added neo4j functions tests#3949
Conversation
This reverts commit be84308.
…penCypherAggregatingFunctionsComprehensiveTest.java Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
…penCypherAggregatingFunctionsComprehensiveTest.java Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
…tion.java Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 80 |
🟢 Coverage 88.74% diff coverage · -8.63% coverage variation
Metric Results Coverage variation ✅ -8.63% coverage variation Diff coverage ✅ 88.74% diff coverage Coverage variation details
Coverable lines Covered lines Coverage Common ancestor commit (4cb5061) 118612 87094 73.43% Head commit (e8507a7) 150156 (+31544) 97293 (+10199) 64.79% (-8.63%) Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch:
<coverage of head commit> - <coverage of common ancestor commit>Diff coverage details
Coverable lines Covered lines Diff coverage Pull request (#3949) 373 331 88.74% Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified:
<covered lines added or modified>/<coverable lines added or modified> * 100%
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes. Give us feedback
There was a problem hiding this comment.
Code Review
This pull request significantly expands OpenCypher function support, adding geospatial, vector, string, and temporal capabilities alongside comprehensive tests. Feedback focuses on aligning implementations with Cypher specifications, specifically for substring(), split(), and point.distance(). The review also identifies potential NullPointerException and NumberFormatException risks in edge cases and cautions against modifying shared SQL functions, like standard deviation, which could break standard SQL semantics.
| final Number z1n = (Number) p1.get("z"); | ||
| final Number z2n = (Number) p2.get("z"); | ||
| if (z1n != null && z2n != null) { | ||
| final double dz = z2n.doubleValue() - z1n.doubleValue(); | ||
| sumSq += dz * dz; | ||
| } |
There was a problem hiding this comment.
According to Cypher specifications (e.g., Neo4j), point.distance() should return null if the points have different dimensions (e.g., comparing a 2D point with a 3D point). The current implementation falls back to a 2D distance calculation if one of the points is missing the 'z' coordinate, which may lead to inconsistent results compared to standard Cypher behavior.
There was a problem hiding this comment.
Fixed. Added if ((z1n == null) != (z2n == null)) return null; before the z-distance calculation. Mixed 2D/3D Cartesian points now return null per Cypher spec. Added regression test pointDistanceMixedDimensions.
| if (variance != null) | ||
| return Math.sqrt((Double) variance); | ||
| return null; | ||
| return 0.0; |
There was a problem hiding this comment.
Changing the return value from null to 0.0 when the variance is null aligns with Cypher's stDev() behavior for empty sets, but it breaks standard SQL semantics where aggregate functions over an empty set (except COUNT) should return NULL. Since this class is part of the SQL function package, this change might cause regressions in SQL queries. Consider handling the null to 0.0 conversion in the Cypher-specific layer instead.
There was a problem hiding this comment.
The 0.0 return is intentional. The Cypher tests stDevNull and stDevPNull in OpenCypherAggregatingFunctionsComprehensiveTest explicitly assert 0.0 for stDev([null, null]), matching Neo4j's documented behavior. No SQL test currently asserts that stddev returns null on an empty/all-null set - the SQL test suite only covers non-empty datasets. Moving this to a Cypher layer would be a larger refactor beyond the scope of this PR.
| if (vectorObj instanceof String s) { | ||
| final String trimmed = s.trim(); | ||
| final String inner = trimmed.startsWith("[") && trimmed.endsWith("]") ? trimmed.substring(1, trimmed.length() - 1) : trimmed; | ||
| final String[] parts = inner.split(","); | ||
| final float[] result = new float[parts.length]; | ||
| for (int i = 0; i < parts.length; i++) | ||
| result[i] = Float.parseFloat(parts[i].trim()); | ||
| return result; | ||
| } |
There was a problem hiding this comment.
Parsing a vector from a string will fail with a NumberFormatException if the string represents an empty array (e.g., "[]"). In this case, inner becomes an empty string, and split(",") returns an array containing one empty string, which Float.parseFloat() cannot handle. An explicit check for an empty string after trimming and removing brackets should be added.
There was a problem hiding this comment.
Fixed. Added an inner.isEmpty() check before splitting - returns new float[0] for "[]" input, avoiding the NumberFormatException.
| final String str = args[0].toString(); | ||
| final int start = ((Number) args[1]).intValue(); | ||
| if (start < 0) |
There was a problem hiding this comment.
In Cypher, if the start index for substring() is negative, it is treated as 0. The current implementation throws a CommandExecutionException, which deviates from standard Cypher behavior. You should use Math.max(0, ...) for the start index instead of throwing an error.
| final String str = args[0].toString(); | |
| final int start = ((Number) args[1]).intValue(); | |
| if (start < 0) | |
| final int start = Math.max(0, ((Number) args[1]).intValue()); |
There was a problem hiding this comment.
Pushing back. The test substringNegativeStartRaisesError in OpenCypherStringFunctionsComprehensiveTest explicitly verifies that a negative start index raises an error. Neo4j 5.x also throws InvalidArgumentException for negative start values in substring(). The current behavior is intentional and tested.
- CypherPointDistanceFunction: null-check WGS-84 coordinate values before
calling doubleValue() to avoid NPE; return null for mixed 2D/3D Cartesian
points per Cypher spec
- VectorUtils: return empty float[] for empty array string "[]" instead of
throwing NumberFormatException
- CypherSplitFunction: use split limit -1 to preserve trailing empty strings
per Cypher spec (e.g. split('a,b,',',') -> ['a','b',''])
- Add regression tests for mixed-dimension point.distance() and trailing
delimiter split()
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
elementId() was implemented in createCypherSpecificExecutor but missing from isCypherSpecificFunction, causing an "Unknown function" error at runtime. Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #3949 +/- ##
==========================================
- Coverage 64.46% 63.85% -0.62%
==========================================
Files 1587 1591 +4
Lines 118612 118917 +305
Branches 25194 25271 +77
==========================================
- Hits 76468 75932 -536
- Misses 31548 32508 +960
+ Partials 10596 10477 -119 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
… 2.70.0 to 2.71.0 [skip ci] Bumps [com.google.api.grpc:proto-google-common-protos](https://github.com/googleapis/sdk-platform-java) from 2.70.0 to 2.71.0. Commits * [`6473668`](googleapis/sdk-platform-java@6473668) chore(main): release 2.63.0 ([#3927](https://redirect.github.com/googleapis/sdk-platform-java/issues/3927)) * [`8015e7e`](googleapis/sdk-platform-java@8015e7e) chore: update googleapis commit at Fri Oct 3 02:28:22 UTC 2025 ([#3923](https://redirect.github.com/googleapis/sdk-platform-java/issues/3923)) * [`48075a8`](googleapis/sdk-platform-java@48075a8) chore: Upper bound file deps change has chore type ([#3949](https://redirect.github.com/googleapis/sdk-platform-java/issues/3949)) * [`1d74663`](googleapis/sdk-platform-java@1d74663) deps: update google auth library dependencies to v1.40.0 ([#3945](https://redirect.github.com/googleapis/sdk-platform-java/issues/3945)) * [`7fb4f15`](googleapis/sdk-platform-java@7fb4f15) deps: Upgrade Google Http Java Client to v2.0.2 ([#3946](https://redirect.github.com/googleapis/sdk-platform-java/issues/3946)) * [`feabef3`](googleapis/sdk-platform-java@feabef3) feat(librariangen): add bazel package ([#3940](https://redirect.github.com/googleapis/sdk-platform-java/issues/3940)) * [`8d6c1f9`](googleapis/sdk-platform-java@8d6c1f9) deps: Bump Guava to v33.5.0 ([#3943](https://redirect.github.com/googleapis/sdk-platform-java/issues/3943)) * [`180b9a0`](googleapis/sdk-platform-java@180b9a0) build(deps): update dependency com.google.cloud:google-cloud-shared-config to... * [`3f548fb`](googleapis/sdk-platform-java@3f548fb) deps: update upper bound dependencies file ([#3947](https://redirect.github.com/googleapis/sdk-platform-java/issues/3947)) * [`a1b5ba3`](googleapis/sdk-platform-java@a1b5ba3) chore: Manage errorprone and j2objc versions in pom-parent ([#3948](https://redirect.github.com/googleapis/sdk-platform-java/issues/3948)) * Additional commits viewable in [compare view](googleapis/sdk-platform-java@gax/v2.70.0...gax/v2.71.0) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Co-authored-by: Pierre F <[email protected]> Co-authored-by: ExtReMLapin <[email protected]> Co-authored-by: CNE Pierre FICHEPOIL <[email protected]> (cherry picked from commit 582167a)
Bumps the github-actions group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) and [github/codeql-action](https://github.com/github/codeql-action). Updates `actions/checkout` from 6.0.2 to 6.0.3 Release notes *Sourced from [actions/checkout's releases](https://github.com/actions/checkout/releases).* > v6.0.3 > ------ > > What's Changed > -------------- > > * Update changelog by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2357](https://redirect.github.com/actions/checkout/pull/2357) > * fix: expand merge commit SHA regex and add SHA-256 test cases by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2414](https://redirect.github.com/actions/checkout/pull/2414) > * Fix checkout init for SHA-256 repositories by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2439](https://redirect.github.com/actions/checkout/pull/2439) > * Update changelog for v6.0.3 by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2446](https://redirect.github.com/actions/checkout/pull/2446) > > New Contributors > ---------------- > > * [`@yaananth`](https://github.com/yaananth) made their first contribution in [actions/checkout#2414](https://redirect.github.com/actions/checkout/pull/2414) > > **Full Changelog**: <actions/checkout@v6...v6.0.3> Changelog *Sourced from [actions/checkout's changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md).* > Changelog > ========= > > v6.0.3 > ------ > > * Fix checkout init for SHA-256 repositories by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2439](https://redirect.github.com/actions/checkout/pull/2439) > * fix: expand merge commit SHA regex and add SHA-256 test cases by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2414](https://redirect.github.com/actions/checkout/pull/2414) > > v6.0.2 > ------ > > * Fix tag handling: preserve annotations and explicit fetch-tags by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2356](https://redirect.github.com/actions/checkout/pull/2356) > > v6.0.1 > ------ > > * Add worktree support for persist-credentials includeIf by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2327](https://redirect.github.com/actions/checkout/pull/2327) > > v6.0.0 > ------ > > * Persist creds to a separate file by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2286](https://redirect.github.com/actions/checkout/pull/2286) > * Update README to include Node.js 24 support details and requirements by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2248](https://redirect.github.com/actions/checkout/pull/2248) > > v5.0.1 > ------ > > * Port v6 cleanup to v5 by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2301](https://redirect.github.com/actions/checkout/pull/2301) > > v5.0.0 > ------ > > * Update actions checkout to use node 24 by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2226](https://redirect.github.com/actions/checkout/pull/2226) > > v4.3.1 > ------ > > * Port v6 cleanup to v4 by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2305](https://redirect.github.com/actions/checkout/pull/2305) > > v4.3.0 > ------ > > * docs: update README.md by [`@motss`](https://github.com/motss) in [actions/checkout#1971](https://redirect.github.com/actions/checkout/pull/1971) > * Add internal repos for checking out multiple repositories by [`@mouismail`](https://github.com/mouismail) in [actions/checkout#1977](https://redirect.github.com/actions/checkout/pull/1977) > * Documentation update - add recommended permissions to Readme by [`@benwells`](https://github.com/benwells) in [actions/checkout#2043](https://redirect.github.com/actions/checkout/pull/2043) > * Adjust positioning of user email note and permissions heading by [`@joshmgross`](https://github.com/joshmgross) in [actions/checkout#2044](https://redirect.github.com/actions/checkout/pull/2044) > * Update README.md by [`@nebuk89`](https://github.com/nebuk89) in [actions/checkout#2194](https://redirect.github.com/actions/checkout/pull/2194) > * Update CODEOWNERS for actions by [`@TingluoHuang`](https://github.com/TingluoHuang) in [actions/checkout#2224](https://redirect.github.com/actions/checkout/pull/2224) > * Update package dependencies by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2236](https://redirect.github.com/actions/checkout/pull/2236) > > v4.2.2 > ------ > > * `url-helper.ts` now leverages well-known environment variables by [`@jww3`](https://github.com/jww3) in [actions/checkout#1941](https://redirect.github.com/actions/checkout/pull/1941) > * Expand unit test coverage for `isGhes` by [`@jww3`](https://github.com/jww3) in [actions/checkout#1946](https://redirect.github.com/actions/checkout/pull/1946) > > v4.2.1 > ------ > > * Check out other refs/\* by commit if provided, fall back to ref by [`@orhantoy`](https://github.com/orhantoy) in [actions/checkout#1924](https://redirect.github.com/actions/checkout/pull/1924) > > v4.2.0 > ------ > > * Add Ref and Commit outputs by [`@lucacome`](https://github.com/lucacome) in [actions/checkout#1180](https://redirect.github.com/actions/checkout/pull/1180) > * Dependency updates by [`@dependabot`](https://github.com/dependabot)- [actions/checkout#1777](https://redirect.github.com/actions/checkout/pull/1777), [actions/checkout#1872](https://redirect.github.com/actions/checkout/pull/1872) > > v4.1.7 > ------ > > * Bump the minor-npm-dependencies group across 1 directory with 4 updates by [`@dependabot`](https://github.com/dependabot) in [actions/checkout#1739](https://redirect.github.com/actions/checkout/pull/1739) > * Bump actions/checkout from 3 to 4 by [`@dependabot`](https://github.com/dependabot) in [actions/checkout#1697](https://redirect.github.com/actions/checkout/pull/1697) > * Check out other refs/\* by commit by [`@orhantoy`](https://github.com/orhantoy) in [actions/checkout#1774](https://redirect.github.com/actions/checkout/pull/1774) ... (truncated) Commits * [`df4cb1c`](actions/checkout@df4cb1c) Update changelog for v6.0.3 ([#2446](https://redirect.github.com/actions/checkout/issues/2446)) * [`1cce339`](actions/checkout@1cce339) Fix checkout init for SHA-256 repositories ([#2439](https://redirect.github.com/actions/checkout/issues/2439)) * [`900f221`](actions/checkout@900f221) fix: expand merge commit SHA regex and add SHA-256 test cases ([#2414](https://redirect.github.com/actions/checkout/issues/2414)) * [`0c366fd`](actions/checkout@0c366fd) Update changelog ([#2357](https://redirect.github.com/actions/checkout/issues/2357)) * See full diff in [compare view](actions/checkout@de0fac2...df4cb1c) Updates `anthropics/claude-code-action` from 1.0.133 to 1.0.140 Release notes *Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).* > v1.0.140 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.140> > > v1.0.139 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.139> > > v1.0.138 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.138> > > v1.0.137 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.137> > > v1.0.136 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.136> > > v1.0.135 > -------- > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.135> > > v1.0.134 > -------- > > What's Changed > -------------- > > * Add workload identity federation support to base-action by [`@ashwin-ant`](https://github.com/ashwin-ant) in [anthropics/claude-code-action#1378](https://redirect.github.com/anthropics/claude-code-action/pull/1378) > * chore: bump actions/setup-node from v4.4.0 to v6.4.0 (Node.js 24) by [`@ant-kurt`](https://github.com/ant-kurt) in [anthropics/claude-code-action#1377](https://redirect.github.com/anthropics/claude-code-action/pull/1377) > * ci: bump checkout and setup-bun in test workflows to Node 24 releases by [`@ant-kurt`](https://github.com/ant-kurt) in [anthropics/claude-code-action#1379](https://redirect.github.com/anthropics/claude-code-action/pull/1379) > > New Contributors > ---------------- > > * [`@ant-kurt`](https://github.com/ant-kurt) made their first contribution in [anthropics/claude-code-action#1377](https://redirect.github.com/anthropics/claude-code-action/pull/1377) > > **Full Changelog**: <anthropics/claude-code-action@v1...v1.0.134> Commits * [`fbda2eb`](anthropics/claude-code-action@fbda2eb) chore: bump Claude Code to 2.1.168 and Agent SDK to 0.3.168 * [`64de744`](anthropics/claude-code-action@64de744) chore: bump Claude Code to 2.1.167 and Agent SDK to 0.3.167 * [`4101658`](anthropics/claude-code-action@4101658) chore: bump Claude Code to 2.1.166 and Agent SDK to 0.3.166 * [`41ea764`](anthropics/claude-code-action@41ea764) chore: bump Claude Code to 2.1.165 and Agent SDK to 0.3.165 * [`0b1b620`](anthropics/claude-code-action@0b1b620) chore: bump Claude Code to 2.1.163 and Agent SDK to 0.3.163 * [`70a6e52`](anthropics/claude-code-action@70a6e52) chore: bump Claude Code to 2.1.162 and Agent SDK to 0.3.162 * [`36a69b6`](anthropics/claude-code-action@36a69b6) chore: bump Claude Code to 2.1.161 and Agent SDK to 0.3.161 * [`bfad70d`](anthropics/claude-code-action@bfad70d) ci: bump checkout and setup-bun in test workflows to Node 24 releases ([#1379](https://redirect.github.com/anthropics/claude-code-action/issues/1379)) * [`dc081a3`](anthropics/claude-code-action@dc081a3) chore: bump actions/setup-node from v4.4.0 to v6.4.0 (Node.js 24) ([#1377](https://redirect.github.com/anthropics/claude-code-action/issues/1377)) * [`420335d`](anthropics/claude-code-action@420335d) Add workload identity federation support to base-action ([#1378](https://redirect.github.com/anthropics/claude-code-action/issues/1378)) * Additional commits viewable in [compare view](anthropics/claude-code-action@787c5a0...fbda2eb) Updates `github/codeql-action` from 4.36.0 to 4.36.2 Release notes *Sourced from [github/codeql-action's releases](https://github.com/github/codeql-action/releases).* > v4.36.2 > ------- > > * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943) > * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937) > * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948) > > v4.36.1 > ------- > > No user facing changes. Changelog *Sourced from [github/codeql-action's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).* > CodeQL Action Changelog > ======================= > > See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs. > > [UNRELEASED] > ------------ > > No user facing changes. > > 4.36.2 - 04 Jun 2026 > -------------------- > > * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943) > * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937) > * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948) > > 4.36.1 - 02 Jun 2026 > -------------------- > > No user facing changes. > > 4.36.0 - 22 May 2026 > -------------------- > > * *Breaking change*: Bump the minimum required CodeQL bundle version to 2.19.4. [#3894](https://redirect.github.com/github/codeql-action/pull/3894) > * Add support for SHA-256 Git object IDs. [#3893](https://redirect.github.com/github/codeql-action/pull/3893) > * Update default CodeQL bundle version to [2.25.5](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5). [#3926](https://redirect.github.com/github/codeql-action/pull/3926) > > 4.35.5 - 15 May 2026 > -------------------- > > * We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. [#3899](https://redirect.github.com/github/codeql-action/pull/3899) > * For performance and accuracy reasons, [improved incremental analysis](https://redirect.github.com/github/roadmap/issues/1158) will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. [#3791](https://redirect.github.com/github/codeql-action/pull/3791) > * If multiple inputs are provided for the GitHub-internal `analysis-kinds` input, only `code-scanning` will be enabled. The `analysis-kinds` input is experimental, for GitHub-internal use only, and may change without notice at any time. [#3892](https://redirect.github.com/github/codeql-action/pull/3892) > * Added an experimental change which, when running a Code Scanning analysis for a PR with [improved incremental analysis](https://redirect.github.com/github/roadmap/issues/1158) enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. [#3880](https://redirect.github.com/github/codeql-action/pull/3880) > > 4.35.4 - 07 May 2026 > -------------------- > > * Update default CodeQL bundle version to [2.25.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.4). [#3881](https://redirect.github.com/github/codeql-action/pull/3881) > > 4.35.3 - 01 May 2026 > -------------------- > > * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. [#3837](https://redirect.github.com/github/codeql-action/pull/3837) > * Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. [#3850](https://redirect.github.com/github/codeql-action/pull/3850) > * Best-effort connection tests for private registries now use `GET` requests instead of `HEAD` for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. [#3853](https://redirect.github.com/github/codeql-action/pull/3853) > * Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. [#3852](https://redirect.github.com/github/codeql-action/pull/3852) > * Update default CodeQL bundle version to [2.25.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.3). [#3865](https://redirect.github.com/github/codeql-action/pull/3865) > > 4.35.2 - 15 Apr 2026 > -------------------- > > * The undocumented TRAP cache cleanup feature that could be enabled using the `CODEQL_ACTION_CLEANUP_TRAP_CACHES` environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the `trap-caching: false` input to the `init` Action. [#3795](https://redirect.github.com/github/codeql-action/pull/3795) > * The Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. [#3789](https://redirect.github.com/github/codeql-action/pull/3789) > * Python analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. [#3794](https://redirect.github.com/github/codeql-action/pull/3794) > * Fixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. [#3807](https://redirect.github.com/github/codeql-action/pull/3807) > * Update default CodeQL bundle version to [2.25.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2). [#3823](https://redirect.github.com/github/codeql-action/pull/3823) ... (truncated) Commits * [`8aad20d`](github/codeql-action@8aad20d) Merge pull request [#3949](https://redirect.github.com/github/codeql-action/issues/3949) from github/update-v4.36.2-dcb947ce1 * [`f521b08`](github/codeql-action@f521b08) Add additional changelog notes * [`8aeff0f`](github/codeql-action@8aeff0f) Update changelog for v4.36.2 * [`dcb947c`](github/codeql-action@dcb947c) Merge pull request [#3948](https://redirect.github.com/github/codeql-action/issues/3948) from github/update-bundle/codeql-bundle-v2.25.6 * [`c251bce`](github/codeql-action@c251bce) Add changelog note * [`62953c1`](github/codeql-action@62953c1) Update default bundle to codeql-bundle-v2.25.6 * [`423b570`](github/codeql-action@423b570) Merge pull request [#3946](https://redirect.github.com/github/codeql-action/issues/3946) from github/dependabot/npm\_and\_yarn/npm-minor-5d507a... * [`c35d1b1`](github/codeql-action@c35d1b1) Merge pull request [#3947](https://redirect.github.com/github/codeql-action/issues/3947) from github/dependabot/github\_actions/dot-github/wor... * [`cb1a588`](github/codeql-action@cb1a588) Merge pull request [#3937](https://redirect.github.com/github/codeql-action/issues/3937) from github/robertbrignull/waitForProcessing\_backoff * [`ba47406`](github/codeql-action@ba47406) Merge pull request [#3943](https://redirect.github.com/github/codeql-action/issues/3943) from github/henrymercer/cache-cli-version-info * Additional commits viewable in [compare view](github/codeql-action@7211b7c...8aad20d) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
What does this PR do?
pick #3428 , rebase it,