)]}'
{
  "log": [
    {
      "commit": "9e4fcbfd98669658e5f43f89c825738389ff925d",
      "tree": "38ab0581e8cb48efe5683b72a976cd884ad3376b",
      "parents": [
        "a02b50e4d4046c313bfd85ed5be41576925a42e0"
      ],
      "author": {
        "name": "Matt Sandy",
        "email": "msandy@google.com",
        "time": "Wed Jul 15 11:43:12 2026 -0700"
      },
      "committer": {
        "name": "Matt Sandy",
        "email": "msandy@google.com",
        "time": "Thu Jul 23 18:53:30 2026 -0700"
      },
      "message": "Reland \"Merge tag \u0027vulkan-sdk-1.4.350.1\u0027 into main\"\n\nThis is a reland of commit c6c58028313c7a46c9ad7661f21543e788b9cf57\n\nOriginal change\u0027s description:\n\u003e Merge tag \u0027vulkan-sdk-1.4.350.1\u0027 into main\n\u003e\n\u003e Bug: 510484520\n\u003e Change-Id: I14ecf0679e1a1468f39748261f2618fc365e2686\n\u003e Reviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1708910\n\u003e Reviewed-by: Craig Stout \u003ccstout@google.com\u003e\n\nBug: 510484520\nChange-Id: I9c143b1baac07e49a6e59f340fb3c4eda7588028\nReviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1721692\nReviewed-by: Craig Stout \u003ccstout@google.com\u003e\nSLSA-Policy-Verified: SLSA Policy Verification Service \u003cdevtools-gerritcodereview-exitgate@google.com\u003e\n"
    },
    {
      "commit": "a02b50e4d4046c313bfd85ed5be41576925a42e0",
      "tree": "6296ffd6861845c0d4f7a20762aa99536cdfb3c5",
      "parents": [
        "c6c58028313c7a46c9ad7661f21543e788b9cf57"
      ],
      "author": {
        "name": "Matt Sandy",
        "email": "msandy@google.com",
        "time": "Thu Jul 23 14:12:24 2026 -0700"
      },
      "committer": {
        "name": "fuchsia-internal-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "fuchsia-internal-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Thu Jul 23 14:18:28 2026 -0700"
      },
      "message": "Revert \"Merge tag \u0027vulkan-sdk-1.4.350.1\u0027 into main\"\n\nThis reverts commit c6c58028313c7a46c9ad7661f21543e788b9cf57.\n\nReason for revert: premature roller\n\nFailure Link: NA\n\nOriginal change\u0027s description:\n\u003e Merge tag \u0027vulkan-sdk-1.4.350.1\u0027 into main\n\u003e\n\u003e Bug: 510484520\n\u003e Change-Id: I14ecf0679e1a1468f39748261f2618fc365e2686\n\u003e Reviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1708910\n\u003e Reviewed-by: Craig Stout \u003ccstout@google.com\u003e\n\nBug: 510484520\nNo-Presubmit: true\nNo-Tree-Checks: true\nNo-Try: true\nChange-Id: I1821cdebc5bbf63fd81af17ecda5f6e1b92828b2\nReviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1721490\nSLSA-Policy-Verified: SLSA Policy Verification Service \u003cdevtools-gerritcodereview-exitgate@google.com\u003e\nExempt: android-build-ayeaye@system.gserviceaccount.com \u003candroid-build-ayeaye@system.gserviceaccount.com\u003e\nCommit-Queue: Matt Sandy \u003cmsandy@google.com\u003e\n"
    },
    {
      "commit": "c6c58028313c7a46c9ad7661f21543e788b9cf57",
      "tree": "38ab0581e8cb48efe5683b72a976cd884ad3376b",
      "parents": [
        "8f0ac7f1d6b64bf2fbe698dd0a75ec46a2de5623",
        "0539c81f69a3daeb706fd3477dca61435b475156"
      ],
      "author": {
        "name": "Matt Sandy",
        "email": "msandy@google.com",
        "time": "Wed Jul 15 11:43:12 2026 -0700"
      },
      "committer": {
        "name": "Matt Sandy",
        "email": "msandy@google.com",
        "time": "Thu Jul 23 13:21:51 2026 -0700"
      },
      "message": "Merge tag \u0027vulkan-sdk-1.4.350.1\u0027 into main\n\nBug: 510484520\nChange-Id: I14ecf0679e1a1468f39748261f2618fc365e2686\nReviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1708910\nReviewed-by: Craig Stout \u003ccstout@google.com\u003e\n"
    },
    {
      "commit": "8f0ac7f1d6b64bf2fbe698dd0a75ec46a2de5623",
      "tree": "6296ffd6861845c0d4f7a20762aa99536cdfb3c5",
      "parents": [
        "6bc1dd69eccfe11bafe2fccd92f3124640486dde"
      ],
      "author": {
        "name": "Aidan Wolter",
        "email": "awolter@google.com",
        "time": "Fri Jun 26 15:19:17 2026 +0000"
      },
      "committer": {
        "name": "fuchsia-internal-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "email": "fuchsia-internal-scoped@luci-project-accounts.iam.gserviceaccount.com",
        "time": "Mon Jun 29 14:06:36 2026 -0700"
      },
      "message": "[fuchsia] Avoid reading .git/HEAD in spvtools_build_version\n\nUpdate spvtools_build_version action to use git_paths.spirv_tools_head\nif in a Fuchsia build, instead of reading .git/HEAD directly.\nThis avoids build invalidation issues and errors in worktrees where\n.git/HEAD might not exist or be accessible in the same way.\n\nThe dependency on CHANGES and the git head are only added when building\ninside the Fuchsia tree, as this tracking is Fuchsia-specific (from\nfxr/558121) and not present upstream.\n\nWe now always redirect spvtools_software_version to build_version in the\ndefault toolchain, and define build_version only in the default\ntoolchain. This is a generic GN optimization that reduces build steps.\n\nTest: fx build (verified by temporarily adding target to default deps)\nBug: 527904737\nCONV: 1b469899-2276-4be4-a2bc-cb0de0f9b978\nChange-Id: Id2e4efe52e5800d497a67fe7745df8669ba4475a\nReviewed-on: https://fuchsia-review.googlesource.com/c/third_party/spirv-tools/+/1681952\nReviewed-by: Yilong Li \u003cliyl@google.com\u003e\nCommit-Queue: Aidan Wolter \u003cawolter@google.com\u003e\nFuchsia-Auto-Submit: Aidan Wolter \u003cawolter@google.com\u003e\n"
    },
    {
      "commit": "0539c81f69a3daeb706fd3477dca61435b475156",
      "tree": "4cb77a6eced2e1030f0623badfa05b2ab7d089fb",
      "parents": [
        "3605cce5b11f6a085107fd400f1721cd2a59c49e"
      ],
      "author": {
        "name": "Alan Harrison",
        "email": "33062996+AlanHarrisonAMD@users.noreply.github.com",
        "time": "Wed Apr 29 13:02:58 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 29 13:02:58 2026 -0400"
      },
      "message": "Handle OpAbortKHR in spvOpcodeIsAbort (#6661)"
    },
    {
      "commit": "3605cce5b11f6a085107fd400f1721cd2a59c49e",
      "tree": "f4a88e304f6d9d4823a13c45db6d0e55facb90c9",
      "parents": [
        "5f7bbe754b40741c4be4f618d37ef3adbfd26f4f"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Mon Apr 27 09:50:02 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:50:02 2026 -0400"
      },
      "message": "kokoro: linux uses clang-18 (#6656)\n\nGoogle-internal bug 393437270"
    },
    {
      "commit": "5f7bbe754b40741c4be4f618d37ef3adbfd26f4f",
      "tree": "0f184c1a16528711301620fc4ba63aee48395459",
      "parents": [
        "3a49d67b15d3ebbb0cb31e9fd2ca58903959a140"
      ],
      "author": {
        "name": "Jordan Robinson",
        "email": "34017385+Jmangles@users.noreply.github.com",
        "time": "Mon Apr 27 09:46:42 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:46:42 2026 -0400"
      },
      "message": "Remove redundant iterations from inliner passes (#6639)\n\nImplemented in both the exhaustive/opaque inliner even though it appears\nthe opaque one is not fully functional.\n\nIn my benchmark tests I found it reduced the time needed to run the\nexhaustive pass by 50% on average with the shaders I was testing with.\n\nAlso fixes two bugs in the opaque inliner. One is from not updating the\nparent of each new block and the other for debug. These could be split\ninto another PR if desired but it\u0027s still pretty small overall.\n\n---------\n\nCo-authored-by: Steven Perron \u003cstevenperron@google.com\u003e"
    },
    {
      "commit": "3a49d67b15d3ebbb0cb31e9fd2ca58903959a140",
      "tree": "cdb048da47bb609551d3bf286214d487d165481c",
      "parents": [
        "7f586c9b065d76341ba9477f374daf1836a464e5"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Apr 27 09:07:04 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:07:04 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ f58ee2660..351086314 (6 commits) (#6655)\n\nhttps://github.com/abseil/abseil-cpp/compare/f58ee266044d...351086314d46\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "7f586c9b065d76341ba9477f374daf1836a464e5",
      "tree": "4a9818943d1aca9a474188166df1b46d7bf47618",
      "parents": [
        "c1cb30bb04e2bf911755a40df1242cc6e3d83e26"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Apr 24 15:08:44 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 24 15:08:44 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ 8a6b6ae90..f58ee2660 (2 commits) (#6651)\n\nhttps://github.com/abseil/abseil-cpp/compare/8a6b6ae902ac...f58ee266044d\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "c1cb30bb04e2bf911755a40df1242cc6e3d83e26",
      "tree": "4d6fa79ab3a8f07be70e02ac718d488ac225a630",
      "parents": [
        "aee3d20c3f083465f566fd6075a81822c3c4ae90"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Fri Apr 24 10:20:46 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 24 10:20:46 2026 -0400"
      },
      "message": "Prepare for v2026.2 release (#6654)"
    },
    {
      "commit": "aee3d20c3f083465f566fd6075a81822c3c4ae90",
      "tree": "5be0e53b0daeee8b090c14ae0f5b3525060ef312",
      "parents": [
        "b1c899180b03cae9ff276ac8c2359e56f14d1758"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Apr 23 15:59:57 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 23 15:59:57 2026 -0400"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 2 updates (#6649)\n\nBumps the github-actions group with 2 updates in the / directory:\n[lukka/get-cmake](https://github.com/lukka/get-cmake) and\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `lukka/get-cmake` from 4.3.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/releases\"\u003elukka/get-cmake\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eCMake v4.3.2\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003eget-cmake\u003c/code\u003e action downloads and caches CMake and\nNinja on your workflows. Versions can be specified using \u003ca\nhref\u003d\"https://docs.npmjs.com/about-semantic-versioning\"\u003esemantic\nversioning ranges\u003c/a\u003e using \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L13\"\u003e\u003ccode\u003ecmakeVersion\u003c/code\u003e\u003c/a\u003e\nand \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L16\"\u003e\u003ccode\u003eninjaVersion\u003c/code\u003e\u003c/a\u003e\ninputs.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elatest\u003c/code\u003e is now using CMake version \u003ccode\u003ev4.3.2\u003c/code\u003e,\nuse this one-liner e.g.:\n\u003ccode\u003euses: lukka/get-cmake@latest\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eEnjoy!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/7bfc9baacbbdcb5e37957ad05c3546b3e222be3c\"\u003e\u003ccode\u003e7bfc9ba\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.3.2\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/ea83089aa35e08e459464341fe24ad024ee2466f...7bfc9baacbbdcb5e37957ad05c3546b3e222be3c\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.35.1 to 4.35.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled\nusing the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment\nvariable is deprecated and will be removed in May 2026. If you are\naffected by this, we recommend disabling TRAP caching by passing the\n\u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis\nnow only applies to repositories that contain submodules. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library,\nrelying instead on models of the standard library. This should result in\nsignificantly faster extraction and analysis times, while the effect on\nalerts should be minimal. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private\nregistries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.35.2 - 15 Apr 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled\nusing the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment\nvariable is deprecated and will be removed in May 2026. If you are\naffected by this, we recommend disabling TRAP caching by passing the\n\u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis\nnow only applies to repositories that contain submodules. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library,\nrelying instead on models of the standard library. This should result in\nsignificantly faster extraction and analysis times, while the effect on\nalerts should be minimal. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private\nregistries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e\ndue to issues with a small percentage of Actions and JavaScript\nanalyses. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e is enabled, since improved incremental analysis\nsupersedes TRAP caching. This will improve performance and reduce\nActions cache usage. We expect to roll this change out to everyone in\nMarch. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses\nthat use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be\ncomplete by the end of April 2026. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip\ncollecting file coverage information on pull requests to improve\nanalysis performance. File coverage information will still be computed\non non-PR analyses. Pull request analyses will log a warning about this\nupcoming change. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a\ncustom repository property with the name\n\u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type\n\u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in\nthe repository\u0027s settings. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e.\nAlternatively, if you are using an advanced setup workflow, you can set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch\nto an advanced setup workflow and set the\n\u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to\n\u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea\nbug\u003c/a\u003e which caused the CodeQL Action to fail loading repository\nproperties if a \u0026quot;Multi select\u0026quot; repository property was\nconfigured for the repository. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom\nrepository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the\ncustomization of features such as\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only\navailable on GitHub.com. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e can be configured with OIDC-based authentication\nfor organizations, the CodeQL Action will now be able to accept such\nconfigurations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would\nfail with the error \u0026quot;Response body object should not be disturbed\nor locked\u0026quot;. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository\nproperty whose name suggests that it relates to the CodeQL Action, but\nwhich is not one of the properties recognised by the current version of\nthe CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003e\u003ccode\u003e95e58e9\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3824\"\u003e#3824\u003c/a\u003e\nfrom github/update-v4.35.2-d2e135a73\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/6f31bfe060e817d81e938dbec767969d20031e25\"\u003e\u003ccode\u003e6f31bfe\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.35.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/d2e135a73a39154e3a231aeb49163c4661c5b8b1\"\u003e\u003ccode\u003ed2e135a\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3823\"\u003e#3823\u003c/a\u003e\nfrom github/update-bundle/codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/60abb65df09fcf213c398e064c8a80db1f15cdaf\"\u003e\u003ccode\u003e60abb65\u003c/code\u003e\u003c/a\u003e\nAdd changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/5a0a562209255e956ad8aafcee303294e64eefa2\"\u003e\u003ccode\u003e5a0a562\u003c/code\u003e\u003c/a\u003e\nUpdate default bundle to codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/65216971a11ded447a6b76263d5a144519e5eee1\"\u003e\u003ccode\u003e6521697\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3820\"\u003e#3820\u003c/a\u003e\nfrom github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3c45af2dd258e1623af1898da5c86545b514e028\"\u003e\u003ccode\u003e3c45af2\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3821\"\u003e#3821\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/npm-minor-345b93...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f1c339364c12f922998186ed897e45e3b4ae8874\"\u003e\u003ccode\u003ef1c3393\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/1024fc496c87e944a93e98d8cf2c09e2c7602a30\"\u003e\u003ccode\u003e1024fc4\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/9dd4cfed96030ccdfe1af4daf7a7964322704fed\"\u003e\u003ccode\u003e9dd4cfe\u003c/code\u003e\u003c/a\u003e\nBump the npm-minor group across 1 directory with 6 updates\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b1c899180b03cae9ff276ac8c2359e56f14d1758",
      "tree": "40c014db0cb44802dc7596b8b6cceaf6f6413c97",
      "parents": [
        "78b881bcf4697e31f248d5545d771ee9ea9a0087"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Apr 23 15:21:55 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 23 15:21:55 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ 04b6110da..b9536c952 (1 commit) (#6638)\n\nhttps://github.com/abseil/abseil-cpp/compare/04b6110da90b...b9536c952c6f\n\nCreated with:\n  roll-dep external/abseil_cpp\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "78b881bcf4697e31f248d5545d771ee9ea9a0087",
      "tree": "c325e984c347e43047db6cfa4842d491028955e2",
      "parents": [
        "ff5c50339cc1e9f34f04cb440a3e5fe89db0161d"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Apr 23 14:36:49 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 23 14:36:49 2026 -0400"
      },
      "message": "opt: Fold OpCompositeExtract feeding from OpCopyLogical or OpLoad (#6614)\n\n- CopyLogicalFeedingExtract: Hoist OpCompositeExtract before\nOpCopyLogical.\n  If the input to an OpCompositeExtract is an OpCopyLogical, we can\n  extract from the original composite and then copy the result.\n- LoadFeedingExtract: Change OpLoad + OpCompositeExtract to\nOpAccessChain + OpLoad.\n  If the input to an OpCompositeExtract is an OpLoad, we can load the\n  specific element instead of the entire composite. This is restricted\n  to non-Function/Private storage classes to avoid interfering with\n  local-access-chain-convert.\n\nUpdated fold_test.cpp with 8 new test cases and updated existing tests\nto use SPV_ENV_UNIVERSAL_1_5.\n\nFixes #6611"
    },
    {
      "commit": "ff5c50339cc1e9f34f04cb440a3e5fe89db0161d",
      "tree": "5e6f7a43856e912a49a8a5cb0b8fd26cc3a4f7d4",
      "parents": [
        "6c0666ec2000ba74ed12df5f6e807a7f721402a1"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Wed Apr 22 16:10:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 22 10:10:57 2026 -0400"
      },
      "message": "spirv-val: Add validation for 4-bit integer types (#6644)\n\nAllow 4-bit integers with Int4TypeINTEL\n\nRequired for test in LLVM tree:\nhttps://github.com/llvm/llvm-project/blob/6b0d268fe544b25fd1f82aad4e246f8a74e260ed/llvm/test/CodeGen/SPIRV/legalization/icmp_extended_int.ll\n\nExtension ref:\nhttps://github.com/KhronosGroup/SPIRV-Registry/blob/main/extensions/INTEL/SPV_INTEL_int4.asciidoc"
    },
    {
      "commit": "6c0666ec2000ba74ed12df5f6e807a7f721402a1",
      "tree": "be777bc9506b2f75e7eb79d2222d4b8f52ab5043",
      "parents": [
        "8b3a3c79b6ecaae7bd11ff20261aea532ce268c2"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Apr 21 16:49:39 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 16:49:39 2026 -0400"
      },
      "message": "build: Fix BUILD.gn for NonSemanticShaderDebugInfo (#6647)\n\nFix for @y-novikov\n(https://github.com/KhronosGroup/SPIRV-Tools/pull/6635#issuecomment-4283010149)"
    },
    {
      "commit": "8b3a3c79b6ecaae7bd11ff20261aea532ce268c2",
      "tree": "e223b9f0b69d6b3c69cbc610b83dae4dfba6c306",
      "parents": [
        "706f1dc8558316213eac02b0611f9cde6fd3d9c5"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Apr 21 12:32:25 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 12:32:25 2026 -0400"
      },
      "message": "spirv-val: Handle OpSpecConstantDataKHR (#6646)\n\n@alan-baker this adds the `spirv-val` to handle `OpSpecConstantDataKHR`\n\nI took out of `opcode.h` because it was only used in `spirv-val` in that\none spot. The next (and hopefully final) PR after this is to fix all the\n`spirv-opt` passes to handle this \"joy to use\" spec constant instruction\ncorrectly\n\n----\n\n**Edit:** - Just added the `CreateSetSpecConstantDefaultValuePass` and\n`CreateFreezeSpecConstantValuePass` pass as well"
    },
    {
      "commit": "706f1dc8558316213eac02b0611f9cde6fd3d9c5",
      "tree": "e552cef46ba910548fbc3a782bf91d4ee1619c3b",
      "parents": [
        "5278681115c9099ca33183cbf91f3726ee962616"
      ],
      "author": {
        "name": "Jay Kwak",
        "email": "82421531+jkwak-work@users.noreply.github.com",
        "time": "Mon Apr 20 13:28:27 2026 -1000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 23:28:27 2026 +0000"
      },
      "message": "Add DebugBuildIdentifier to the live worklist during initialization (#6626)\n\nDebugBuildIdentifier was missing from the set of NonSemantic debug\ninstructions added to the worklist in\nInitializeModuleScopeLiveInstructions. Instead it was handled in\nProcessGlobalValues (after the worklist is exhausted) using\nlive_insts_.Set() on its direct operands.\n\nlive_insts_.Set() marks an instruction live but does not enqueue it, so\ntransitive operand dependencies are never visited. In shaders where the\nonly use of a type (e.g. OpTypeInt) is through a constant that is itself\nonly referenced by DebugBuildIdentifier\u0027s flags argument, the type\ninstruction is not marked live and is incorrectly killed by ADCE.\n\nThe surviving constant then references a deleted type, producing invalid\nSPIR-V. Any subsequent pass that rebuilds the DefUseManager (e.g. CCP)\nwill fail with \"Definition is not registered.\"\n\nFix: include NonSemanticShaderDebugInfo100DebugBuildIdentifier in the\nworklist loop alongside the other always-live debug instructions. The\nworklist\u0027s transitive closure correctly marks all operand dependencies\nlive before global-value cleanup runs. The existing special-case code in\nProcessGlobalValues becomes unreachable for this opcode (IsLive returns\ntrue, so the early continue fires) and is now dead; it is left in\nplacefor safety.\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "5278681115c9099ca33183cbf91f3726ee962616",
      "tree": "39aa7ba6c68377d07e09f10bf7f7c2a08e0bd1eb",
      "parents": [
        "878ba274712e077474118a721e8edef4f6951a47"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sat Apr 18 17:20:41 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Apr 18 11:20:41 2026 -0400"
      },
      "message": "spirv-val: Validate OpConstantDataKHR (#6643)\n\n(based on https://github.com/KhronosGroup/SPIRV-Tools/pull/6642)\n\nadds the missing validation for `OpConstantDataKHR`"
    },
    {
      "commit": "878ba274712e077474118a721e8edef4f6951a47",
      "tree": "131619965c565ae14296438aacce300ad466b97f",
      "parents": [
        "7f88e7df21e7e6d8bf0a9bd684e5b70c427db013"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Fri Apr 17 16:54:27 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 17 16:54:27 2026 -0400"
      },
      "message": "Fix crash in shuffle validation (#6645)\n\nRefs https://crbug.com/oss-fuzz/502697533\n\n* Fix a crash if a typeless instruction id is used as a vector operand"
    },
    {
      "commit": "7f88e7df21e7e6d8bf0a9bd684e5b70c427db013",
      "tree": "585743389d8ef4bbff7e9baa4101239b8b209dfc",
      "parents": [
        "2e8b5e20ee8d9bdb37a6416508247955087a3453"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Apr 17 14:15:51 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 17 14:15:51 2026 +0200"
      },
      "message": "spirv-as: Fix OpConstantDataKHR new grammar (#6642)\n\nTalked to David at F2F and we decided for now, to just get a fix in to\n`OpConstantDataKHR` from\nhttps://github.com/KhronosGroup/SPIRV-Headers/commit/ad9184e76a66b1001c29db9b0a3e87f646c64de0\n\nin the future, we can apply the \"joy to use\" `UTFEncodedKHR` decoration\nto allow `spirv-as`/`spirv-dis` to handle strings"
    },
    {
      "commit": "2e8b5e20ee8d9bdb37a6416508247955087a3453",
      "tree": "2fcbd56ffd44575f9cac95b0e8e284539ef05a7a",
      "parents": [
        "d6f49d73881c76d2824bda1b2406a41845f193fd"
      ],
      "author": {
        "name": "Steve Urquhart",
        "email": "53908460+SteveUrquhart@users.noreply.github.com",
        "time": "Thu Apr 16 12:09:57 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 16 12:09:57 2026 -0400"
      },
      "message": "spirv-opt: Fix DebugValue placements (#6599)\n\nThis PR fixes several problems with DebugDeclare and DebugValue\ninstructions created during optimization. Together, they address the\ndebug info problems reported in\nhttps://github.com/microsoft/DirectXShaderCompiler/issues/8112.\n\nThe DebugInfoManager changes correct a problem that can occur when\ncloning a previous instruction. The given insert_pos from the\noptimization may not be dominated by the cloned operands. We now now\ndetect this and insert safely after the debug instruction.\n\nThe inline pass was creating invalid SPIR-V when an OpAccessChain was\nreferencing dynamic values. The indices of a DebugDecalre or DebugValue\nfollow the same rules as OpAccessChain, which requires constant values\nwhen indexing into a structure. Since there is no valid way to represent\nthis DebugDeclare following optimization, we kill it.\n\nThe change to instruction.cpp handles the case where a user invoked\n--fixup-opextinst-opcodes prior to optimization.\n\nThe scalar replacement pass was relocating DebugValue\u0027s and creating\ninvalid SPIR-V.\n\nTogether, these changes allow the 1st shader reported in\nhttps://github.com/microsoft/DirectXShaderCompiler/issues/8112 to\ncompile and validate cleanly. There are still one or more problems with\nthe 2nd shader in the ticket, but I fixed all the debug info problems\nthat I saw."
    },
    {
      "commit": "d6f49d73881c76d2824bda1b2406a41845f193fd",
      "tree": "076308195b327e9f110a0f3e8af105f33495ead6",
      "parents": [
        "8d245e02504488aaa51ab561cfd8725b7916c91d"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Thu Apr 16 13:56:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 16 11:56:59 2026 +0000"
      },
      "message": "Only run autoroll workflow on upstream repository (#6640)\n\nAvoid creating \u0027roll deps\u0027 PRs in forks"
    },
    {
      "commit": "8d245e02504488aaa51ab561cfd8725b7916c91d",
      "tree": "789be7256a2783a64e586568986d0910f9c6d93c",
      "parents": [
        "4b3bd66f3806ee0b67d9fe7c591d8f29ca535ccd"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Wed Apr 15 17:18:39 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 15 11:18:39 2026 -0400"
      },
      "message": "Test spvtools::TextToBinaryTestBase::MaybeFlipWords (#6637)\n\nMaybeFlipWords is used in the tests for parsing\nbinaries in both endiannesses."
    },
    {
      "commit": "4b3bd66f3806ee0b67d9fe7c591d8f29ca535ccd",
      "tree": "5d00578cc380daa5bb83320f44c6d2eb4a6e2f9d",
      "parents": [
        "5d7c08d0cde5ba67e540ba379b2ef0ee2fc92fa9"
      ],
      "author": {
        "name": "Diego Novillo",
        "email": "dnovillo@nvidia.com",
        "time": "Wed Apr 15 03:14:02 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 15 09:14:02 2026 +0200"
      },
      "message": "Add validation for NSDI 101 (#6635)\n\nThis is the next step in implementing NSDI 101\n(https://github.com/KhronosGroup/SPIRV-Registry/pull/390)).\n\nThis PR updates SPIRV-Tools to validate NSDI.101 modules:\n\n- DEPS: Update `spirv_headers_revision` to the NSDI.101 SPIRV-Headers\nchanges.\n- Change build system files to use the version-agnostic headers and\ngrammar files. In `utils/ggt.py`, I added a special case to map\n`SPV_EXT_INST_TYPE_NONSEMANTIC_SHADER_DEBUGINFO` back to\n`SPV_EXT_INST_TYPE_NONSEMANTIC_SHADER_DEBUGINFO_100`. I didn\u0027t want to\nmake an API breaking change here.\n- Since we are now including the unified version header, all the\nembedded `100` strings can be removed. I updated all references across\n`source/opt/` and `source/val/`. The numeric values are identical; none\nof these symbols are part of the public API.\n- Finally, the actual validator changes:\n\n1. `GetNSDIVersion` parses the declared version from the\n`OpExtInstImport` string (e.g., `NonSemantic.Shader.DebugInfo.101`\nreturns `101`).\n2. `kNSDIKnownVersion` is set to `NonSemanticShaderDebugInfoVersion` (\u003d\n101). A `has_optional_at(n)` lambda replaces the previous `num_words \u003d\u003d\nn` checks for optional trailing operands. It accepts the optional\noperand when the module declares a version newer than\n`kNSDIKnownVersion` or when the word count is exactly `n`.\n3. Added a new helper\n`ValidateUint32ConstOrSpecConstOperandForDebugInfo` and macro\n`CHECK_CONST_OR_SPEC_UINT_OPERAND`. This accepts both constants and spec\nconstants.\n4. Two new cases in the `vulkanDebugInfo` branch of `ValidateExtInst`:\n   - `DebugTypeVectorIdEXT`\n   - `DebugTypeCooperativeMatrixKHR`\n5. `DebugTypeBasic` validation is updated to accept the new optional\n`FPEncoding` operand.\n6. Added new tests for the validator for all the new opcodes."
    },
    {
      "commit": "5d7c08d0cde5ba67e540ba379b2ef0ee2fc92fa9",
      "tree": "99a0b1d473b79ed6c3a94fcd49f35d838d8d1b0d",
      "parents": [
        "5c00fbc68c0428cee0ea38aafe19341708b9c913"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Apr 14 10:37:19 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 10:37:19 2026 -0400"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 2 updates (#6636)\n\nBumps the github-actions group with 2 updates in the / directory:\n[actions/cache](https://github.com/actions/cache) and\n[actions/upload-artifact](https://github.com/actions/upload-artifact).\n\nUpdates `actions/cache` from 5.0.4 to 5.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003eactions/cache\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.5\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ts-http-runtime dependency by \u003ca\nhref\u003d\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1747\"\u003eactions/cache#1747\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/v5...v5.0.5\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e\nwith the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e\nsection.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by\nupdating the \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e\nfile with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed\nand merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e\nuse the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you\nmade in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca\nhref\u003d\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version\nnumber.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags\nfor this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar\npatterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb\nprotection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca\nhref\u003d\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via\n\u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and\nrequires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003e\u003ccode\u003e27d5ce7\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1747\"\u003e#1747\u003c/a\u003e\nfrom actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/f280785d7b6e1884c7d12b9136eb0f4a1574fcfd\"\u003e\u003ccode\u003ef280785\u003c/code\u003e\u003c/a\u003e\nlicensed changes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/619aeb1606e195be0b36fd0ff68dcf1aff6b65a7\"\u003e\u003ccode\u003e619aeb1\u003c/code\u003e\u003c/a\u003e\nnpm run build generated dist files\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/bcf16c2893940a4899761e55c7ac3c1cf88a04f6\"\u003e\u003ccode\u003ebcf16c2\u003c/code\u003e\u003c/a\u003e\nUpdate ts-http-runtime to 0.3.5\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca\nhref\u003d\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e\nfrom actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e\nInclude changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e\nReadme: bump all the example versions to v7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e\nUpdate the readme with direct upload details (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5c00fbc68c0428cee0ea38aafe19341708b9c913",
      "tree": "6a7d6d0ba20f710397a80737f4208836a7da5940",
      "parents": [
        "af662dddb957564fdabe61b40c6f2731d8d2e0d1"
      ],
      "author": {
        "name": "mjkrol",
        "email": "mjkrol@gmail.com",
        "time": "Tue Apr 14 16:21:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 14:21:29 2026 +0000"
      },
      "message": "spirv-val: Check output location uniqueness per-stream for GeometryStreams (#6630)\n\nThe VK_EXT_transform_feedback extension exists specifically to support\ntranslation layers from other 3D APIs. In D3D\u0027s stream output model, all\nfour geometry streams share the same 32 output registers. When a vertex\nis emitted on any stream, the current register values go to that\nstream\u0027s buffer and all registers become undefined.\n\nSPIR-V\u0027s current location uniqueness rule prevents this by requiring\nglobally-unique locations across all output variables, forcing\ntranslation layers to use unique locations per stream. This exhausts\nmaxGeometryOutputComponents (typically 128) at just eight vec4\u0027s per\nstream instead of the 32 that D3D supports.\n\nRelax the location uniqueness check for geometry shader outputs when\nGeometryStreams capability is present, allowing variables on different\nstreams to share the same location. This matches the D3D hardware model\nwhere streams alias the same register file.\n\nAdd tests for per-stream output location uniqueness:\n- Different streams at the same location pass.\n- Same stream at the same location still conflicts (VUID 08722).\n- Component-sharing across streams is allowed.\n- Without the GeometryStreams capability, duplicate output locations\n  in a Geometry shader still conflict.\n- Input variables in a Geometry+GeometryStreams entry point still\n  require unique locations (VUID 08721).\n\n---------\n\nSigned-off-by: Michal Krol \u003cmichal.krol@broadcom.com\u003e"
    },
    {
      "commit": "af662dddb957564fdabe61b40c6f2731d8d2e0d1",
      "tree": "085524dd53500700e64a0be75c70e143fc0767a8",
      "parents": [
        "ef36b6395e11a9821c78735bb1a91d8687539844"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Tue Apr 14 09:55:46 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 09:55:46 2026 -0400"
      },
      "message": "roll deps (#6631)\n\n- **Roll external/abseil_cpp/ 884282e28..9034b9ca6 (1 commit)**\n- **Roll external/spirv-headers/ 6dd7ba990..ce9dfb014 (1 commit)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "ef36b6395e11a9821c78735bb1a91d8687539844",
      "tree": "6396486e7e522b8130dc4d8a249d3fd90d835949",
      "parents": [
        "31f2d2e644d0432b6749262b9d58bb0b5e00b300"
      ],
      "author": {
        "name": "Ralph Potter",
        "email": "ralph@rendering.io",
        "time": "Tue Apr 14 12:59:11 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 07:59:11 2026 -0400"
      },
      "message": "Add support for SPV_KHR_abort and SPV_KHR_constant_data (#6625)\n\nSupersedes #6624\n\nBuilds on original contribution by @archimedus.\n\n* Corrects invalid SPIR-V in various tests\n* Expands validation to cover operand compatibility\n* Validates the OpAbortKHR terminates a block\n* Relocates text to binary tests\n* Removes unnecessary changes to test_fixture.h\n\n---------\n\nCo-authored-by: Boris Zanin \u003cboris.zanin@amd.com\u003e\nCo-authored-by: Craig Graham \u003ccraig.graham@samsung.com\u003e"
    },
    {
      "commit": "31f2d2e644d0432b6749262b9d58bb0b5e00b300",
      "tree": "a0fb1d53898359f37003f6313a4927217441e35c",
      "parents": [
        "a52828d672ab1622c308d0a6fc99630b79561609"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "arseniy.obolenskiy@amd.com",
        "time": "Mon Apr 13 17:51:09 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 13 11:51:09 2026 -0400"
      },
      "message": "spirv-val: Do not require type on untyped def instructions (#6634)\n\nThe \"requires a type\" check in IdPass only considered whether the using\ninstruction expects typed operands, not whether the def instruction is\nlegitimately untyped. Instructions like OpAliasScopeListDeclINTEL,\nOpAliasScopeDeclINTEL, and OpAliasDomainDeclINTEL intentionally have no\nresult type, so they should not trigger the error when referenced by\nother instructions\n\nRequired for 2 tests in\nhttps://github.com/llvm/llvm-project/issues/190736 (IR is legit, but\nspirv-val rejects it):\n-\nhttps://github.com/llvm/llvm-project/blob/6dbf9d1ac5e68ec6811e6b05c67f12fda07f62e3/llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_memory_access_aliasing/alias-load-store-struct.ll\n-\nhttps://github.com/llvm/llvm-project/blob/6dbf9d1ac5e68ec6811e6b05c67f12fda07f62e3/llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_memory_access_aliasing/alias-load-store.ll"
    },
    {
      "commit": "a52828d672ab1622c308d0a6fc99630b79561609",
      "tree": "82b7359a05d4c36f36ffe811f60dc386352f2c99",
      "parents": [
        "9fc4e611ff6af82ff01ef48cdf14df895b3fb9ad"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Apr 09 10:37:39 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 16:37:39 2026 +0200"
      },
      "message": "spirv-val: Fix newline not marked as a line for DebugShaderInfo (#6623)\n\nfollow up of the issues @Keenuts was finding in\nhttps://github.com/KhronosGroup/SPIRV-Tools/pull/5986\n\nsummary is the following\n\n```\n%24 \u003d OpString \"-with-source-test -fcgl  %s -spirv | FileCheck %s ; line 1\n                                                                                                                    ; line2\n\"                                                                                                                  ; line3\n```\n\nwas not counting `line 3` as a zero-length, empty line and it would\ncause an off-by-1 later below it\n\n(should fix the failing DXC CI as well)"
    },
    {
      "commit": "9fc4e611ff6af82ff01ef48cdf14df895b3fb9ad",
      "tree": "4f9353d31e093103a22252f4894cd215293e1a0f",
      "parents": [
        "34bc8ea6f3f84d5ed7739daa66b01e7273aed458"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Thu Apr 09 10:35:29 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 16:35:29 2026 +0200"
      },
      "message": "spirv-opt: Add extensions to the allow list (#6629)\n\nAdds SPV_EXT_shader_atomic_float16_add, SPV_KHR_abort, and\nSPV_KHR_constant_data to the allow lists.\n\nFixes #6486"
    },
    {
      "commit": "34bc8ea6f3f84d5ed7739daa66b01e7273aed458",
      "tree": "0eb00c5623853a9501845c643c4c4efb877352a3",
      "parents": [
        "64edccb611c8adbc74572349cccd75c716cab7b6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Apr 08 12:49:32 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 08 12:49:32 2026 -0400"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 2 updates (#6621)\n\nBumps the github-actions group with 2 updates in the / directory:\n[lukka/get-cmake](https://github.com/lukka/get-cmake) and\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `lukka/get-cmake` from 4.3.0 to 4.3.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/ea83089aa35e08e459464341fe24ad024ee2466f\"\u003e\u003ccode\u003eea83089\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.3.1\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/b78306120111dc2522750771cfd09ee7ca723687...ea83089aa35e08e459464341fe24ad024ee2466f\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.34.1 to 4.35.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.35.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis\nnow only applies to repositories that contain submodules. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library,\nrelying instead on models of the standard library. This should result in\nsignificantly faster extraction and analysis times, while the effect on\nalerts should be minimal. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e\ndue to issues with a small percentage of Actions and JavaScript\nanalyses. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e is enabled, since improved incremental analysis\nsupersedes TRAP caching. This will improve performance and reduce\nActions cache usage. We expect to roll this change out to everyone in\nMarch. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses\nthat use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be\ncomplete by the end of April 2026. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip\ncollecting file coverage information on pull requests to improve\nanalysis performance. File coverage information will still be computed\non non-PR analyses. Pull request analyses will log a warning about this\nupcoming change. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a\ncustom repository property with the name\n\u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type\n\u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in\nthe repository\u0027s settings. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e.\nAlternatively, if you are using an advanced setup workflow, you can set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch\nto an advanced setup workflow and set the\n\u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to\n\u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea\nbug\u003c/a\u003e which caused the CodeQL Action to fail loading repository\nproperties if a \u0026quot;Multi select\u0026quot; repository property was\nconfigured for the repository. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom\nrepository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the\ncustomization of features such as\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only\navailable on GitHub.com. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e can be configured with OIDC-based authentication\nfor organizations, the CodeQL Action will now be able to accept such\nconfigurations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would\nfail with the error \u0026quot;Response body object should not be disturbed\nor locked\u0026quot;. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository\nproperty whose name suggests that it relates to the CodeQL Action, but\nwhich is not one of the properties recognised by the current version of\nthe CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.5 - 02 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to\ndisable \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository\nproperty with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and\nthe type \u0026quot;True/false\u0026quot; in the organization\u0027s settings. Then in\nthe repository\u0027s settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to\ndisable improved incremental analysis. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e. This\nfeature is not yet available on GitHub Enterprise Server. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e fails on a runner — potentially due to\ninsufficient disk space — the failure is recorded in the Actions cache\nso that subsequent runs will automatically skip improved incremental\nanalysis until something changes (e.g. a larger runner is provisioned or\na new CodeQL version is released). We expect to roll this change out to\neveryone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c10b8064de6f491fea524254123dbe5e09572f13\"\u003e\u003ccode\u003ec10b806\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3782\"\u003e#3782\u003c/a\u003e\nfrom github/update-v4.35.1-d6d1743b8\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c5ffd0683786820677d054e3505e1c5bb4b8c227\"\u003e\u003ccode\u003ec5ffd06\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.35.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/d6d1743b8ec7ecd94f78ad1ce4cb3d8d2ba58001\"\u003e\u003ccode\u003ed6d1743\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3781\"\u003e#3781\u003c/a\u003e\nfrom github/henrymercer/update-git-minimum-version\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/65d2efa7333ad65f97cc54be40f4cd18630f884c\"\u003e\u003ccode\u003e65d2efa\u003c/code\u003e\u003c/a\u003e\nAdd changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/2437b20ab31021229573a66717323dd5c6ce9319\"\u003e\u003ccode\u003e2437b20\u003c/code\u003e\u003c/a\u003e\nUpdate minimum git version for overlay to 2.36.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/ea5f71947c021286c99f61cc426a10d715fe4434\"\u003e\u003ccode\u003eea5f719\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3775\"\u003e#3775\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/node-forge-1.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/45ceeea896ba2293e10982f871198d1950ee13d6\"\u003e\u003ccode\u003e45ceeea\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3777\"\u003e#3777\u003c/a\u003e\nfrom github/mergeback/v4.35.0-to-main-b8bb9f28\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/24448c98434f429f901d27db7ddae55eec5cc1c4\"\u003e\u003ccode\u003e24448c9\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/7c510606312e5c68ac8b27c009e5254f226f5dfa\"\u003e\u003ccode\u003e7c51060\u003c/code\u003e\u003c/a\u003e\nUpdate changelog and version after v4.35.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/b8bb9f28b8d3f992092362369c57161b755dea45\"\u003e\u003ccode\u003eb8bb9f2\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3776\"\u003e#3776\u003c/a\u003e\nfrom github/update-v4.35.0-0078ad667\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/38697555549f1db7851b81482ff19f1fa5c4fedc...c10b8064de6f491fea524254123dbe5e09572f13\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "64edccb611c8adbc74572349cccd75c716cab7b6",
      "tree": "14ce4a9f49647b2406f2efa692bcdb4343bbd499",
      "parents": [
        "d8030391e8ed342f74df92f27bbfc993055dd4b4"
      ],
      "author": {
        "name": "Kévin Petit",
        "email": "kevin.petit@arm.com",
        "time": "Wed Apr 08 16:51:20 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 08 11:51:20 2026 -0400"
      },
      "message": "spirv-opt: add missing OpConstantCompositeReplicateEXT support to constant manager (#6616)\n\nSigned-off-by: Kevin Petit \u003ckevin.petit@arm.com\u003e\nSigned-off-by: Mohammadreza Ameri Mahabadian\n\u003cmohammadreza.amerimahabadian@arm.com\u003e\n\nSigned-off-by: Mohammadreza Ameri Mahabadian \u003cmohammadreza.amerimahabadian@arm.com\u003e\nSigned-off-by: Kevin Petit \u003ckevin.petit@arm.com\u003e"
    },
    {
      "commit": "d8030391e8ed342f74df92f27bbfc993055dd4b4",
      "tree": "81dc6fe120b00d44b30f938e9aa4341792850517",
      "parents": [
        "2d14d2e76aa7de72404b17078eda15c20a6a0389"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Wed Apr 08 11:48:48 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 08 11:48:48 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ 5c01794f7..ed2114e8f (2 commits) (#6627)\n\nhttps://github.com/abseil/abseil-cpp/compare/5c01794f7902...ed2114e8ff2e\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "2d14d2e76aa7de72404b17078eda15c20a6a0389",
      "tree": "abf28b5764a7187ea159f90342cffbf9ced665b2",
      "parents": [
        "c6e04520cc3093a4e0cf7ba2817581e279eec3ed"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Apr 02 22:27:35 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 02 22:27:35 2026 -0400"
      },
      "message": "roll deps (#6620)\n\n- **Roll external/googletest/ 015950a93..246174399 (1 commit)**\n- **Roll external/abseil_cpp/ 0093ac6ca..d2910b037 (1 commit)**\n- **Roll external/spirv-headers/ 00898b201..39e5d40a3 (1 commit)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "c6e04520cc3093a4e0cf7ba2817581e279eec3ed",
      "tree": "8470b385e43eb1cde173025b07616081458d9839",
      "parents": [
        "d7ba8c9fc218830544008cb71e4618adb1c56e12"
      ],
      "author": {
        "name": "Arseniy Obolenskiy",
        "email": "gooddoog@student.su",
        "time": "Thu Apr 02 16:40:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 02 10:40:16 2026 -0400"
      },
      "message": "spirv-val: Add vector support for OpConvertPtrToU/OpConvertUToPtr with SPV_INTEL_masked_gather_scatter extension (#6575)\n\nAdd missing support for vector operands in `OpConvertPtrToU` and\n`OpConvertUToPtr` when\n[SPV_INTEL_masked_gather_scatter](https://github.com/KhronosGroup/SPIRV-Registry/blob/278044a51fee280bfc91322cdb55b51357db5cb8/extensions/INTEL/SPV_INTEL_masked_gather_scatter.asciidoc)\nextension is enabled"
    },
    {
      "commit": "d7ba8c9fc218830544008cb71e4618adb1c56e12",
      "tree": "109f116a5c536552c9abfc5d815ae2a6dc6c7579",
      "parents": [
        "2c75d08e3b31a673726ce6be80ab528250247064"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Mar 30 21:03:46 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 30 21:03:46 2026 -0400"
      },
      "message": "spirv-val: Slightly improve 04965 error message (#6622)\n\nrelated to https://gitlab.khronos.org/vulkan/vulkan/-/issues/4766\n\nmainly wanted to just improve the error message and add the 2 VVL tests\nhere I had"
    },
    {
      "commit": "2c75d08e3b31a673726ce6be80ab528250247064",
      "tree": "22014f183e4ad1fe34fc692b3b02c2faea563ac7",
      "parents": [
        "669844c5e47f1d764a90f9117f6c9bba726a942d"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:44:51 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:44:51 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ b7c61d35e..0093ac6ca (2 commits) (#6615)\n\nhttps://github.com/abseil/abseil-cpp/compare/b7c61d35e6c7...0093ac6cac89\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "669844c5e47f1d764a90f9117f6c9bba726a942d",
      "tree": "bbfddee3ca50b3705cdbe600c5fdbc1c20e82806",
      "parents": [
        "4743e69a64255650ac902d87dc51022b6604c607"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Mar 27 20:32:34 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 20:32:34 2026 -0400"
      },
      "message": "spirv-val: Check DebugLine Line/Column are valid (#5986)\n\nI had to raise issue in Glslang because it would generate\n`Line`/`Column` that didn\u0027t actually point to any valid spot in the\n`DebugSource`\u0027s text\n\nThis adds some validation where if there is a `DebugSource` with `Text`\nthen any `Line`/`Column` must be correct, otherwise every other consume\ntool (like Validation Layers) need to do this before trying to print out\nthe snippet in the source code"
    },
    {
      "commit": "4743e69a64255650ac902d87dc51022b6604c607",
      "tree": "5a0120b6b0df98e3faa4d6c06fa48843daf94f5a",
      "parents": [
        "7e4606da87931662d66c8e3ac425eec087d17053"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Mar 26 14:04:01 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 26 14:04:01 2026 -0400"
      },
      "message": "build(deps): bump the github-actions group across 1 directory with 3 updates (#6610)\n\nBumps the github-actions group with 3 updates in the / directory:\n[actions/cache](https://github.com/actions/cache),\n[lukka/get-cmake](https://github.com/lukka/get-cmake) and\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `actions/cache` from 5.0.3 to 5.0.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003eactions/cache\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.4\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release instructions and update maintainer docs by \u003ca\nhref\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1696\"\u003eactions/cache#1696\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePotential fix for code scanning alert no. 52: Workflow does not\ncontain permissions by \u003ca\nhref\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1697\"\u003eactions/cache#1697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix workflow permissions and cleanup workflow names / formatting by\n\u003ca href\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1699\"\u003eactions/cache#1699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: Update examples to use the latest version by \u003ca\nhref\u003d\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix proxy integration tests by \u003ca\nhref\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1701\"\u003eactions/cache#1701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix cache key in examples.md for bun.lock by \u003ca\nhref\u003d\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate dependencies \u0026amp; patch security vulnerabilities by \u003ca\nhref\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1738\"\u003eactions/cache#1738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/v5...v5.0.4\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e\nwith the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e\nsection.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by\nupdating the \u003ca\nhref\u003d\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e\nfile with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed\nand merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca\nhref\u003d\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e\nuse the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you\nmade in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca\nhref\u003d\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version\nnumber.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags\nfor this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar\npatterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb\nprotection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca\nhref\u003d\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via\n\u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and\nrequires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003e\u003ccode\u003e6682284\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1738\"\u003e#1738\u003c/a\u003e\nfrom actions/prepare-v5.0.4\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/e34039626f957d3e3e50843d15c1b20547fc90e2\"\u003e\u003ccode\u003ee340396\u003c/code\u003e\u003c/a\u003e\nUpdate RELEASES\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/8a671105293e81530f1af99863cdf94550aba1a6\"\u003e\u003ccode\u003e8a67110\u003c/code\u003e\u003c/a\u003e\nAdd licenses\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/1865903e1b0cb750dda9bc5c58be03424cc62830\"\u003e\u003ccode\u003e1865903\u003c/code\u003e\u003c/a\u003e\nUpdate dependencies \u0026amp; patch security vulnerabilities\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/565629816435f6c0b50676926c9b05c254113c0c\"\u003e\u003ccode\u003e5656298\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1722\"\u003e#1722\u003c/a\u003e\nfrom RyPeck/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/4e380d19e192ace8e86f23f32ca6fdec98a673c6\"\u003e\u003ccode\u003e4e380d1\u003c/code\u003e\u003c/a\u003e\nFix cache key in examples.md for bun.lock\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/b7e8d49f17405cc70c1c120101943203c98d3a4b\"\u003e\u003ccode\u003eb7e8d49\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/cache/issues/1701\"\u003e#1701\u003c/a\u003e\nfrom actions/Link-/fix-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/984a21b1cb176a0936f4edafb42be88978f93ef1\"\u003e\u003ccode\u003e984a21b\u003c/code\u003e\u003c/a\u003e\nAdd traffic sanity check step\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/acf2f1f76affe1ef80eee8e56dfddd3b3e5f0fba\"\u003e\u003ccode\u003eacf2f1f\u003c/code\u003e\u003c/a\u003e\nFix resolution\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/cache/commit/95a07c51324af6001b4d6ab8dff29f4dfadc2531\"\u003e\u003ccode\u003e95a07c5\u003c/code\u003e\u003c/a\u003e\nAdd wait for proxy\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lukka/get-cmake` from 4.2.3 to 4.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/releases\"\u003elukka/get-cmake\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eCMake v4.3.0\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003eget-cmake\u003c/code\u003e action downloads and caches CMake and\nNinja on your workflows. Versions can be specified using \u003ca\nhref\u003d\"https://docs.npmjs.com/about-semantic-versioning\"\u003esemantic\nversioning ranges\u003c/a\u003e using \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L13\"\u003e\u003ccode\u003ecmakeVersion\u003c/code\u003e\u003c/a\u003e\nand \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/blob/latest/action.yml#L16\"\u003e\u003ccode\u003eninjaVersion\u003c/code\u003e\u003c/a\u003e\ninputs.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elatest\u003c/code\u003e is now using CMake version \u003ccode\u003ev4.3.0\u003c/code\u003e,\nuse this one-liner e.g.:\n\u003ccode\u003euses: lukka/get-cmake@latest\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eEnjoy!\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/b78306120111dc2522750771cfd09ee7ca723687\"\u003e\u003ccode\u003eb783061\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-v4.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/9004e4575548904aeed26fb81e6a4b85d8ffa048\"\u003e\u003ccode\u003e9004e45\u003c/code\u003e\u003c/a\u003e\nMigrate to Node 24\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/6e70939585f9e200ced798068227e505a7204ef8\"\u003e\u003ccode\u003e6e70939\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-rc-v4.3.0-rc3 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/242\"\u003e#242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/9cd6c6b338a41017c69286cb3fe8db5c4513e74c\"\u003e\u003ccode\u003e9cd6c6b\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-rc-v4.3.0-rc2 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/241\"\u003e#241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/7697ef75dc9ed6b3272f78db9f33ab1c0283bc5c\"\u003e\u003ccode\u003e7697ef7\u003c/code\u003e\u003c/a\u003e\nBump actions/upload-artifact from 6 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/239\"\u003e#239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/54f69bf0821bdee1b09d61998039cf2c499cd4e1\"\u003e\u003ccode\u003e54f69bf\u003c/code\u003e\u003c/a\u003e\nBump actions/download-artifact from 7 to 8 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/240\"\u003e#240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/b9a171adf54022d8446fc53ac8397858d387ad9d\"\u003e\u003ccode\u003eb9a171a\u003c/code\u003e\u003c/a\u003e\nBump actions/upload-artifact from 5 to 6 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/227\"\u003e#227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/2b80711d6d74d65d9c96f1d4146f0704357b8e3e\"\u003e\u003ccode\u003e2b80711\u003c/code\u003e\u003c/a\u003e\nBump actions/download-artifact from 6 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/228\"\u003e#228\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/30c1a5f5bd8c0a8962200f9a3ff5e7e933432c79\"\u003e\u003ccode\u003e30c1a5f\u003c/code\u003e\u003c/a\u003e\nBump minimatch from 3.1.2 to 3.1.5 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/238\"\u003e#238\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/commit/4f9746d71696c9c93399c56d527dcd372434c814\"\u003e\u003ccode\u003e4f9746d\u003c/code\u003e\u003c/a\u003e\nNew CMake version(s): cmake-rc-v4.3.0-rc1 (\u003ca\nhref\u003d\"https://redirect.github.com/lukka/get-cmake/issues/236\"\u003e#236\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/lukka/get-cmake/compare/f176ccd3f28bda569c43aae4894f06b2435a3375...b78306120111dc2522750771cfd09ee7ca723687\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.32.6 to 4.33.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.33.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip\ncollecting file coverage information on pull requests to improve\nanalysis performance. File coverage information will still be computed\non non-PR analyses. Pull request analyses will log a warning about this\nupcoming change. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a\ncustom repository property with the name\n\u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type\n\u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in\nthe repository\u0027s settings. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e.\nAlternatively, if you are using an advanced setup workflow, you can set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch\nto an advanced setup workflow and set the\n\u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to\n\u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea\nbug\u003c/a\u003e which caused the CodeQL Action to fail loading repository\nproperties if a \u0026quot;Multi select\u0026quot; repository property was\nconfigured for the repository. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom\nrepository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the\ncustomization of features such as\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only\navailable on GitHub.com. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e can be configured with OIDC-based authentication\nfor organizations, the CodeQL Action will now be able to accept such\nconfigurations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would\nfail with the error \u0026quot;Response body object should not be disturbed\nor locked\u0026quot;. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository\nproperty whose name suggests that it relates to the CodeQL Action, but\nwhich is not one of the properties recognised by the current version of\nthe CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip\ncollecting file coverage information on pull requests to improve\nanalysis performance. File coverage information will still be computed\non non-PR analyses. Pull request analyses will log a warning about this\nupcoming change. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a\ncustom repository property with the name\n\u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type\n\u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in\nthe repository\u0027s settings. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e.\nAlternatively, if you are using an advanced setup workflow, you can set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch\nto an advanced setup workflow and set the\n\u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to\n\u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set\nthe \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable\nto \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea\nbug\u003c/a\u003e which caused the CodeQL Action to fail loading repository\nproperties if a \u0026quot;Multi select\u0026quot; repository property was\nconfigured for the repository. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom\nrepository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the\ncustomization of features such as\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only\navailable on GitHub.com. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e can be configured with OIDC-based authentication\nfor organizations, the CodeQL Action will now be able to accept such\nconfigurations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would\nfail with the error \u0026quot;Response body object should not be disturbed\nor locked\u0026quot;. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository\nproperty whose name suggests that it relates to the CodeQL Action, but\nwhich is not one of the properties recognised by the current version of\nthe CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.5 - 02 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to\ndisable \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository\nproperty with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and\nthe type \u0026quot;True/false\u0026quot; in the organization\u0027s settings. Then in\nthe repository\u0027s settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to\ndisable improved incremental analysis. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e. This\nfeature is not yet available on GitHub Enterprise Server. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e fails on a runner — potentially due to\ninsufficient disk space — the failure is recorded in the Actions cache\nso that subsequent runs will automatically skip improved incremental\nanalysis until something changes (e.g. a larger runner is provisioned or\na new CodeQL version is released). We expect to roll this change out to\neveryone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe minimum memory check for improved incremental analysis is now\nskipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3515\"\u003e#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduced log levels for best-effort private package registry\nconnection check failures to reduce noise from workflow annotations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3516\"\u003e#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which lowers the minimum disk space\nrequirement for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e, enabling it to run on standard GitHub Actions\nrunners. We expect to roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3498\"\u003e#3498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which allows the\n\u003ccode\u003estart-proxy\u003c/code\u003e action to resolve the CodeQL CLI version from\nfeature flags instead of using the linked CLI bundle version. We expect\nto roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3512\"\u003e#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe previously experimental changes from versions 4.32.3, 4.32.4,\n3.32.3 and 3.32.4 are now enabled by default. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3503\"\u003e#3503\u003c/a\u003e,\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3504\"\u003e#3504\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.4 - 20 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.2\"\u003e2.24.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3493\"\u003e#3493\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which improves how certificates are\ngenerated for the authentication proxy that is used by the CodeQL Action\nin Default Setup when \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries are configured\u003c/a\u003e. This is expected to generate more\nwidely compatible certificates and should have no impact on analyses\nwhich are working correctly already. We expect to roll this change out\nto everyone in February. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3473\"\u003e#3473\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen the CodeQL Action is run \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/scan-code-for-vulnerabilities/troubleshooting/troubleshooting-analysis-errors/logs-not-detailed-enough#creating-codeql-debugging-artifacts-for-codeql-default-setup\"\u003ewith\ndebugging enabled in Default Setup\u003c/a\u003e and \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries are configured\u003c/a\u003e, the \u0026quot;Setup proxy for\nregistries\u0026quot; step will output additional diagnostic information that\ncan be used for troubleshooting. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3486\"\u003e#3486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded a setting which allows the CodeQL Action to enable network\ndebugging for Java programs. This will help GitHub staff support\ncustomers with troubleshooting issues in GitHub-managed CodeQL\nworkflows, such as Default Setup. This setting can only be enabled by\nGitHub staff. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3485\"\u003e#3485\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded a setting which enables GitHub-managed workflows, such as\nDefault Setup, to use a \u003ca\nhref\u003d\"https://github.com/dsp-testing/codeql-cli-nightlies\"\u003enightly\nCodeQL CLI release\u003c/a\u003e instead of the latest, stable release that is\nused by default. This will help GitHub staff support customers whose\nanalyses for a given repository or organization require early access to\na change in an upcoming CodeQL CLI release. This setting can only be\nenabled by GitHub staff. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3484\"\u003e#3484\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.3 - 13 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded experimental support for testing connections to \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e. This feature is not currently enabled for any\nanalysis. In the future, it may be enabled by default for Default Setup.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3466\"\u003e#3466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.2 - 05 Feb 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/b1bff81932f5cdfc8695c7752dcee935dcd061c8\"\u003e\u003ccode\u003eb1bff81\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3574\"\u003e#3574\u003c/a\u003e\nfrom github/update-v4.32.7-7dd76e6bf\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/e682234222f60d9549e37004a04a8f097bbd5798\"\u003e\u003ccode\u003ee682234\u003c/code\u003e\u003c/a\u003e\nAdd changelog entry for \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3570\"\u003e#3570\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/95be291f41a39216811b3ce1a63a8df71d40d405\"\u003e\u003ccode\u003e95be291\u003c/code\u003e\u003c/a\u003e\nBump minor version\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/59bcb6025e4788109a6bb8f7ac4ad9c6a8d6beeb\"\u003e\u003ccode\u003e59bcb60\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.32.7\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/7dd76e6bf79d24133aa649887a6ee01d8b063816\"\u003e\u003ccode\u003e7dd76e6\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3572\"\u003e#3572\u003c/a\u003e\nfrom github/mbg/pr-checks/eslint\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/e3200e331bf51e47d45a8a5645d2a125c8a8a643\"\u003e\u003ccode\u003ee3200e3\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3563\"\u003e#3563\u003c/a\u003e\nfrom github/mbg/private-registry/oidc\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/4c356c71a28eb968dbcf4fb717211e82f406874f\"\u003e\u003ccode\u003e4c356c7\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3570\"\u003e#3570\u003c/a\u003e\nfrom github/mbg/repo-props/warn-on-unexpected-props\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/b4937c19e53d395cc647fe16c4e00788a4e7ded3\"\u003e\u003ccode\u003eb4937c1\u003c/code\u003e\u003c/a\u003e\nOnly emit one message with accumulated property names\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/136b8ab3777165e3ec7a19faa7ef9732ace305da\"\u003e\u003ccode\u003e136b8ab\u003c/code\u003e\u003c/a\u003e\nRemove \u003ccode\u003ecache-dependency-path\u003c/code\u003e options as well\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/a5aba5952cd5add76ec9f971654d61461a3ac2bd\"\u003e\u003ccode\u003ea5aba59\u003c/code\u003e\u003c/a\u003e\nRemove \u003ccode\u003epackage-lock.json\u003c/code\u003e that\u0027s no longer needed\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/0d579ffd059c29b07949a3cce3983f0780820c98...b1bff81932f5cdfc8695c7752dcee935dcd061c8\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7e4606da87931662d66c8e3ac425eec087d17053",
      "tree": "11c669b9077dfad98dbc435bad7574da83eae4a1",
      "parents": [
        "556c7ca95c6a309278c6cee98129d573827a05b4"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Thu Mar 26 13:17:43 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 26 13:17:43 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ 04f3bc01d..972e4ab4a (2 commits) (#6584)\n\nhttps://github.com/abseil/abseil-cpp/compare/04f3bc01d12c...972e4ab4a076\n\nCreated with:\n  roll-dep external/abseil_cpp\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "556c7ca95c6a309278c6cee98129d573827a05b4",
      "tree": "9316130adfb048792ae73176eea8b1574d048d1d",
      "parents": [
        "42956b77fea93fb1e1824d20169f174419e9845d"
      ],
      "author": {
        "name": "Diego Novillo",
        "email": "dnovillo@nvidia.com",
        "time": "Tue Mar 24 17:57:43 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 24 17:57:43 2026 -0400"
      },
      "message": "spirv-dis: Add --handle-unknown-opcodes flag (#6604)\n\nThis addresses a frequent issue we have when working with new\nextensions/instructions in SPIR-V. Often, the assembler/disassembler\nwill not understand the new opcodes, so running `spirv-dis` on such a\nmodule just errors out.\n\nIn #6024 Cassie added support for `OpUnknown` to the assembler, so if\n`spirv-dis` were to emit `OpUnknown` when it finds an instruction it\ndoesn\u0027t know, we would be able to get a textual representation that can\nbe re-assembled even when there are unknown instructions. The main use\nI\u0027m thinking of here is testing. When calling `spirv-dis\n--handle-unknown-opcodes`:\n\n- Unknown opcodes: the instruction words are consumed raw and the\ninstruction is passed to the callback.\n- Unknown extended instruction numbers in semantic sets: parsing\ncontinues by treating the remaining operands as\n`SPV_OPERAND_TYPE_VARIABLE_ID`.\n- Known opcodes with unknown enum operands (`StorageClass`,\n`Capability`, `FunctionControl`, `MemoryAccess`, etc.): re-emits the\ninstruction as raw data.\n\nIn all three cases the disassembler emits:\n\n```\n  OpUnknown(\u003copcode\u003e, \u003cword_count\u003e) \u003cword[1]\u003e ... \u003cword[n]\u003e\n```\n\nAdded several tests to validate that it is possible to round-trip a\nSPIR-V module containing new instructions that the assembler still does\nnot understand.\n\nThere is one limitation that is possible to fix, but it is not a big\ndeal in the use case I\u0027m considering. When the disassembler emits\n`OpUnknown` operand words as bare decimal integers, the assembler does\nnot track those integers as ID definitions. If an unknown instruction\ndefines a result ID that is larger than every ID in the rest of the\nmodule, the reassembled module\u0027s ID bound will be too low.\n\nThis is not a concern for round-trips that do not involve validation.\nThe instruction words in the reassembled binary are byte-for-byte\nidentical to the original and only the module header ID bound field may\nbe wrong. Tools that do not validate the header are unaffected.\n\nOne way to fix this would be for the disassembler to emit all\n`OpUnknown` operands as ID references instead of bare decimal integers.\nThe issue is that words which are plain integer immediates (not IDs)\nwould also be treated as ID references, causing the reassembled module\u0027s\nID bound to be larger than necessary. This would be harmless, I think.\n\nThe real problem is with string operands.\n`SPV_OPERAND_TYPE_OPTIONAL_CIV` also accepts string literals, and a\nmulti-word string packed into `uint32_t` words must be emitted as a\nquoted string token, not as `%N`. Without grammar, the disassembler\ncannot tell which words start a string. String operands are not common,\nso this may not be a big issue."
    },
    {
      "commit": "42956b77fea93fb1e1824d20169f174419e9845d",
      "tree": "b749d4b87a13b8bf619e8ff9d7a16d7864d25a38",
      "parents": [
        "8a13595dd4ae5049ef42d0f30297d0c427db54b5"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Mar 24 12:46:53 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 24 12:46:53 2026 -0400"
      },
      "message": "spirv-val: Add Vulkan Image Format check (#6597)\n\n4 years, and a 3rd try of\nhttps://github.com/KhronosGroup/SPIRV-Tools/pull/4748 and\nhttps://github.com/KhronosGroup/SPIRV-Tools/pull/5458 to get\n`VUID-StandaloneSpirv-Image-04965` in\n\nLast time this stalled on\nhttps://gitlab.khronos.org/spirv/SPIR-V/-/issues/766 /\nhttps://gitlab.khronos.org/spirv/SPIR-V/-/merge_requests/302/"
    },
    {
      "commit": "8a13595dd4ae5049ef42d0f30297d0c427db54b5",
      "tree": "7d7c65b4925b752e99b3f23771539bfad9e60498",
      "parents": [
        "93cde4f5ce430f0f74b13dfa0e573b5105b1cfbe"
      ],
      "author": {
        "name": "Diego Novillo",
        "email": "dnovillo@nvidia.com",
        "time": "Thu Mar 19 07:46:33 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 08:46:33 2026 -0400"
      },
      "message": "spirv-val: Allow spec constants as DebugTypeArray component counts (#6608)\n\nThis updates the validator to match the spec update in\nhttps://github.com/KhronosGroup/SPIRV-Registry/pull/371 to allow any\nconstant instruction as the component count operand of `DebugTypeArray`.\n\nIt fixes the glslang issue\nhttps://github.com/KhronosGroup/glslang/issues/4186.\n\nThe constant check now determines whether it\u0027s checking for\nOpenCL.DebugInfo.100 or NSDI. The new rule only affects NSDI."
    },
    {
      "commit": "93cde4f5ce430f0f74b13dfa0e573b5105b1cfbe",
      "tree": "c4525759e802d6a42647304a7b2f58ff9f67fe6b",
      "parents": [
        "26fb01b92b00e4f40452d7c89494cf72a9f68a8f"
      ],
      "author": {
        "name": "Nathan Gauër",
        "email": "brioche@google.com",
        "time": "Thu Mar 19 11:56:24 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 06:56:24 2026 -0400"
      },
      "message": "opt: fix OpUntypedVariableKHR removed from interfaces (#6607)\n\nThe remove_unused_interface pass was unaware of the OpUntypedVariableKHR\nopcode, and thus was wrongly removing those from the listed interfaces."
    },
    {
      "commit": "26fb01b92b00e4f40452d7c89494cf72a9f68a8f",
      "tree": "bc0718d8b3a4bcc3a3b25d58cd353bfecf648c6b",
      "parents": [
        "8d0044201984c645ef1d048a5c5a325b77a5146e"
      ],
      "author": {
        "name": "Paulius Velesko",
        "email": "pvelesko@pglc.io",
        "time": "Thu Mar 19 00:06:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 22:06:29 2026 +0000"
      },
      "message": "Add validation support for Intel SPIR-V extensions (#6232)\n\nThis PR adds validation support for three Intel SPIR-V extensions:\n\nOpConstantFunctionPointerINTEL: Added validation logic and test coverage\nArbitraryPrecisionIntegersINTEL: Added type validation support and tests\nOpAliasScopeDeclINTEL/OpAliasScopeListDeclINTEL: Added ID validation\nsupport and tests\n\nFixes #6034"
    },
    {
      "commit": "8d0044201984c645ef1d048a5c5a325b77a5146e",
      "tree": "bf9d34e5c5eb9b4ea5df31e820ed540a1a4bde4b",
      "parents": [
        "e4bceacf59fdfe742047e94e41ef65a48999a0dd"
      ],
      "author": {
        "name": "Nathan Gauër",
        "email": "brioche@google.com",
        "time": "Tue Mar 17 09:47:53 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 17 09:47:53 2026 +0100"
      },
      "message": "opt: allow aggressive DCE to optimize untyped_pointers (#6602)\n\nThis will be required to allow DXC generating descriptor heaps code\nwhich uses untyped pointers/descriptor_heap"
    },
    {
      "commit": "e4bceacf59fdfe742047e94e41ef65a48999a0dd",
      "tree": "bda78c7dc69071474a43dccd7ca99d5c69c2b538",
      "parents": [
        "989e29a489ba32e451d9e23c9016999eb75378e4"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sun Mar 15 21:10:24 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 15 21:10:24 2026 -0400"
      },
      "message": "spirv-val: Add remaining OpSpecConstantOp (#6596)\n\nMy personal final PR for\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6564\n\nThere is still the access chains left, but those are going to be ugly,\nand since its only a `Kernel` feature, I don\u0027t have the bandwidth to\nlook into right now. (But did left some test for the person who does in\nthe future)"
    },
    {
      "commit": "989e29a489ba32e451d9e23c9016999eb75378e4",
      "tree": "b999ddabf5089bca02adea85fb1b0e84b0fde77d",
      "parents": [
        "5d6745bfdd3bdb3a5e04a6016104851244e12cdb"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Fri Mar 13 22:10:49 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 13 22:10:49 2026 -0400"
      },
      "message": "Improve constant composite validation (#6598)\n\n* Refactored a lot of repetitive code\n* Improved operand checks to disallow spec constants in regular\nconstants\n* Removed some tests that no longer trigger appropriate messages\n  * replaced more generally"
    },
    {
      "commit": "5d6745bfdd3bdb3a5e04a6016104851244e12cdb",
      "tree": "3d8258e4d8fc05d8328f33048264e454fa4906c0",
      "parents": [
        "5a1eea1546c372a945a27d9b10e0a059db6cc651"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Fri Mar 13 09:32:53 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 13 09:32:53 2026 -0400"
      },
      "message": "Improve variable pointer validation (#6595)\n\nFixes #6532\n\n* Check through types to ensure only valid pointers are allocated in\nlogical variables\n* Fix up some invalid tests"
    },
    {
      "commit": "5a1eea1546c372a945a27d9b10e0a059db6cc651",
      "tree": "989f4d8e7cf64cbbca2fc722c3e9b0de22cd893b",
      "parents": [
        "7eda548e509357103af154ab70f63a8ffdbb4934"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Mar 12 22:21:46 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 22:21:46 2026 -0400"
      },
      "message": "spirv-val: Add SubpassData and TileImageEXT checks (#6591)\n\nAdds `VUID-StandaloneSpirv-SubpassData-04660` and\n`VUID-StandaloneSpirv-None-08720`"
    },
    {
      "commit": "7eda548e509357103af154ab70f63a8ffdbb4934",
      "tree": "4da07061f273fd949e2240edf9272725fabd0460",
      "parents": [
        "b8ad063791ad9e338f93b78e07fa5287294f43da"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Mar 12 15:34:03 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 15:34:03 2026 -0400"
      },
      "message": "spirv-val: Breakup ValidateVariable (#6592)\n\nI tried to work on `ValidateVariable` and its honestly a 800 line mess\nof a function and no clue \"where\" to add anything\n\nI tried to break it up into some more smaller functions and group things\ntogether to make it more manageable"
    },
    {
      "commit": "b8ad063791ad9e338f93b78e07fa5287294f43da",
      "tree": "53942a5b4f63e08d65214091cec93568937f1928",
      "parents": [
        "334a9b71795f66477d4b60f9459ac160a081d939"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Mar 12 12:02:18 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 12:02:18 2026 -0400"
      },
      "message": "spirv-val: Add missing SPV_EXT_descriptor_indexing caps (#6589)\n\n(from\nhttps://github.com/KhronosGroup/Vulkan-ValidationLayers/issues/11860)\nAdds two missing `SPV_EXT_descriptor_indexing` from being allowed in\nVulkan1.2"
    },
    {
      "commit": "334a9b71795f66477d4b60f9459ac160a081d939",
      "tree": "7a45c57edf64560f87340a18bbf7ddf167fddcd0",
      "parents": [
        "c75e3498595a4c1fcf67045e58c40d215a3d3901"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Mar 12 11:14:40 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 11:14:40 2026 -0400"
      },
      "message": "spirv-val: More OpSpecConstantOp (#6585)\n\nAll is left after for\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6564 is the\nVectorShuffle/CompositeInsert/CompositeExtract and the AccessChains,\nthese will need some more changes to passing in the operand index, so\nsaving them for last"
    },
    {
      "commit": "c75e3498595a4c1fcf67045e58c40d215a3d3901",
      "tree": "1ba4f2461638743ec68282ba0b621d6ca101246c",
      "parents": [
        "85dc1ee2348bd28985e40a3f60e0b8eec2aed422"
      ],
      "author": {
        "name": "alan-baker",
        "email": "alanbaker@google.com",
        "time": "Thu Mar 12 09:52:17 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 09:52:17 2026 -0400"
      },
      "message": "Add validation for SPV_EXT_replicated_composites (#6583)\n\nFixes #6529\n\n* OpConstantCompositeReplicateEXT\n* OpSpecConstantCompositeReplicateEXT\n* OpCompositeConstructReplicateEXT"
    },
    {
      "commit": "85dc1ee2348bd28985e40a3f60e0b8eec2aed422",
      "tree": "f6e6255cbf6a0fa9cae66cee3eebd297bd172ee2",
      "parents": [
        "281fecf9d669adc3aec219b6c1fe103a2915af41"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Mar 11 22:14:52 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 22:14:52 2026 -0400"
      },
      "message": "spirv-val: Add OpSpecConstantOp for Arithmetics and Bitwise (#6582)\n\nanother chunk of https://github.com/KhronosGroup/SPIRV-Tools/issues/6564\n\nadds `ArithmeticsPass` and `BitwisePass`"
    },
    {
      "commit": "281fecf9d669adc3aec219b6c1fe103a2915af41",
      "tree": "c1348e42f14310626294d51a97ca03b2fe8fbf7b",
      "parents": [
        "6e9d60d80905f561858c2b1234bbb82bb529c044"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Wed Mar 11 22:14:15 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 22:14:15 2026 -0400"
      },
      "message": "spirv-val: Label LongVector VUID (#6581)\n\nWe decided today to move these to Standalone VUID\nhttps://gitlab.khronos.org/vulkan/vulkan/-/merge_requests/8106/diffs"
    },
    {
      "commit": "6e9d60d80905f561858c2b1234bbb82bb529c044",
      "tree": "451e4d61814e469e05c809c2240bee6601a03edc",
      "parents": [
        "40093b5e37ff92f9b63329f9ccd701ae1a12e0d2"
      ],
      "author": {
        "name": "Marijn Suijten",
        "email": "marijns95@gmail.com",
        "time": "Wed Mar 11 15:55:51 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 10:55:51 2026 -0400"
      },
      "message": "Optimize `SPV_EXT_opacity_micromap` and `SPV_EXT_shader_invocation_reorder` (#6571)\n\nIt\u0027s been a while since I last added extensions to these lists, but I\njust ran into a long-forgotten related issue again that DXC outputs\ninvalid SPIR-V before it\u0027s stripped away by `spirv-opt`:\nhttps://github.com/microsoft/DirectXShaderCompiler/issues/8210.\n\nShaders with these extensions weren\u0027t yet extensively tested but this at\nleast gets us past `spir-val` in both DXC (can also be disabled with\n`-Vd`) and the validation layers.\n\n---\n\nI\u0027m probably way out of my league to ask, but is there still much\nsignificance to `extensions_allowlist_`? It seems like a maintenance\nburden that\u0027s very easy to miss, for (currently) a single extension\nthat\u0027s specifically commented out to not be optimized.\n\nIt\u0027s also mostly duplicated but not entirely in sync across all 4 passes\neither. I even noticed that `SPV_KHR_shader_clock` which **I added** to\n`dead_code_elim_pass` in\nhttps://github.com/KhronosGroup/SPIRV-Tools/pull/4049 isn\u0027t in any other\nfile, which must have been an oversight on my part but also means that\npresence of this extension erroneously disables all the other 3 passes."
    },
    {
      "commit": "40093b5e37ff92f9b63329f9ccd701ae1a12e0d2",
      "tree": "747f92cf222625f9a88f45ea6407b11e00e64ad1",
      "parents": [
        "47eef7be333fe709795fd695ba4f8e58c70a0cf0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Mar 11 10:50:02 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 10:50:02 2026 -0400"
      },
      "message": "build(deps): bump github/codeql-action from 4.32.5 to 4.32.6 in the github-actions group (#6572)\n\nBumps the github-actions group with 1 update:\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `github/codeql-action` from 4.32.5 to 4.32.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.32.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/0d579ffd059c29b07949a3cce3983f0780820c98\"\u003e\u003ccode\u003e0d579ff\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3551\"\u003e#3551\u003c/a\u003e\nfrom github/update-v4.32.6-72d2d850d\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/d4c6be7cf1c47a33a06fa9183269e133e6863574\"\u003e\u003ccode\u003ed4c6be7\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/72d2d850d1f91d4e1e024f4cf4276fd16bb68462\"\u003e\u003ccode\u003e72d2d85\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3548\"\u003e#3548\u003c/a\u003e\nfrom github/update-bundle/codeql-bundle-v2.24.3\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/23f983ce00d9a853697a6aaa9eae8d5abbf14849\"\u003e\u003ccode\u003e23f983c\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3544\"\u003e#3544\u003c/a\u003e\nfrom github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/832e97ccad228ef72e06ffee26f6251bceeb7e5f\"\u003e\u003ccode\u003e832e97c\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3545\"\u003e#3545\u003c/a\u003e\nfrom github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/5ef38c0b13c2f0f5ce928cb7706f5fb19fc97ae2\"\u003e\u003ccode\u003e5ef38c0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3546\"\u003e#3546\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/tar-7.5.10\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/80c9cda73902bba67939606c4bf3a1d9606bb150\"\u003e\u003ccode\u003e80c9cda\u003c/code\u003e\u003c/a\u003e\nAdd changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f2669dd916c673b2811839169929a8ba71bb7634\"\u003e\u003ccode\u003ef2669dd\u003c/code\u003e\u003c/a\u003e\nUpdate default bundle to codeql-bundle-v2.24.3\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/bd03c44cf40965f5476f66fad404194e4cb35710\"\u003e\u003ccode\u003ebd03c44\u003c/code\u003e\u003c/a\u003e\nMerge branch \u0027main\u0027 into\ndependabot/github_actions/dot-github/workflows/actio...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/102d7627b63c066871badf0743c11b2f6dd9c9e9\"\u003e\u003ccode\u003e102d762\u003c/code\u003e\u003c/a\u003e\nBump tar from 7.5.7 to 7.5.10\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/c793b717bc78562f491db7b0e93a3a178b099162...0d579ffd059c29b07949a3cce3983f0780820c98\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.32.5\u0026new-version\u003d4.32.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "47eef7be333fe709795fd695ba4f8e58c70a0cf0",
      "tree": "1ffdbbfa8b4eb774a2cc61de12d86332da62f8bc",
      "parents": [
        "c1ad8d6247520655a3debaae46be9e764402cee5"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Wed Mar 11 10:03:07 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 10:03:07 2026 -0400"
      },
      "message": "Roll external/abseil_cpp/ 3b777f679..267879b45 (1 commit) (#6569)\n\nhttps://github.com/abseil/abseil-cpp/compare/3b777f67987d...267879b45aab\n\nCreated with:\n  roll-dep external/abseil_cpp\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "c1ad8d6247520655a3debaae46be9e764402cee5",
      "tree": "d7d211a0f5d1ad1801c7b2226ee75014af008128",
      "parents": [
        "608e62007ec9d6b9ef3cf9c76fd247e623e80ea2"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Mar 10 13:57:23 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 10 13:57:23 2026 -0400"
      },
      "message": "spirv-val: Get things to cases for OpSpecConstantOp (#6579)\n\nFor the \"final prep\" for\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6564\n\nMade a commit per file (incase people have fun with merge conflicts) to\nmake main pass function call into smaller functions, this will allow for\nthe `OpSpecConstantOp` usage to work as well\n\nThis was a pure copy-and-paste PR"
    },
    {
      "commit": "608e62007ec9d6b9ef3cf9c76fd247e623e80ea2",
      "tree": "065c45f049c6fa79a5332b866e19dbc6679f821f",
      "parents": [
        "2aa281c16ca42348b2e5262c809318a8935e3989"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Tue Mar 10 09:54:08 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 10 09:54:08 2026 -0400"
      },
      "message": "spirv-val: Add remaining Convert SpecConstantOp (#6578)\n\nspirv-val: Adds the rest of the `Convert` for\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6564"
    },
    {
      "commit": "2aa281c16ca42348b2e5262c809318a8935e3989",
      "tree": "51a4b94fbe3f03e168e123411bc3a145cd203b77",
      "parents": [
        "05ac2f3a4f962704565aa6f512801a274f7be98a"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Mar 09 17:18:00 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 09 17:18:00 2026 -0400"
      },
      "message": "spirv-val: Add U/S/FConvert SpecConstantOp (#6576)\n\nFirst few of https://github.com/KhronosGroup/SPIRV-Tools/issues/6564\n\nI chose `UConvert`/`SConvert`/`FConvert` as I knew they had the most\n\"needed to fix in other tests\" such that future additions are more\n\"additive\" only from here"
    },
    {
      "commit": "05ac2f3a4f962704565aa6f512801a274f7be98a",
      "tree": "d574e3ea1061687546dd67ebeba372799cde6ea8",
      "parents": [
        "7d8d9e58c384949f1615c069d4c9346bf51b9738"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Mar 09 17:14:19 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 09 17:14:19 2026 -0400"
      },
      "message": "spirv-val: Label VU 11165 OpCopyMemorySized (#6577)\n\nNew error\n\n\u003e [VUID-RuntimeSpirv-Size-11165] Size must be a multiple of 4. This is\nvalid if Source (StorageBuffer) and Target (StorageBuffer) storage\nclasses both support either 8-bit or 16-bit\n\n1. This adds the VUID to be tracked in VVL\n2. The current error message didn\u0027t make it obvious **why** it must be a\nmultiple of 2 or 4"
    },
    {
      "commit": "7d8d9e58c384949f1615c069d4c9346bf51b9738",
      "tree": "f336323b6176ee90795b33058ee5c79fdb34cdba",
      "parents": [
        "93b56e1990705c5f78be53ad910414aa187f1095"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Sat Mar 07 07:19:10 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Mar 07 07:19:10 2026 -0500"
      },
      "message": ".gitignore: android_test local build artifacts (#6574)\n\nIgnore directories created during the kokoro/android build flow."
    },
    {
      "commit": "93b56e1990705c5f78be53ad910414aa187f1095",
      "tree": "cc1e5fb7d0cfc686119a6868b02692393ea0462b",
      "parents": [
        "69f1c0dbc881676d09527edcc9ebb7c6e683e6fa"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Mar 06 17:31:54 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 06 17:31:54 2026 -0500"
      },
      "message": "kokoro:  reorg build config dirs to match their names (#6573)"
    },
    {
      "commit": "69f1c0dbc881676d09527edcc9ebb7c6e683e6fa",
      "tree": "5762fe28dd02d2b82fed37726c7c108088ff83ae",
      "parents": [
        "915b8a63fa303edb9d58d57ba33ba3e3a12a9681"
      ],
      "author": {
        "name": "alister-chowdhury",
        "email": "30833607+alister-chowdhury@users.noreply.github.com",
        "time": "Fri Mar 06 16:20:19 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 06 16:20:19 2026 +0000"
      },
      "message": "spirv-opt: Adding nested reassociation rules (#6453)\n\n**ReassociateNestedGenericInt**\nReassociate integer instructions where both operands share the same\nopcode and both source instructions contain a constant.\ne.g:\n```\n  (a * C0) * (C1 * b) \u003d (C0 * C1) * (a * b)\n  (a ^ C0) ^ (b ^ C1) \u003d (C0 ^ C1) ^ (a ^ b)\n  (C0 | a) | (b | C1) \u003d (C0 | C1) | (a | b)\n  (a \u0026 C0) \u0026 (b \u0026 C1) \u003d (C0 \u0026 C1) \u0026 (a \u0026 b)\n```\n\n**ReassociateNestedMulDivFloat**\nReassociate floating point mul/div instructions, which have mul/div\ninputs, both of which contain a constant.\ne.g:\n```\n  (a * C0) / (C1 / b) \u003d  (C0 / C1) * (a * b)\n  (C0 / a) * (b / C1) \u003d  (C0 / C1) * (b / a)\n  (a / C0) / (b * C1) \u003d  (1 / (C0 * C1)) * (a / b)\n```\n\n**ReassociateNestedAddSub**\nReassociate add/sub instructions, which have add/sub inputs, both of\nwhich contain a constant.\ne.g:\n```\n  (a + C0) - (C1 - b) \u003d  (C0 - C1) + (a + b)\n  (C0 - a) + (b - C1) \u003d  (C0 - C1) + (b - a)\n  (a - C0) - (b + C1) \u003d (-C0 - C1) + (a - b)\n```\n\n---------\n\nCo-authored-by: Steven Perron \u003cstevenperron@google.com\u003e"
    },
    {
      "commit": "915b8a63fa303edb9d58d57ba33ba3e3a12a9681",
      "tree": "bbd4c5c1250bb31bb88aab26f2d8712f37eec5db",
      "parents": [
        "d83d9363b0b4466b78331f73ab64550416389d95"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Mar 05 21:42:57 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 05 21:42:57 2026 -0500"
      },
      "message": "spirv-val: Create functions for convert validation (#6570)\n\nFirst step towards\nhttps://github.com/KhronosGroup/SPIRV-Tools/issues/6564 where we need to\nfirst create separate functions instead of the huge mega function\n\nThis was a copy-and-paste change"
    },
    {
      "commit": "d83d9363b0b4466b78331f73ab64550416389d95",
      "tree": "807f049ac324a0d83f00250cd96d5c8dc2a6ee5a",
      "parents": [
        "46b1e005696db761fd19067cda0d6d93e4d0b63c"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Wed Mar 04 14:05:50 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 04 14:05:50 2026 -0500"
      },
      "message": "val: more validation of OpTypeFloat (#6568)\n\n- add tests for too many arguments\n- check if 32-bit and 64-bit float types have an encoding arg\n- check encoding arg for 16 bit types"
    },
    {
      "commit": "46b1e005696db761fd19067cda0d6d93e4d0b63c",
      "tree": "a128c057928c2b17c334ceabec72fac675cbd11b",
      "parents": [
        "7108829b7bbe18a370cef91b7ce8307d57a2baa2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Mar 04 10:32:12 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 04 10:32:12 2026 -0500"
      },
      "message": "build(deps): bump github/codeql-action from 4.32.4 to 4.32.5 in the github-actions group (#6566)\n\nBumps the github-actions group with 1 update:\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `github/codeql-action` from 4.32.4 to 4.32.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.32.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to\ndisable \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository\nproperty with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and\nthe type \u0026quot;True/false\u0026quot; in the organization\u0027s settings. Then in\nthe repository\u0027s settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to\ndisable improved incremental analysis. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e. This\nfeature is not yet available on GitHub Enterprise Server. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e fails on a runner — potentially due to\ninsufficient disk space — the failure is recorded in the Actions cache\nso that subsequent runs will automatically skip improved incremental\nanalysis until something changes (e.g. a larger runner is provisioned or\na new CodeQL version is released). We expect to roll this change out to\neveryone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe minimum memory check for improved incremental analysis is now\nskipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3515\"\u003e#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduced log levels for best-effort private package registry\nconnection check failures to reduce noise from workflow annotations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3516\"\u003e#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which lowers the minimum disk space\nrequirement for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e, enabling it to run on standard GitHub Actions\nrunners. We expect to roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3498\"\u003e#3498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which allows the\n\u003ccode\u003estart-proxy\u003c/code\u003e action to resolve the CodeQL CLI version from\nfeature flags instead of using the linked CLI bundle version. We expect\nto roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3512\"\u003e#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe previously experimental changes from versions 4.32.3, 4.32.4,\n3.32.3 and 3.32.4 are now enabled by default. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3503\"\u003e#3503\u003c/a\u003e,\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3504\"\u003e#3504\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.32.5 - 02 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the\n\u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to\ndisable \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository\nproperty with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and\nthe type \u0026quot;True/false\u0026quot; in the organization\u0027s settings. Then in\nthe repository\u0027s settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to\ndisable improved incremental analysis. For more information, see \u003ca\nhref\u003d\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging\ncustom properties for repositories in your organization\u003c/a\u003e. This\nfeature is not yet available on GitHub Enterprise Server. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e fails on a runner — potentially due to\ninsufficient disk space — the failure is recorded in the Actions cache\nso that subsequent runs will automatically skip improved incremental\nanalysis until something changes (e.g. a larger runner is provisioned or\na new CodeQL version is released). We expect to roll this change out to\neveryone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe minimum memory check for improved incremental analysis is now\nskipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3515\"\u003e#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduced log levels for best-effort private package registry\nconnection check failures to reduce noise from workflow annotations. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3516\"\u003e#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which lowers the minimum disk space\nrequirement for \u003ca\nhref\u003d\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved\nincremental analysis\u003c/a\u003e, enabling it to run on standard GitHub Actions\nrunners. We expect to roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3498\"\u003e#3498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which allows the\n\u003ccode\u003estart-proxy\u003c/code\u003e action to resolve the CodeQL CLI version from\nfeature flags instead of using the linked CLI bundle version. We expect\nto roll this change out to everyone in March. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3512\"\u003e#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe previously experimental changes from versions 4.32.3, 4.32.4,\n3.32.3 and 3.32.4 are now enabled by default. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3503\"\u003e#3503\u003c/a\u003e,\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3504\"\u003e#3504\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.4 - 20 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.2\"\u003e2.24.2\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3493\"\u003e#3493\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which improves how certificates are\ngenerated for the authentication proxy that is used by the CodeQL Action\nin Default Setup when \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries are configured\u003c/a\u003e. This is expected to generate more\nwidely compatible certificates and should have no impact on analyses\nwhich are working correctly already. We expect to roll this change out\nto everyone in February. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3473\"\u003e#3473\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen the CodeQL Action is run \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/scan-code-for-vulnerabilities/troubleshooting/troubleshooting-analysis-errors/logs-not-detailed-enough#creating-codeql-debugging-artifacts-for-codeql-default-setup\"\u003ewith\ndebugging enabled in Default Setup\u003c/a\u003e and \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries are configured\u003c/a\u003e, the \u0026quot;Setup proxy for\nregistries\u0026quot; step will output additional diagnostic information that\ncan be used for troubleshooting. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3486\"\u003e#3486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded a setting which allows the CodeQL Action to enable network\ndebugging for Java programs. This will help GitHub staff support\ncustomers with troubleshooting issues in GitHub-managed CodeQL\nworkflows, such as Default Setup. This setting can only be enabled by\nGitHub staff. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3485\"\u003e#3485\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded a setting which enables GitHub-managed workflows, such as\nDefault Setup, to use a \u003ca\nhref\u003d\"https://github.com/dsp-testing/codeql-cli-nightlies\"\u003enightly\nCodeQL CLI release\u003c/a\u003e instead of the latest, stable release that is\nused by default. This will help GitHub staff support customers whose\nanalyses for a given repository or organization require early access to\na change in an upcoming CodeQL CLI release. This setting can only be\nenabled by GitHub staff. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3484\"\u003e#3484\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.3 - 13 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded experimental support for testing connections to \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registries\u003c/a\u003e. This feature is not currently enabled for any\nanalysis. In the future, it may be enabled by default for Default Setup.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3466\"\u003e#3466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.2 - 05 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.1\"\u003e2.24.1\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3460\"\u003e#3460\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.1 - 02 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eA warning is now shown in Default Setup workflow logs if a \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registry is configured\u003c/a\u003e using a GitHub Personal Access Token\n(PAT), but no username is configured. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3422\"\u003e#3422\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug which caused the CodeQL Action to fail when repository\nproperties cannot successfully be retrieved. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3421\"\u003e#3421\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.0 - 26 Jan 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0\"\u003e2.24.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3425\"\u003e#3425\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.11 - 23 Jan 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eWhen running a Default Setup workflow with \u003ca\nhref\u003d\"https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging\"\u003eActions\ndebugging enabled\u003c/a\u003e, the CodeQL Action will now use more unique names\nwhen uploading logs from the Dependabot authentication proxy as workflow\nartifacts. This ensures that the artifact names do not clash between\nmultiple jobs in a build matrix. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3409\"\u003e#3409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved error handling throughout the CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3415\"\u003e#3415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded experimental support for automatically excluding \u003ca\nhref\u003d\"https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github\"\u003egenerated\nfiles\u003c/a\u003e from the analysis. This feature is not currently enabled for\nany analysis. In the future, it may be enabled by default for some\nGitHub-managed analyses. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3318\"\u003e#3318\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe changelog extracts that are included with releases of the CodeQL\nAction are now shorter to avoid duplicated information from appearing in\nDependabot PRs. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3403\"\u003e#3403\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c793b717bc78562f491db7b0e93a3a178b099162\"\u003e\u003ccode\u003ec793b71\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3523\"\u003e#3523\u003c/a\u003e\nfrom github/update-v4.32.5-ca42bf226\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/06cd615ad8b3edfe6778d58fb83174989a173272\"\u003e\u003ccode\u003e06cd615\u003c/code\u003e\u003c/a\u003e\nSoften language re overlay failures\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f5516c663089381234544cc3360963ecb4620691\"\u003e\u003ccode\u003ef5516c6\u003c/code\u003e\u003c/a\u003e\nImprove changelog\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/97519e197e39ab1f818d1cd777ebde1f36b6fc8b\"\u003e\u003ccode\u003e97519e1\u003c/code\u003e\u003c/a\u003e\nUpdate release date\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/05259a1d08a6131e0365f17225b6cdd505374c9d\"\u003e\u003ccode\u003e05259a1\u003c/code\u003e\u003c/a\u003e\nAdd more changelog notes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/01ee2f785a9e66afe909ab712595ddf300b09a62\"\u003e\u003ccode\u003e01ee2f7\u003c/code\u003e\u003c/a\u003e\nAdd changelog notes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c72d9a49330eb56ae30a094ad1542127d5971876\"\u003e\u003ccode\u003ec72d9a4\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.32.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/ca42bf226a3801a25101149fe11787e34845a41d\"\u003e\u003ccode\u003eca42bf2\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3522\"\u003e#3522\u003c/a\u003e\nfrom github/henrymercer/update-supported-versions-table\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/6704d80ac6a9b194063f79c3c9d7f67dda457e70\"\u003e\u003ccode\u003e6704d80\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3520\"\u003e#3520\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/fast-xml-parser-...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/76348c0f1239a07d2ee606be6d12e01be8aa88d1\"\u003e\u003ccode\u003e76348c0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3521\"\u003e#3521\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/minimatch-3.1.5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/89a39a4e59826350b863aa6b6252a07ad50cf83e...c793b717bc78562f491db7b0e93a3a178b099162\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.32.4\u0026new-version\u003d4.32.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7108829b7bbe18a370cef91b7ce8307d57a2baa2",
      "tree": "033736dea701ee7ef1275b0950394713d4ea76b4",
      "parents": [
        "c28f5937bce369dde1d645299a8c9873da43dc72"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Wed Mar 04 09:45:48 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 04 09:45:48 2026 -0500"
      },
      "message": "Roll external/abseil_cpp/ dee6c6283..8836ff0ba (3 commits) (#6563)\n\nhttps://github.com/abseil/abseil-cpp/compare/dee6c628372a...8836ff0ba6a0\n\nCreated with:\n  roll-dep external/abseil_cpp\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "c28f5937bce369dde1d645299a8c9873da43dc72",
      "tree": "973c98a173021ddf7c4f89fa211c95e256149e82",
      "parents": [
        "6b956f34e4f26a5e53c30935863f94d227b1e6c6"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Tue Mar 03 12:11:47 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 03 12:11:47 2026 -0500"
      },
      "message": "opt: Fix build issue with gcc 16  (replaeces PR #6542) (#6567)\n\nCompiling with gcc 16 throws this error:\n\nFAILED: [code\u003d1]\nsource/opt/CMakeFiles/SPIRV-Tools-opt.dir/decoration_manager.cpp.o\n    source/opt/decoration_manager.cpp: In member function\n‘spvtools::opt::analysis::DecorationManager::CloneDecorations(unsigned\nint, unsigned int)’:\n    source/opt/decoration_manager.cpp:546:27: error:\n‘MEM[(unsigned int \u0026)\u0026op + 24]’ may be used uninitialized\n[-Werror\u003dmaybe-uninitialized]\n\n546 | if (op.words[0] \u003d\u003d from) { // add new pair of operands: (to,\nliteral)\n    source/opt/decoration_manager.cpp:545:19: note: ‘op’ declared here\n      545 |           Operand op \u003d inst-\u003eGetOperand(i);\n          |                   ^~\n    cc1plus: all warnings being treated as errors\n\nMake sure that the vector is not empty before using it.\n\nCo-authored-by: José Expósito \u003cjose.exposito89@gmail.com\u003e"
    },
    {
      "commit": "6b956f34e4f26a5e53c30935863f94d227b1e6c6",
      "tree": "0d09b221bf0e3819f03af562e0389409d5200cdb",
      "parents": [
        "4972c69eb50255b314fc0925ca757c4417e6b6c0"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Tue Mar 03 11:28:20 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 03 11:28:20 2026 -0500"
      },
      "message": "assembler: Handle leading + in hex float literals (#6565)\n\nMake it symmetric with a leading -\n\nTest underflow to zero.\n\nBug: crbug.com/488728576"
    },
    {
      "commit": "4972c69eb50255b314fc0925ca757c4417e6b6c0",
      "tree": "9a9749a7ce3d6810372079cdc95946f105339e33",
      "parents": [
        "1c8c845843ca77f70a862fc94d371d36fe703498"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Feb 27 18:15:00 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 27 18:15:00 2026 -0500"
      },
      "message": "spirv-as: Validate bit width of float types with explicit encodings (#6562)\n\nDo this in the assembler because it\u0027s silly to let it get any farther.\n\nBug: crbug.com/465892071"
    },
    {
      "commit": "1c8c845843ca77f70a862fc94d371d36fe703498",
      "tree": "0b086e7344d64dcbd71bc9433157601ba201e3ec",
      "parents": [
        "eeb5282f753f7e0fdce90e16eb7853b4c2c6e2e7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Feb 27 12:15:12 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 27 12:15:12 2026 -0500"
      },
      "message": "build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 in the github-actions group (#6561)\n\nBumps the github-actions group with 1 update:\n[actions/upload-artifact](https://github.com/actions/upload-artifact).\n\nUpdates `actions/upload-artifact` from 6.0.0 to 7.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003ev7 What\u0027s new\u003c/h2\u003e\n\u003ch3\u003eDirect Uploads\u003c/h3\u003e\n\u003cp\u003eAdds support for uploading single files directly (unzipped). Callers\ncan set the new \u003ccode\u003earchive\u003c/code\u003e parameter to \u003ccode\u003efalse\u003c/code\u003e to\nskip zipping the file during upload. Right now, we only support single\nfiles. The action will fail if the glob passed resolves to multiple\nfiles. The \u003ccode\u003ename\u003c/code\u003e parameter is also ignored with this\nsetting. Instead, the name of the artifact will be the name of the\nuploaded file.\u003c/p\u003e\n\u003ch3\u003eESM\u003c/h3\u003e\n\u003cp\u003eTo support new versions of the \u003ccode\u003e@actions/*\u003c/code\u003e packages,\nwe\u0027ve upgraded the package to ESM.\u003c/p\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd proxy integration test by \u003ca\nhref\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade the module to ESM and bump dependencies by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/762\"\u003eactions/upload-artifact#762\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport direct file uploads by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/764\"\u003eactions/upload-artifact#764\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/754\"\u003eactions/upload-artifact#754\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/upload-artifact/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f\"\u003e\u003ccode\u003ebbbca2d\u003c/code\u003e\u003c/a\u003e\nSupport direct file uploads (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/764\"\u003e#764\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/589182c5a4cec8920b8c1bce3e2fab1c97a02296\"\u003e\u003ccode\u003e589182c\u003c/code\u003e\u003c/a\u003e\nUpgrade the module to ESM and bump dependencies (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/762\"\u003e#762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/47309c993abb98030a35d55ef7ff34b7fa1074b5\"\u003e\u003ccode\u003e47309c9\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/754\"\u003e#754\u003c/a\u003e\nfrom actions/Link-/add-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/02a8460834e70dab0ce194c64360c59dc1475ef0\"\u003e\u003ccode\u003e02a8460\u003c/code\u003e\u003c/a\u003e\nAdd proxy integration test\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/b7c566a772e6b6bfb58ed0dc250532a479d7789f...bbbca2ddaa5d8feaa63e36b76fdaad77386f024f\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/upload-artifact\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6.0.0\u0026new-version\u003d7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "eeb5282f753f7e0fdce90e16eb7853b4c2c6e2e7",
      "tree": "4adb2a4b5d217c16316a1a9369deb5cad8289308",
      "parents": [
        "ff6adfd1511c21fb92e79384bec96955c400b84c"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Feb 27 11:25:43 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 27 11:25:43 2026 -0500"
      },
      "message": "roll deps (#6554)\n\n- **Roll external/googletest/ e9907112b..a40796659 (2 commits)**\n- **Roll external/abseil_cpp/ 64c1b40d7..4dc2be8a9 (4 commits)**\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "ff6adfd1511c21fb92e79384bec96955c400b84c",
      "tree": "d352df300217bd1bd922f53d6c5ff3431c0058fa",
      "parents": [
        "90d8e7d8ae287980dc9bda69e1bf03f072351f2f"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Fri Feb 27 10:04:44 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 27 10:04:44 2026 -0500"
      },
      "message": "kokoro: use \"gcloud storage\" instead of gsutil (#6551)\n\ngsutil is deprecated"
    },
    {
      "commit": "90d8e7d8ae287980dc9bda69e1bf03f072351f2f",
      "tree": "b1d520b285fab6c65dabd5d79a1f860924e86229",
      "parents": [
        "05bbb6906a5b52d590adda62b9ef756e7cb13569"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Feb 26 23:22:00 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 26 23:22:00 2026 -0500"
      },
      "message": "spirv-val: Add constant check to mesh execution mode (#6560)\n\nWe discussed in https://gitlab.khronos.org/vulkan/vulkan/-/issues/4694\nthat having a `SetMeshOutputsEXT` with bogus constant values should be\ndisallowed, even if never taken as it currently causes various drivers\nissues trying to lower that code\n\nI added test to ensure that with spec constants, this is only validated\nwhen they are frozen"
    },
    {
      "commit": "05bbb6906a5b52d590adda62b9ef756e7cb13569",
      "tree": "f321cf32822ec890df846fcade4bde14290eeec6",
      "parents": [
        "d96e27bb8583639743240d9640d808e748e7de0c"
      ],
      "author": {
        "name": "Pankaj Mistry",
        "email": "63069047+pmistryNV@users.noreply.github.com",
        "time": "Thu Feb 26 16:25:42 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 26 19:25:42 2026 -0500"
      },
      "message": "Fix C++20 compilation: add \u0027u\u0027 suffix to 4294967295 integer literal (#6557)\n\nThe literal 4294967295 (UINT32_MAX / 0xFFFFFFFF) exceeds INT_MAX\n(2,147,483,647) on 32-bit systems. In C++20, integer literal rules are\nstricter, and the compiler may treat it as int, causing overflow and\ncompilation failure.\n\nFix by adding the \u0027u\u0027 suffix to make the literal explicitly unsigned\n(4294967295u), which:\n- Correctly represents the value as unsigned int\n- Matches the expected uint32_t key type in SpecIdToValueStrMap\n- Matches the uint32_t field type in DescriptorSetAndBinding"
    },
    {
      "commit": "d96e27bb8583639743240d9640d808e748e7de0c",
      "tree": "621108174cfb78cd39baa231a36e2175a082093c",
      "parents": [
        "17a2dcf8d4ae5f344019586949790ee12aa71ce4"
      ],
      "author": {
        "name": "Diego Novillo",
        "email": "dnovillo@nvidia.com",
        "time": "Thu Feb 26 17:17:24 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 26 17:17:24 2026 -0500"
      },
      "message": "spirv-val, spirv-opt: Support versioned NSDI imports (#6555)\n\nWith https://github.com/KhronosGroup/SPIRV-Registry/pull/384\nNonSemantic.Shader.DebugInfo started using a unified versioning\nscheme where later versions use a suffixed import name (e.g.\nNonSemantic.Shader.DebugInfo.101).\n\nThis updates the parser, optimizer, and validator to treat any\nNonSemantic.Shader.DebugInfo.\u003cversion\u003e import as the known instruction\nset rather than requiring the exact string \"...100\".\n\nFor known non-semantic extension instructions, push\nSPV_OPERAND_TYPE_VARIABLE_ID before the instruction-specific operands so\nthat extra trailing operands from future NSDI versions are silently absorbed\n\nMake operand checks strict for the current known version and lenient for unknown\nfuture versions.\n\nAdd tests for forward-compatibility cases."
    },
    {
      "commit": "17a2dcf8d4ae5f344019586949790ee12aa71ce4",
      "tree": "e4a588cd3cfd0e8e85f4b2ab7d257c8730f5a93c",
      "parents": [
        "e63ee307a0cbcd42fd8d80aa3c716e8159ac13aa"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Thu Feb 26 14:17:15 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 26 14:17:15 2026 -0500"
      },
      "message": "spirv-val: Set MeshShadingPass to match other passes (#6559)\n\nI have another PR coming for Mesh, but wanted to just make\n`MeshShadingPass` not be a monolithic function and branch it out like we\ndo for other passes\n\nthis is all just copy-and-pasting and hence why made a separate MR"
    },
    {
      "commit": "e63ee307a0cbcd42fd8d80aa3c716e8159ac13aa",
      "tree": "2775bd0d8df4e0b7767937587d8bf8e6fb86ab8c",
      "parents": [
        "b2033ea811c6c0150982b114c3cf4d3139c65fee"
      ],
      "author": {
        "name": "David Neto",
        "email": "dneto@google.com",
        "time": "Tue Feb 24 13:56:21 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 24 13:56:21 2026 -0500"
      },
      "message": "[bazel] Use \"moderate\" timeout for opt_fold_test (#6553)\n\nIt hovers around 60s on Intel-based Mac.\n\nFixed: #6552"
    },
    {
      "commit": "b2033ea811c6c0150982b114c3cf4d3139c65fee",
      "tree": "5263b0ae8aceb9c408583823650eaeeecbb6f221",
      "parents": [
        "54ad621f6e3fa758c1b80981489fcf0b62d2b752"
      ],
      "author": {
        "name": "dan sinclair",
        "email": "dsinclair@chromium.org",
        "time": "Mon Feb 23 14:38:59 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Feb 23 14:38:59 2026 -0500"
      },
      "message": "Remove SVA. (#6550)\n\nThe SVA tool has not been maintained in a long time. WebGPU does not\ningest SPIR-V so this is no longer useful in general."
    },
    {
      "commit": "54ad621f6e3fa758c1b80981489fcf0b62d2b752",
      "tree": "42eaf2d6dd80c3d5a535c853670b1af3eeb44556",
      "parents": [
        "e16e629d42af475f2d3853b6430b8207e258d8fd"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Mon Feb 23 11:31:59 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Feb 23 11:31:59 2026 -0500"
      },
      "message": "cmake: Fix redundant dependency for build-version.inc (#6549)\n\nThe custom command to generate build-version.inc was being depended on\nin two ways by the SPIRV-Tools-static target.\n\nThis caused issues with the Xcode \"new build system\" which does not\nallow\nthis.\n\nThis change removes the redundant dependency through the\nspirv-tools-build-version target. The dependency through the source file\nproperties on software_version.cpp is sufficient.\n\nThe spirv-tools-build-version target has also been removed since it is\nno longer used and was only a convenience target.\n\nFixes #6548"
    },
    {
      "commit": "e16e629d42af475f2d3853b6430b8207e258d8fd",
      "tree": "499ef732db0cbd61562ca99aa8d3cc621484b903",
      "parents": [
        "0436c4b0556fbfcff46610e888974965fd36be2a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Feb 23 10:14:13 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Feb 23 10:14:13 2026 -0500"
      },
      "message": "build(deps): bump github/codeql-action from 4.32.0 to 4.32.1 in the github-actions group (#6531)\n\nBumps the github-actions group with 1 update:\n[github/codeql-action](https://github.com/github/codeql-action).\n\nUpdates `github/codeql-action` from 4.32.0 to 4.32.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.32.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eA warning is now shown in Default Setup workflow logs if a \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registry is configured\u003c/a\u003e using a GitHub Personal Access Token\n(PAT), but no username is configured. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3422\"\u003e#3422\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug which caused the CodeQL Action to fail when repository\nproperties cannot successfully be retrieved. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3421\"\u003e#3421\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases\"\u003ereleases\npage\u003c/a\u003e for the relevant changes to the CodeQL CLI and language\npacks.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.32.1 - 02 Feb 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eA warning is now shown in Default Setup workflow logs if a \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate\npackage registry is configured\u003c/a\u003e using a GitHub Personal Access Token\n(PAT), but no username is configured. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3422\"\u003e#3422\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug which caused the CodeQL Action to fail when repository\nproperties cannot successfully be retrieved. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3421\"\u003e#3421\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.0 - 26 Jan 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca\nhref\u003d\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0\"\u003e2.24.0\u003c/a\u003e.\n\u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3425\"\u003e#3425\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.11 - 23 Jan 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eWhen running a Default Setup workflow with \u003ca\nhref\u003d\"https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging\"\u003eActions\ndebugging enabled\u003c/a\u003e, the CodeQL Action will now use more unique names\nwhen uploading logs from the Dependabot authentication proxy as workflow\nartifacts. This ensures that the artifact names do not clash between\nmultiple jobs in a build matrix. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3409\"\u003e#3409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved error handling throughout the CodeQL Action. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3415\"\u003e#3415\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded experimental support for automatically excluding \u003ca\nhref\u003d\"https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github\"\u003egenerated\nfiles\u003c/a\u003e from the analysis. This feature is not currently enabled for\nany analysis. In the future, it may be enabled by default for some\nGitHub-managed analyses. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3318\"\u003e#3318\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe changelog extracts that are included with releases of the CodeQL\nAction are now shorter to avoid duplicated information from appearing in\nDependabot PRs. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3403\"\u003e#3403\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.10 - 12 Jan 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.23.9. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3393\"\u003e#3393\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.9 - 16 Dec 2025\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.31.8 - 11 Dec 2025\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.23.8. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3354\"\u003e#3354\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.7 - 05 Dec 2025\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.23.7. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3343\"\u003e#3343\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.6 - 01 Dec 2025\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.31.5 - 24 Nov 2025\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to 2.23.6. \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/pull/3321\"\u003e#3321\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.31.4 - 18 Nov 2025\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/6bc82e05fd0ea64601dd4b465378bbcf57de0314\"\u003e\u003ccode\u003e6bc82e0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3447\"\u003e#3447\u003c/a\u003e\nfrom github/update-v4.32.1-f52cbc830\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/42f00f2d33668fbcf1dc3dd5c3bb29d28da0e60d\"\u003e\u003ccode\u003e42f00f2\u003c/code\u003e\u003c/a\u003e\nAdd a couple of change notes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/cedee6de9f72b4373125bf3febfbf6c602a0b2d1\"\u003e\u003ccode\u003ecedee6d\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v4.32.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f52cbc83091da34ce9a8ae0e3db2f977e8d4ecb2\"\u003e\u003ccode\u003ef52cbc8\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3445\"\u003e#3445\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/fast-xml-parser-...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/c5aaca4bb9117e5ece543792c718f055ed6ef031\"\u003e\u003ccode\u003ec5aaca4\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3446\"\u003e#3446\u003c/a\u003e\nfrom github/mbg/ci/pin-node-packages\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/3e58739c65d3c9ec50eda6506523bacfae244e1e\"\u003e\u003ccode\u003e3e58739\u003c/code\u003e\u003c/a\u003e\nPin \u003ccode\u003e@actions/tool-cache@3\u003c/code\u003e in workflows to avoid failures\nwith \u003ccode\u003egithub-script\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/a6ccefb47c262aa74c12cd875ddb489a95683052\"\u003e\u003ccode\u003ea6ccefb\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/0e64858573fbb4884fb38ad67277bd9d10949e52\"\u003e\u003ccode\u003e0e64858\u003c/code\u003e\u003c/a\u003e\nBump fast-xml-parser from 5.3.3 to 5.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/f985be5b50bd175586d44aac9ac52926adf12893\"\u003e\u003ccode\u003ef985be5\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/github/codeql-action/issues/3443\"\u003e#3443\u003c/a\u003e\nfrom github/dependabot/npm_and_yarn/tar-7.5.7\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/github/codeql-action/commit/0c8e06dfb239195730995b6e2e320fe7e8d423c0\"\u003e\u003ccode\u003e0c8e06d\u003c/code\u003e\u003c/a\u003e\nBump tar from 7.5.6 to 7.5.7\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/github/codeql-action/compare/b20883b0cd1f46c72ae0ba6d1090936928f9fa30...6bc82e05fd0ea64601dd4b465378bbcf57de0314\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dgithub/codeql-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.32.0\u0026new-version\u003d4.32.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after\nyour CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge\nand block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating\nit. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s major version (unless you unignore this specific\ndependency\u0027s major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this\ngroup update PR and stop Dependabot creating any more for the specific\ndependency\u0027s minor version (unless you unignore this specific\ndependency\u0027s minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR\nand stop Dependabot creating any more for the specific dependency\n(unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore\nconditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will\nremove the ignore condition of the specified dependency and ignore\nconditions\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0436c4b0556fbfcff46610e888974965fd36be2a",
      "tree": "962e6f8c3c0e5a979889378850e58c824b289f83",
      "parents": [
        "0c49637e746147bb42b1c3437e3f78e4067859fe"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Sat Feb 21 13:39:19 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Feb 21 13:39:19 2026 -0500"
      },
      "message": "Roll external/abseil_cpp/ 0e5031d3c..49cd3c7a2 (1 commit) (#6530)\n\nhttps://github.com/abseil/abseil-cpp/compare/0e5031d3c00d...49cd3c7a20fb\n\nCreated with:\n  roll-dep external/abseil_cpp\n\n---------\n\nCo-authored-by: GitHub Actions[bot] \u003c\u003e"
    },
    {
      "commit": "0c49637e746147bb42b1c3437e3f78e4067859fe",
      "tree": "3f9f6710945930af4a478e7b7c8b55c97ba3c97c",
      "parents": [
        "3173273e78edeeacaae9d752afa2151e44af5f65"
      ],
      "author": {
        "name": "Piers Daniell",
        "email": "pdaniell@nvidia.com",
        "time": "Fri Feb 20 11:19:51 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 20 14:19:51 2026 -0500"
      },
      "message": "Allow SPV_NV_push_constant_bank to be optimized (#6547)\n\nThis is needed to continue to allow certain optimizations on shaders\nthat use SPV_NV_push_constant_bank."
    },
    {
      "commit": "3173273e78edeeacaae9d752afa2151e44af5f65",
      "tree": "94c9ee97024ff385ec5d38b32d57620847277fe8",
      "parents": [
        "9ade896574632f65cec0d6c8a7c9df9a5356a839"
      ],
      "author": {
        "name": "changhwipark-arm",
        "email": "chang-hwi.park@arm.com",
        "time": "Fri Feb 20 16:54:18 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 20 16:54:18 2026 +0000"
      },
      "message": "spirv-val: Add OpColorAttachmentReadEXT, OpDepthAttachmentReadEXT, OpStencilAttachmentReadEXT (#6543)\n\nIssue: https://github.com/KhronosGroup/SPIRV-Tools/issues/6528\n\nThe following validations are already handled by the existing capability\nchecks, so I did not add additional logics:\n- `TileImageColorReadAccessEXT` must be declared to use\n`OpColorAttachmentReadEXT`\n- `TileImageDepthReadAccessEXT` must be declared to use\n`OpDepthAttachmentReadEXT`\n- `TileImageStencilReadAccessEXT` must be declared to use\n`OpStencilAttachmentReadEXT`\n\nThe following validations and their corresponding unit tests were added\nin `validate_image.cpp`:\n- `OpColorAttachmentReadEXT` - Result Type must be a scalar or vector of\nfloating-point type or integer type.\n- `OpColorAttachmentReadEXT` - Result Type, if a vector, must be the\ncomponent type the same as Sampled Type of the OpTypeImage\n- `OpColorAttachmentReadEXT` - Attachment must be an object whose type\nis OpTypeImage with a Dim of TileImageDataEXT\n- `OpColorAttachmentReadEXT` - Sample must be an integer type scalar.\n- `OpColorAttachmentReadEXT` - only valid in the Fragment Execution\nModel.\n- `OpDepthAttachmentReadEXT` - Result Type must be a 32-bit\nfloating-point type scalar.\n- `OpDepthAttachmentReadEXT` - Sample must be an integer type scalar.\n- `OpDepthAttachmentReadEXT` - only valid in the Fragment Execution\nModel.\n- `OpStencilAttachmentReadEXT` - Result Type must be a 32-bit\nfloating-point type scalar.\n- `OpStencilAttachmentReadEXT` - Sample must be an integer type scalar.\n- `OpStencilAttachmentReadEXT` - only valid in the Fragment Execution\nModel."
    },
    {
      "commit": "9ade896574632f65cec0d6c8a7c9df9a5356a839",
      "tree": "67f1b7633940182d738b606a60e4e5a887e267e3",
      "parents": [
        "64f5770f59db933d46b9cad6edc42b4186409ef4"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Feb 20 10:56:56 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 20 10:56:56 2026 -0500"
      },
      "message": "spirv-val: Add SPV_VALVE_mixed_float_dot_product (#6546)\n\nfor `SPV_VALVE_mixed_float_dot_product` added in\nhttps://github.com/KhronosGroup/SPIRV-Registry/pull/387"
    },
    {
      "commit": "64f5770f59db933d46b9cad6edc42b4186409ef4",
      "tree": "55d61562c6a5ec130f23d89c297dc3d2cd183f53",
      "parents": [
        "a8fa7f5032a528c06339a58d0bd23541085fcfb2"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Feb 18 10:43:43 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 18 10:43:43 2026 -0500"
      },
      "message": "spirv-opt: Reorder access chain and multi-dim array passes (#6545)\n\nThe combine-access-chain pass leaves dead code that breaks the\nlegalization pass. Additionally, the legalize-multi-dim-arrays pass\ncreates arithmetic expressions that could be folded.\n\nThis commit moves these passes earlier in the pipeline to ensure the\ncode they create can be cleaned up. It is safe to move them earlier\nbecause they are flexible and do not depend on the later passes."
    },
    {
      "commit": "a8fa7f5032a528c06339a58d0bd23541085fcfb2",
      "tree": "74e54421d649d9a3e7ad3a7828a662dbfb5629f0",
      "parents": [
        "cb38b2342beedde25bcff582dc3528a135cf6e67"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Mon Feb 16 23:38:37 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Feb 16 23:38:37 2026 -0500"
      },
      "message": "spirv-val: Add Pipe validation (#6540)\n\nAdds all the various `Pipe` instruction validation"
    },
    {
      "commit": "cb38b2342beedde25bcff582dc3528a135cf6e67",
      "tree": "18ddce756bcdddbfbc1c5065831abc9efa7bcb25",
      "parents": [
        "f139c64525c7c449c83d299a9fda4e1657bf37ab"
      ],
      "author": {
        "name": "Steven Perron",
        "email": "stevenperron@google.com",
        "time": "Wed Feb 11 09:44:41 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 11 09:44:41 2026 -0500"
      },
      "message": "spirv-opt: Add LegalizeMultidimArrayPass (#6535)\n\nThis pass transforms multidimensional arrays of resources (e.g.,\nTexture2D g_Textures[2][3]) into single-dimensional arrays (e.g.,\nTexture2D g_Textures[6]) and updates all access chains that reference\nthem.\n\nThis transformation is required for Vulkan compatibility, as\nmultidimensional\nresource arrays are not allowed in some storage classes.\n\nSpecifically, it helps avoid:\n- VUID-StandaloneSpirv-Uniform-06807\n- VUID-StandaloneSpirv-UniformConstant-04655\n\nFixes https://github.com/microsoft/DirectXShaderCompiler/issues/7922"
    },
    {
      "commit": "f139c64525c7c449c83d299a9fda4e1657bf37ab",
      "tree": "4a9ec23b974582a4100292bac9720d63c8c962de",
      "parents": [
        "04d0b166dcd62e29509bf2aac3ca0c5ccdcb6929"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sun Feb 08 17:34:14 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Feb 08 17:34:14 2026 -0500"
      },
      "message": "spirv-val: Add SPV_KHR_ray_tracing_position_fetch (#6539)\n\ncloses https://github.com/KhronosGroup/SPIRV-Tools/issues/5884"
    },
    {
      "commit": "04d0b166dcd62e29509bf2aac3ca0c5ccdcb6929",
      "tree": "c52329d6f44a42defde4b226571d0d77d937a385",
      "parents": [
        "f700a727ea5dfacb2ba41854f8a5c2894d322298"
      ],
      "author": {
        "name": "Ben Ashbaugh",
        "email": "ben.ashbaugh@intel.com",
        "time": "Sat Feb 07 14:26:47 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Feb 07 17:26:47 2026 -0500"
      },
      "message": "add FPRoundingMode decoration checks for Kernel SPIR-V (#6537)\n\nAdds FPRoundingMode decoration checks for Kernel SPIR-V.  See:\n\n\nhttps://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_Env.html#_rounding_modes_for_conversions\n\n---------\n\nSigned-off-by: Ben Ashbaugh \u003cben.ashbaugh@intel.com\u003e"
    },
    {
      "commit": "f700a727ea5dfacb2ba41854f8a5c2894d322298",
      "tree": "2e899711c543be519e6e6dce36e00737ff7171b2",
      "parents": [
        "a8afb0250b8498f4ccdd3851a77f6a33e43a5684"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Sat Feb 07 14:09:28 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Feb 07 14:09:28 2026 -0500"
      },
      "message": "spirv-val: Small cleanup in EvalInt32IfConst (#6538)\n\n"
    },
    {
      "commit": "a8afb0250b8498f4ccdd3851a77f6a33e43a5684",
      "tree": "1b3ee1847135ca015fcac5b78c3b435a706d65e4",
      "parents": [
        "447aeb0029d46de6a1d1ad6889280073d3aa6e72"
      ],
      "author": {
        "name": "Spencer",
        "email": "94135891+spencer005@users.noreply.github.com",
        "time": "Fri Feb 06 18:20:17 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 06 13:20:17 2026 -0500"
      },
      "message": "spirv-opt: handle mixed-width shifts in RedundantAndShift (#6504)\n\nI encountered a crash with instruction folding enabled while using\nshaderc (reproduced in test case 15) where shaderc generated code with a\n32 shift on a 64bit int, this commit adds support for instruction\nfolding for all different cases I interpreted as valid from reading the\nspirv spec.\n\nhttps://registry.khronos.org/SPIR-V/specs/unified1/SPIRV.html 3.3.14.\nBit Instructions\n\nTo the best of my knowledge this is correct and I added tests\n\nonly supports 8/16/32/64 width since that\u0027s what I saw defined in the\nspec but should handle things like\nhttps://github.khronos.org/SPIRV-Registry/extensions/ALTERA/SPV_ALTERA_arbitrary_precision_integers.html\nfine by not folding as it did before while fixing the mixed-width shift\ncase and supporting 8/16"
    },
    {
      "commit": "447aeb0029d46de6a1d1ad6889280073d3aa6e72",
      "tree": "cc03579c0803b0e444ccf77d3fe963681fcb51b0",
      "parents": [
        "d9d2ec123c1b92de48c12fd084fc278cd99c6fce"
      ],
      "author": {
        "name": "Spencer Fricke",
        "email": "115671160+spencer-lunarg@users.noreply.github.com",
        "time": "Fri Feb 06 11:24:28 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 06 11:24:28 2026 -0500"
      },
      "message": "spirv-val: Add ArrayStrideIdEXT zero check (#6536)\n\nHit a bug where VVL wasn\u0027t detecting `ArrayStrideIdEXT` stride was zero\nbecause the spec constant was forgotten the default was taking, crashing\nin the driver\n\nThis matches the `ArrayStride 0` check we have and confirmed VVL with\nthis will now detect it"
    },
    {
      "commit": "d9d2ec123c1b92de48c12fd084fc278cd99c6fce",
      "tree": "45e77815dbc844e1c120f1a64c8d403f278d95a7",
      "parents": [
        "97e05b836c6a79ff75dd761f93c88f6dbdb81c48"
      ],
      "author": {
        "name": "alister-chowdhury",
        "email": "30833607+alister-chowdhury@users.noreply.github.com",
        "time": "Wed Feb 04 17:20:57 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 04 12:20:57 2026 -0500"
      },
      "message": "spirv-opt: Adding rule for redundant OpLogicalEqual/OpLogicalNotEqual (#6454)\n\n*RedundantLogicalEqual*\n```\n(a \u003d\u003d true)  \u003d  a\n(a \u003d\u003d false) \u003d !a\n(a !\u003d true)  \u003d !a\n(a !\u003d false) \u003d  a\n```"
    },
    {
      "commit": "97e05b836c6a79ff75dd761f93c88f6dbdb81c48",
      "tree": "4569e02a55b4531f94d5b0a3182464c35dfc0f29",
      "parents": [
        "cb0ba4dd475eeccb2df2e9a04eab22697c94f74e"
      ],
      "author": {
        "name": "alister-chowdhury",
        "email": "30833607+alister-chowdhury@users.noreply.github.com",
        "time": "Wed Feb 04 16:58:01 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 04 11:58:01 2026 -0500"
      },
      "message": "spriv-opt: Adding a rule to merge select-binaryop (#6456)\n\nIt seems that things like `(a ? 1u : 0u) \u003d\u003d 1u` are surprisingly\nprevalent.\nWhen the select results are constants and a binary op is constant, we\ncan merge the result directly into the select.\nThe following cases have been added:\n```\n  ((a ? C0 : C1) \u003d\u003d C2)  \u003d  ((a ? (C0 \u003d\u003d C2) : (C1 \u003d\u003d C2))\n  ((a ? C0 : C1) !\u003d C2)  \u003d  ((a ? (C0 !\u003d C2) : (C1 !\u003d C2))\n  ((a ? C0 : C1) \u003c  C2)  \u003d  ((a ? (C0 \u003c  C2) : (C1 \u003c  C2))\n  ((a ? C0 : C1) \u003c\u003d C2)  \u003d  ((a ? (C0 \u003c\u003d C2) : (C1 \u003c\u003d C2))\n  ((a ? C0 : C1) \u003e  C2)  \u003d  ((a ? (C0 \u003e  C2) : (C1 \u003e  C2))\n  ((a ? C0 : C1) \u003e\u003d C2)  \u003d  ((a ? (C0 \u003e\u003d C2) : (C1 \u003e\u003d C2))\n  ((a ? C0 : C1) || C2)  \u003d  ((a ? (C0 || C2) : (C1 || C2))\n  ((a ? C0 : C1) \u0026\u0026 C2)  \u003d  ((a ? (C0 \u0026\u0026 C2) : (C1 \u0026\u0026 C2))\n  ((a ? C0 : C1) +  C2)  \u003d  ((a ? (C0 +  C2) : (C1 +  C2))\n  ((a ? C0 : C1) -  C2)  \u003d  ((a ? (C0 -  C2) : (C1 -  C2))\n  ((a ? C0 : C1) *  C2)  \u003d  ((a ? (C0 *  C2) : (C1 *  C2))\n  ((a ? C0 : C1) /  C2)  \u003d  ((a ? (C0 /  C2) : (C1 /  C2))\n  ((a ? C0 : C1) \u003e\u003e C2)  \u003d  ((a ? (C0 \u003e\u003e C2) : (C1 \u003e\u003e C2))\n  ((a ? C0 : C1) \u003c\u003c C2)  \u003d  ((a ? (C0 \u003c\u003c C2) : (C1 \u003c\u003c C2))\n  ((a ? C0 : C1) ^  C2)  \u003d  ((a ? (C0 ^  C2) : (C1 ^  C2))\n  ((a ? C0 : C1) |  C2)  \u003d  ((a ? (C0 |  C2) : (C1 |  C2))\n  ((a ? C0 : C1) \u0026  C2)  \u003d  ((a ? (C0 \u0026  C2) : (C1 \u0026  C2))\n```\n\nThis further opens the door to further collapses like: `(a ? true :\nfalse) \u003d a`"
    },
    {
      "commit": "cb0ba4dd475eeccb2df2e9a04eab22697c94f74e",
      "tree": "e6608ac846fb11f9c3d36c30469600c111498b51",
      "parents": [
        "a66a95eecf5102f2b19d6208385538c7c29aa7a1"
      ],
      "author": {
        "name": "Steve Urquhart",
        "email": "53908460+SteveUrquhart@users.noreply.github.com",
        "time": "Wed Feb 04 11:48:37 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 04 11:48:37 2026 -0500"
      },
      "message": "spirv-opt: Allow exe preserve_interface to be false (#6521)\n\nThe spirv-opt.exe front-end initializes preserve_interface to true, and\nallows the user to reinitialize it to true by passing\n--preserve-interface. It should be initialized to false, so the user has\nboth options available from the command line.\n\nThe PR includes a test, but the test framework doesn\u0027t seem to exercise\nthe exe front-ends, so it passes without this commit. We can either omit\nthe test or extend the testing to allow exercising the exe\u0027s."
    }
  ],
  "next": "a66a95eecf5102f2b19d6208385538c7c29aa7a1"
}
