7457de244a408f35966fab2fb45fda9c8...55cc8345863c7cc4c66a329aec7e433d2d1c52a9\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action/upload-sarif\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.37.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0\"\u003e2.26.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3995\"\u003e#3995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIn addition to the existing input format, the\n\u003ccode\u003econfig-file\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e\nstep will soon support a new \u003ccode\u003e[owner/]repo[@ref][:path]\u003c/code\u003e\nformat. All components except the repository name are optional. If\nomitted, \u003ccode\u003eowner\u003c/code\u003e defaults to the same owner as the repository\nthe analysis is running for, \u003ccode\u003eref\u003c/code\u003e to \u003ccode\u003emain\u003c/code\u003e, and\n\u003ccode\u003epath\u003c/code\u003e to \u003ccode\u003e.github/codeql-action.yaml\u003c/code\u003e. Support\nfor this format ships in this version of the CodeQL Action, but will\nonly be enabled over the coming weeks. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3973\"\u003e#3973\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.36.3\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action/upload-sarif\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUpcoming breaking change\u003c/em\u003e: Add a deprecation warning for\ncustomers using CodeQL version 2.20.6 and earlier. These versions of\nCodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise\nServer 3.16, and will be unsupported by the next minor release of the\nCodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3956\"\u003e#3956\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.37.0 - 08 Jul 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0\"\u003e2.26.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3995\"\u003e#3995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIn addition to the existing input format, the\n\u003ccode\u003econfig-file\u003c/code\u003e input for the \u003ccode\u003ecodeql-action/init\u003c/code\u003e\nstep will soon support a new \u003ccode\u003e[owner/]repo[@ref][:path]\u003c/code\u003e\nformat. All components except the repository name are optional. If\nomitted, \u003ccode\u003eowner\u003c/code\u003e defaults to the same owner as the repository\nthe analysis is running for, \u003ccode\u003eref\u003c/code\u003e to \u003ccode\u003emain\u003c/code\u003e, and\n\u003ccode\u003epath\u003c/code\u003e to \u003ccode\u003e.github/codeql-action.yaml\u003c/code\u003e. Support\nfor this format ships in this version of the CodeQL Action, but will\nonly be enabled over the coming weeks. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3973\"\u003e#3973\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.36.3 - 01 Jul 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.36.2 - 04 Jun 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCache CodeQL CLI version information across Actions steps. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3943\"\u003e#3943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduce requests while waiting for analysis processing by using\nexponential backoff when polling SARIF processing status. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3937\"\u003e#3937\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6\"\u003e2.25.6\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3948\"\u003e#3948\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.36.1 - 02 Jun 2026\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.36.0 - 22 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eBreaking change\u003c/em\u003e: Bump the minimum required CodeQL bundle\nversion to 2.19.4. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3894\"\u003e#3894\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for SHA-256 Git object IDs. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3893\"\u003e#3893\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5\"\u003e2.25.5\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3926\"\u003e#3926\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.5 - 15 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eWe have improved how the JavaScript bundles for the CodeQL Action\nare generated to avoid duplication across bundles and reduce the size of\nthe repository by around 70%. This should have no effect on the runtime\nbehaviour of the CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3899\"\u003e#3899\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFor performance and accuracy reasons, \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e will now only be enabled on a pull request when\ndiff-informed analysis is also enabled for that run. If diff-informed\nanalysis is unavailable (for example, because the PR diff ranges could\nnot be computed), the action will fall back to a full analysis. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3791\"\u003e#3791\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIf multiple inputs are provided for the GitHub-internal\n\u003ccode\u003eanalysis-kinds\u003c/code\u003e input, only \u003ccode\u003ecode-scanning\u003c/code\u003e will\nbe enabled. The \u003ccode\u003eanalysis-kinds\u003c/code\u003e input is experimental, for\nGitHub-internal use only, and may change without notice at any time. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3892\"\u003e#3892\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which, when running a Code Scanning\nanalysis for a PR with \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e enabled, prefers CodeQL CLI versions that have\na cached overlay-base database for the configured languages. This speeds\nup analysis for a repository when there is not yet a cached overlay-base\ndatabase for the latest CLI version. We expect to roll this change out\nto everyone in May. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3880\"\u003e#3880\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.4 - 07 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.4\"\u003e2.25.4\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3881\"\u003e#3881\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.3 - 01 May 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUpcoming breaking change\u003c/em\u003e: Add a deprecation warning for\ncustomers using CodeQL version 2.19.3 and earlier. These versions of\nCodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise\nServer 3.15, and will be unsupported by the next minor release of the\nCodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3837\"\u003e#3837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConfigurations for private registries that use Cloudsmith or GCP\nOIDC are now accepted. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3850\"\u003e#3850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBest-effort connection tests for private registries now use\n\u003ccode\u003eGET\u003c/code\u003e requests instead of \u003ccode\u003eHEAD\u003c/code\u003e for better\ncompatibility with various registry implementations. For NuGet feeds,\nthe test is now always performed against the service index. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3853\"\u003e#3853\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug where two diagnostics produced within the same\nmillisecond could overwrite each other on disk, causing one of them to\nbe lost. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3852\"\u003e#3852\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/99df26d4f13ea111d4ec1a7dddef6063f76b97e9\"\u003e\u003ccode\u003e99df26d\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3996\"\u003e#3996\u003c/a\u003e\nfrom github/update-v4.37.0-c7c896d71\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/31c27074fda95256cda077009907f8a6022dd7c0\"\u003e\u003ccode\u003e31c2707\u003c/code\u003e\u003c/a\u003e\nAdd changenote for \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3973\"\u003e#3973\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/72df2181aac054d1f4b44264399d2aac12cf11c6\"\u003e\u003ccode\u003e72df218\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.37.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c7c896d71b3055d36f2aff93b16bcc6c69923b91\"\u003e\u003ccode\u003ec7c896d\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3995\"\u003e#3995\u003c/a\u003e\nfrom github/update-bundle/codeql-bundle-v2.26.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3f34ff0ea3f5153c96071437b7cbf71ea3757146\"\u003e\u003ccode\u003e3f34ff0\u003c/code\u003e\u003c/a\u003e\nAdd changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/43bec09f1dc368b430cab4b5d69799bc904079d1\"\u003e\u003ccode\u003e43bec09\u003c/code\u003e\u003c/a\u003e\nUpdate default bundle to codeql-bundle-v2.26.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f58f0d11ebf5dedd870fab2f999275f7602cfa46\"\u003e\u003ccode\u003ef58f0d1\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3973\"\u003e#3973\u003c/a\u003e\nfrom github/mbg/repo-props/config-file-shorthands\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/7dc37cbb5b3e37f0e1cd1f18b61e0ea849898fb8\"\u003e\u003ccode\u003e7dc37cb\u003c/code\u003e\u003c/a\u003e\nMerge remote-tracking branch \u0027origin/main\u0027 into\nmbg/repo-props/config-file-sh...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/8e22350a7e28c34c82a5a499fc241923301c2c4f\"\u003e\u003ccode\u003e8e22350\u003c/code\u003e\u003c/a\u003e\nThread \u003ccode\u003eActionState\u003c/code\u003e to \u003ccode\u003einitConfig\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/69c9e8c7d918cf2fee13b8b72fdde15883ff155b\"\u003e\u003ccode\u003e69c9e8c\u003c/code\u003e\u003c/a\u003e\nMark some \u003ccode\u003estatus-report\u003c/code\u003e imports as \u003ccode\u003etype\u003c/code\u003e-only\nto avoid circular dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...99df26d4f13ea111d4ec1a7dddef6063f76b97e9\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "502666433f77439bece5b4c5c7e67bff90af2350",
      "tree": "ad88cb319004b79ce1ece4836318b35f3e3c869f",
      "parents": [
        "6ef84b5c64c698487e2fc28a397157f28eb8422f"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Thu Jul 09 19:24:16 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 09 19:24:16 2026"
      },
      "message": "[val] Allow Generic casts to/from CodeSectionINTEL storage class (#6787)\n\nresolves https://github.com/KhronosGroup/SPIRV-Tools/issues/6700"
    },
    {
      "commit": "6ef84b5c64c698487e2fc28a397157f28eb8422f",
      "tree": "8019caaf5cfc29ce08ca6640af7e56ae0346f3a9",
      "parents": [
        "f877466a5d2a08685e746af5c859ed4ae469218f"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Thu Jul 09 15:58:58 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 09 15:58:58 2026"
      },
      "message": "[val] Do not reject OpExtInst for BFloat16/FP8 result types (#6734)\n\nNeeded for https://github.com/llvm/llvm-project/pull/202859"
    },
    {
      "commit": "f877466a5d2a08685e746af5c859ed4ae469218f",
      "tree": "416fb6c23d050707ddb9443f9c83338c2f5f25f1",
      "parents": [
        "b707790a898e44038547df54580022fc1cf89c3d"
      ],
      "author": {
        "name": "Wooyoung Kim",
        "email": "wooykim@qti.qualcomm.com",
        "time": "Thu Jul 09 15:07:27 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 09 15:07:27 2026"
      },
      "message": "SPV_QCOM_image_processing3 (#6672)\n\nValidation support for SPV_QCOM_image_processing3"
    },
    {
      "commit": "b707790a898e44038547df54580022fc1cf89c3d",
      "tree": "7fd17032635fe47f2f2050827b27bb2e5b3becab",
      "parents": [
        "48bd3e9d0c91be4aac0aa5f44dba7e8b97dbc154"
      ],
      "author": {
        "name": "Natalie Chouinard",
        "email": "sudonatalie@google.com",
        "time": "Wed Jul 08 19:46:47 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 19:46:47 2026"
      },
      "message": "Prepare release v2026.3 (#6784)\n\nRoll external/googletest/ 8b5333659..8240fa7d6 (8 commits)\n\nhttps://github.com/google/googletest/compare/8b53336594cc...8240fa7d62f7\n\nCreated with:\n  roll-dep external/googletest\n\nRoll external/abseil_cpp/ 35b9f25ba..db1bdc86e (37 commits)\n\nhttps://github.com/abseil/abseil-cpp/compare/35b9f25ba74a...db1bdc86effd\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nRoll external/spirv-headers/ 8d56066ee..29981f652 (3 commits)\n\n\nhttps://github.com/KhronosGroup/SPIRV-Headers/compare/8d56066eee52...29981f652416\n\nCreated with:\n  roll-dep external/spirv-headers"
    },
    {
      "commit": "48bd3e9d0c91be4aac0aa5f44dba7e8b97dbc154",
      "tree": "2e97d97d1dd7fa94f3d3eaeba1bf514439aa5b85",
      "parents": [
        "87a678a9c23b6ae5de8659d7f2639714e37b8b17"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Mon Jul 06 22:50:22 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 22:50:22 2026"
      },
      "message": "Use FloatEquals on one remaining float equality test (#6783)\n\nThis accommodates environments that warn on float point equality\ncomparisons."
    },
    {
      "commit": "87a678a9c23b6ae5de8659d7f2639714e37b8b17",
      "tree": "1b3b56e6bb22907b0c6105dbef006292cc71d14a",
      "parents": [
        "a14486e06742ee09bc7db68d3afa94ffe2d3f20c"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Jul 06 19:29:03 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 19:29:03 2026"
      },
      "message": "spirv-val: Fix OpBufferPointerEXT Explicit Layout (#6709)\n\nTaken out of https://github.com/KhronosGroup/SPIRV-Tools/pull/6701/files\nas we just approved\nhttps://gitlab.khronos.org/vulkan/vulkan/-/merge_requests/8305"
    },
    {
      "commit": "a14486e06742ee09bc7db68d3afa94ffe2d3f20c",
      "tree": "c8aaa0e9986a32295894ca923f831c8542f9ab1f",
      "parents": [
        "891df4cab0da905a9d22231b4e239552022911f0"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sat Jul 04 23:33:02 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 23:33:02 2026"
      },
      "message": "spirv-val: Add VUID for SPV_EXT_ocp_microscaling_types (#6779)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/6774"
    },
    {
      "commit": "891df4cab0da905a9d22231b4e239552022911f0",
      "tree": "c1e353a2ca5a5cf1c561864d0754907c750841fd",
      "parents": [
        "114d39f512d4c551e9499b8f057cc6b4e879cdb0"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Sat Jul 04 21:17:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 21:17:07 2026"
      },
      "message": "Fix array length validation (#6777)\n\nFixes https://crbug.com/oss-fuzz/529845250\n\n* Fix a segfault from nullptr deref when an operand with no type id is\npassed as the pointer operand"
    },
    {
      "commit": "114d39f512d4c551e9499b8f057cc6b4e879cdb0",
      "tree": "d8e664b7f005d2310ff8131fd75e6db96508facf",
      "parents": [
        "62fee34702d5cf1f862f54c6c2b0bb3994c6a1f7"
      ],
      "author": {
        "name": "Wooyoung Kim",
        "email": "wooykim@qti.qualcomm.com",
        "time": "Sat Jul 04 14:58:51 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 14:58:51 2026"
      },
      "message": "SPV_QCOM_multiple_wait_queues (#6671)"
    },
    {
      "commit": "62fee34702d5cf1f862f54c6c2b0bb3994c6a1f7",
      "tree": "8031bfe454d5d3cb189cae093f7b1b433ae784da",
      "parents": [
        "7fa1f024cf86890b2f9ac2aab19d0583cea59277"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Jul 03 22:23:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 22:23:07 2026"
      },
      "message": "hex-float: adapt to strict fp compilation options (#6778)\n\n- avoid implicit conversions from float to double\n- guard floating point equality checks with pragmas"
    },
    {
      "commit": "7fa1f024cf86890b2f9ac2aab19d0583cea59277",
      "tree": "cf34ced72175a5e6a5eef36482bc25117bc2857b",
      "parents": [
        "667f063adc0236664519d72d3f6d9ffd08afc757"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Jul 03 16:50:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 16:50:28 2026"
      },
      "message": "assembler, disassembler support fo SPV_QCOM_image_processing3 (#6776)\n\nAddes new operand type SPV_OPERAND_TYPE_GATHER_MODES. This is not\nactually used since the gather mode operand is provided as an ID."
    },
    {
      "commit": "667f063adc0236664519d72d3f6d9ffd08afc757",
      "tree": "3fc5940cde3eb79bab38a5fd4037ba66cc60c65a",
      "parents": [
        "f80351511e9c4672e284842c7b124315c511078a"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Thu Jul 02 20:10:39 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 02 20:10:39 2026"
      },
      "message": "bazel: bump bazel_dep versions to latest releases (#6773)"
    },
    {
      "commit": "f80351511e9c4672e284842c7b124315c511078a",
      "tree": "2d4f8c769fca1d8f154e3a93bc460fe8f67d430e",
      "parents": [
        "cbcd15add9bac4c652203f05f159a13cb7cd652d"
      ],
      "author": {
        "name": "Kévin Petit",
        "email": "kevin.petit@arm.com",
        "time": "Thu Jul 02 19:31:17 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 02 19:31:17 2026"
      },
      "message": "Add support for SPV_EXT_ocp_microscaling_types (#6772)\n\nCo-authored-by: Kevin Petit \u003ckevin.petit@arm.com\u003e\nCo-authored-by: Guillaume Trebuchet \u003cguillaume.trebuchet@arm.com\u003e\n\n---------\n\nSigned-off-by: Kevin Petit \u003ckevin.petit@arm.com\u003e\nSigned-off-by: Guillaume Trebuchet \u003cguillaume.trebuchet@arm.com\u003e\nCo-authored-by: David Neto \u003cdneto@google.com\u003e"
    },
    {
      "commit": "cbcd15add9bac4c652203f05f159a13cb7cd652d",
      "tree": "51d89401d68022a90b6d58d2c8c34573fe0c2db4",
      "parents": [
        "91e89a94297f63c81939023e03500031958df532"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Tue Jun 30 21:32:06 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 21:32:06 2026"
      },
      "message": "github workflows: tighten security (#6770)\n\n- don\u0027t persist credentials when using actions/checkout\n- use GITHUB_REF_NAME instead of github.ref_name expansion.\n\n\ncrbug.com/529861263"
    },
    {
      "commit": "91e89a94297f63c81939023e03500031958df532",
      "tree": "9923ae16a1fce74b63815e3d0ef401934deab29e",
      "parents": [
        "d5bbf95d87dd6d2694fbf09acfb42a00c93575e8"
      ],
      "author": {
        "name": "Viktoria Maximova",
        "email": "viktoria.maksimova@intel.com",
        "time": "Tue Jun 30 13:04:55 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 13:04:55 2026"
      },
      "message": "[val] Allow untyped access chains in OpSpecConstantOp (#6768)\n\nSPV_KHR_untyped_pointers allows the following opcodes to be used in\n`OpSpecConstantOp` with the `Kernel` capability:\n* `OpUntypedAccessChainKHR`\n* `OpUntypedInBoundsAccessChainKHR`\n* `OpUntypedPtrAccessChainKHR`\n* `OpUntypedInBoundsPtrAccessChainKHR`\n\nContributes to #6564"
    },
    {
      "commit": "d5bbf95d87dd6d2694fbf09acfb42a00c93575e8",
      "tree": "9383c2e74373c0ec141996dba93c0edf8e1ed518",
      "parents": [
        "f25a3b067eed21f6ce43186942eec3c407cade02"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Jun 29 13:21:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 13:21:29 2026"
      },
      "message": "Roll external/abseil_cpp/ 0300f0d67..35b9f25ba (6 commits) (#6766)\n\nhttps://github.com/abseil/abseil-cpp/compare/0300f0d679b2...35b9f25ba74a\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "f25a3b067eed21f6ce43186942eec3c407cade02",
      "tree": "0b2d2c23766f803d5b6923c22f0b0a8451d1969c",
      "parents": [
        "eb5b9970f54bdc56ee957cf4b1306ed8dcb7af4c"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Jun 26 18:49:34 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 18:49:34 2026"
      },
      "message": "spirv-opt: Invalidate analyses in DeadBranchElimPass (#6764)\n\nInvalidate kAnalysisCFG, kAnalysisDominatorAnalysis, and\nkAnalysisStructuredCFG\nanalyses when DeadBranchElimPass makes changes to basic blocks. This\nforces\nFixBlockOrder() to rebuild them rather than using stale caches\ncontaining\ndeleted basic block references.\n\nFixes #6632"
    },
    {
      "commit": "eb5b9970f54bdc56ee957cf4b1306ed8dcb7af4c",
      "tree": "abf26f5f38e98d287c3cbb782161b9bc77683c56",
      "parents": [
        "74d3c74c919298b1a5b7f6f1083d0d4b28c7ac2d"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Jun 26 17:34:50 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 17:34:50 2026"
      },
      "message": "Fix unbounded memory usage in FriendlyNameMapper (#6763)\n\nLimit the size of friendly names suggested by FriendlyNameMapper to a\nmaximum of 256 characters. Suggested names exceeding this limit will\nfall back to the string representation of the instruction ID to prevent\nOOM vulnerability caused by recursive OpTypeArray definitions.\n\nFixes #6756"
    },
    {
      "commit": "74d3c74c919298b1a5b7f6f1083d0d4b28c7ac2d",
      "tree": "c3a3bfda491434a29439d5e701da278d56942c87",
      "parents": [
        "a55f5cf60de9496372557836bc8ee5765ba7add1"
      ],
      "author": {
        "name": "jmestwa-coder",
        "email": "jmestwa@gmail.com",
        "time": "Fri Jun 26 13:36:13 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 13:36:13 2026"
      },
      "message": "cast to unsigned char before ctype calls on untrusted input (#6740)\n\nctype functions get a plain `char` that can be negative when the byte is\n\u003e\u003d 0x80, which is undefined for everything but unsigned char and EOF:\n- text.cpp `spvIsValidIDCharacter` and spirv_target_env.cpp version scan\nrun over raw assembly text\n- the spec-constant and sampled-image option parsers walk an arbitrary\n`const char*`\n- io.cpp hex tokenizer feeds file bytes straight into\nisspace/tolower/isxdigit\ncast each argument to unsigned char at the call site. hex_float.h\nalready does the right thing via istream::peek (returns int) so it is\nleft alone."
    },
    {
      "commit": "a55f5cf60de9496372557836bc8ee5765ba7add1",
      "tree": "3b452e775e3386df469109fa221b764d78f319b2",
      "parents": [
        "5befd211432adbde96c71b02037630b1e6ca1012"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 26 13:31:19 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 13:31:19 2026"
      },
      "message": "build(deps): bump actions/cache from 5.0.5 to 6.0.0 in the github-actions group across 1 directory (#6760)\n\nBumps the github-actions group with 1 update in the / directory:\n[actions/cache](https://github.com/actions/cache).\n\nUpdates `actions/cache` from 5.0.5 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003eactions/cache\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate packages, migrate to ESM by \u003ca\nhref\u003d\"https://github.com/Samirat\"\u003e\u003ccode\u003e@​Samirat\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1760\"\u003eactions/cache#1760\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/v5...v6.0.0\"\u003ehttps://github.com/actions/cache/compare/v5...v6.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e\nwith the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e\nsection.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by\nupdating the \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e\nfile with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed\nand merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e\nuse the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you\nmade in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca\nhref\u003d\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version\nnumber.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags\nfor this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e6.1.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v6.1.0 to pick up \u003ca\nhref\u003d\"https://redirect.github.com/actions/toolkit/pull/2435\"\u003eactions/toolkit#2435\nHandle cache write error due to read-only token\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSwitch redundant \u0026quot;Cache save failed\u0026quot; warning to debug log\nin save-only\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e6.0.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated \u003ccode\u003e@actions/cache\u003c/code\u003e to ^6.0.1,\n\u003ccode\u003e@actions/core\u003c/code\u003e to ^3.0.1, \u003ccode\u003e@actions/exec\u003c/code\u003e to\n^3.0.0, \u003ccode\u003e@actions/io\u003c/code\u003e to ^3.0.2\u003c/li\u003e\n\u003cli\u003eMigrated to ESM module system\u003c/li\u003e\n\u003cli\u003eUpgraded Jest to v30 and test infrastructure to be ESM\ncompatible\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar\npatterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb\nprotection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca\nhref\u003d\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8\"\u003e\u003ccode\u003e2c8a9bd\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1760\"\u003e#1760\u003c/a\u003e\nfrom actions/samirat/esm_migration_and_package_update\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023\"\u003e\u003ccode\u003ee9b91fd\u003c/code\u003e\u003c/a\u003e\nPrettier fixes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb\"\u003e\u003ccode\u003ee4884b8\u003c/code\u003e\u003c/a\u003e\nRebuild dist\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f\"\u003e\u003ccode\u003e10baf01\u003c/code\u003e\u003c/a\u003e\nFixed licenses\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37\"\u003e\u003ccode\u003ee39b386\u003c/code\u003e\u003c/a\u003e\nFix test mock return order\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06\"\u003e\u003ccode\u003eb692820\u003c/code\u003e\u003c/a\u003e\nPR feedback\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1\"\u003e\u003ccode\u003e6074912\u003c/code\u003e\u003c/a\u003e\nRebuild dist bundles as ESM to match type:module\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e\"\u003e\u003ccode\u003e5a912e8\u003c/code\u003e\u003c/a\u003e\nFix lint and jest issues\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/b9bf592b98b6a5d0cad9929c76247de1cac78abe\"\u003e\u003ccode\u003eb9bf592\u003c/code\u003e\u003c/a\u003e\nUpdate documentation for v6 release\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/80f777761d0990932f64ed2740522d7226a49062\"\u003e\u003ccode\u003e80f7777\u003c/code\u003e\u003c/a\u003e\nUpdate packages, migrate to ESM\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fccae...2c8a9bd7457de244a408f35966fab2fb45fda9c8\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5befd211432adbde96c71b02037630b1e6ca1012",
      "tree": "d05eb676b889ad87624f3692b6e6e04a106c5c12",
      "parents": [
        "7db050bf022d203df651f8daa3e4542fdc2a8aea"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Jun 26 12:34:10 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 12:34:10 2026"
      },
      "message": "Roll external/abseil_cpp/ 3b33f7fd5..0300f0d67 (2 commits) (#6761)\n\nhttps://github.com/abseil/abseil-cpp/compare/3b33f7fd5c9b...0300f0d679b2\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "7db050bf022d203df651f8daa3e4542fdc2a8aea",
      "tree": "388e9aa6898bc3950be09654ea58f505128798fa",
      "parents": [
        "f014211c2d16408ff9673b052de90ac4b1602fdc"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Jun 25 20:20:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 25 20:20:12 2026"
      },
      "message": "roll deps (#6759)\n\n- **Roll external/googletest/ 1fc11dea1..8b5333659 (2 commits)**\n- **Roll external/abseil_cpp/ 41253e45e..de672d07f (5 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "f014211c2d16408ff9673b052de90ac4b1602fdc",
      "tree": "e58db762e0e7a2e3a584ec40647bfebcfea0499f",
      "parents": [
        "12f9d942a7b19c039bbf2a18b84a36bb7b12664a"
      ],
      "author": {
        "name": "vperus",
        "email": "vperus@gmail.com",
        "time": "Tue Jun 23 19:02:22 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 23 19:02:22 2026"
      },
      "message": "disasm: Avoid copying string with passing by reference (#6757)\n\nChange from value to reference argument passing and store line string\nvalue in local value to avoid allocating memory twice."
    },
    {
      "commit": "12f9d942a7b19c039bbf2a18b84a36bb7b12664a",
      "tree": "32b21e04e75ea7cfac61a46ee6a8a4b7b108102a",
      "parents": [
        "58fe144fdc8847b303be51d4f8fcc9e7da17056e"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Tue Jun 23 14:48:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 23 14:48:28 2026"
      },
      "message": "roll deps (#6758)\n\n- **Roll external/googletest/ 0b1e895ba..1fc11dea1 (1 commit)**\n- **Roll external/abseil_cpp/ ce2e0bc69..41253e45e (3 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "58fe144fdc8847b303be51d4f8fcc9e7da17056e",
      "tree": "439ddb5950d1146c2c5a9d3274fbe7721c13ac7a",
      "parents": [
        "b9250830dd7aa056bb94464cd978a40564028cf2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 19 18:27:01 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 18:27:01 2026"
      },
      "message": "build(deps): bump the github-actions group with 2 updates (#6753)\n\nBumps the github-actions group with 2 updates:\n[actions/checkout](https://github.com/actions/checkout) and\n[lukka/get-cmake](https://github.com/lukka/get-cmake).\n\nUpdates `actions/checkout` from 6.0.3 to 7.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/releases\"\u003eactions/checkout\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eblock checking out fork pr for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the\nminor-actions-dependencies group across 1 directory by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and\n\u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3\nupdates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003egetting ready for checkout v7 release by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2464\"\u003eactions/checkout#2464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate error wording by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2467\"\u003eactions/checkout#2467\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/v6.0.3...v7.0.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/blob/main/CHANGELOG.md\"\u003eactions/checkout\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock checking out fork PR for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the\nminor-actions-dependencies group across 1 directory by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and\n\u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3\nupdates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePersist creds to a separate file by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2286\"\u003eactions/checkout#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README to include Node.js 24 support details and requirements\nby \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2248\"\u003eactions/checkout#2248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v5 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2301\"\u003eactions/checkout#2301\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions checkout to use node 24 by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2226\"\u003eactions/checkout#2226\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v4 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2305\"\u003eactions/checkout#2305\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README.md by \u003ca\nhref\u003d\"https://github.com/motss\"\u003e\u003ccode\u003e@​motss\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1971\"\u003eactions/checkout#1971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd internal repos for checking out multiple repositories by \u003ca\nhref\u003d\"https://github.com/mouismail\"\u003e\u003ccode\u003e@​mouismail\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1977\"\u003eactions/checkout#1977\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation update - add recommended permissions to Readme by \u003ca\nhref\u003d\"https://github.com/benwells\"\u003e\u003ccode\u003e@​benwells\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2043\"\u003eactions/checkout#2043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdjust positioning of user email note and permissions heading by \u003ca\nhref\u003d\"https://github.com/joshmgross\"\u003e\u003ccode\u003e@​joshmgross\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2044\"\u003eactions/checkout#2044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca\nhref\u003d\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2194\"\u003eactions/checkout#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate CODEOWNERS for actions by \u003ca\nhref\u003d\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2224\"\u003eactions/checkout#2224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate package dependencies by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2236\"\u003eactions/checkout#2236\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eurl-helper.ts\u003c/code\u003e now leverages well-known environment\nvariables by \u003ca href\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1941\"\u003eactions/checkout#1941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand unit test coverage for \u003ccode\u003eisGhes\u003c/code\u003e by \u003ca\nhref\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1946\"\u003eactions/checkout#1946\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCheck out other refs/* by commit if provided, fall back to ref by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1924\"\u003eactions/checkout#1924\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\"\u003e\u003ccode\u003e9c091bb\u003c/code\u003e\u003c/a\u003e\nupdate error wording (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2467\"\u003e#2467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a\"\u003e\u003ccode\u003e1044a6d\u003c/code\u003e\u003c/a\u003e\ngetting ready for checkout v7 release (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2464\"\u003e#2464\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f\"\u003e\u003ccode\u003ef028218\u003c/code\u003e\u003c/a\u003e\nBump the minor-npm-dependencies group across 1 directory with 3 updates\n(\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2462\"\u003e#2462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d\"\u003e\u003ccode\u003ed914b26\u003c/code\u003e\u003c/a\u003e\nupgrade module to esm and update dependencies (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2463\"\u003e#2463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d\"\u003e\u003ccode\u003e537c7ef\u003c/code\u003e\u003c/a\u003e\nBump \u003ccode\u003e@​actions/core\u003c/code\u003e and \u003ccode\u003e@​actions/tool-cache\u003c/code\u003e\nand Remove uuid (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2459\"\u003e#2459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6\"\u003e\u003ccode\u003e130a169\u003c/code\u003e\u003c/a\u003e\nBump js-yaml from 4.1.0 to 4.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2461\"\u003e#2461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3\"\u003e\u003ccode\u003e7d09575\u003c/code\u003e\u003c/a\u003e\nBump flatted from 3.3.1 to 3.4.2 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2460\"\u003e#2460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e\"\u003e\u003ccode\u003e0f9f3aa\u003c/code\u003e\u003c/a\u003e\nBump actions/publish-immutable-action (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2458\"\u003e#2458\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7\"\u003e\u003ccode\u003ef9e715a\u003c/code\u003e\u003c/a\u003e\nblock checking out fork pr for pull_request_target and workflow_run (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2454\"\u003e#2454\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lukka/get-cmake` from 4.3.3 to 4.3.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/f5b8fbb4d77cec1acc5a5f9f0df4beffaf5d98d9\"\u003e\u003ccode\u003ef5b8fbb\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.3.4cmake-rc-v4.4.0-rc2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/033b1fec76074854546b62b7082085c6c4666668\"\u003e\u003ccode\u003e033b1fe\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-rc-v4.4.0-rc1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/6d69ef55f2a444126e5f212d09cd8b390149194b\"\u003e\u003ccode\u003e6d69ef5\u003c/code\u003e\u003c/a\u003e\nBump peter-evans/create-pull-request from 7 to 8\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/591817e96fcad43505fb4eae36172462abb3a42e...f5b8fbb4d77cec1acc5a5f9f0df4beffaf5d98d9\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    }
  ],
  "next": "b9250830dd7aa056bb94464cd978a40564028cf2"
}
