Pull requests from dependabot that bump this codeql-action fail to pull in release notes because this repo isn't properly reporting its release notes on GitHub Releases.
It is exceedingly frustrating when github's own products don't properly follow github's own tooling processes.
This is a github first-party action.
That isn't using github's releases feature properly.
Which then breaks github's dependabot feature.
"see release notes"
"see changelog"
"see ..."
Please update your release process to properly use github's infra.