Skip to content

Commit 39038de

Browse files
committed
Changelog for 2.20.3
1 parent 1fa8741 commit 39038de

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

CHANGELOG.md

+13
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,19 @@
1616
checklist for a CLI release, you can edit here. But then
1717
you know what to do).
1818
-->
19+
20+
## Release 2.20.3 (2025-01-24)
21+
22+
### Security Updates
23+
24+
- Resolves a security vulnerability where CodeQL databases or logs produced by the CodeQL CLI may contain the environment variables from the time of
25+
database creation. This includes any secrets stored in an environment variables. For more information, see the
26+
[CodeQL CLI security advisory](https://github.com/github/codeql-cli-binaries/security/advisories/GHSA-gqh3-9prg-j95m).
27+
28+
All users of CodeQL should follow the advice in the CodeQL advisory mentioned above or upgrade to this version or a later version of CodeQL.
29+
30+
If you are using the CodeQL Action, also see the related [CodeQL Action security advisory](https://github.com/github/codeql-action/security/advisories/GHSA-vqf5-2xx6-9wfm).
31+
1932
## Release 2.20.2 (2025-01-22)
2033

2134
### Improvements

0 commit comments

Comments
 (0)