Revert usage of `--codescanning-config` flag by edoardopirovano · Pull Request #1018 · github/codeql-action

Backs out the change from #957 and most of the subsequent fix to it in #999 (although I've left some code in place to make it easier to do this again in future).

A customer has run into another issue with this change: the Action allows specifying additional queries directly in the workflow file rather than in the config file, but the new code path does not respect these additional queries. The proper fix here, I think, is that we should have the Action inject these additional queries into the config file we pass to the CLI, like we are already doing for the ATM queries. In the interest of caution, however, I think we should revert this change temporarily while we get a stable version into GHES 3.5, then add it in with the aforementioned fix and a new test to cover this case once code freeze has passed.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Confirm the readme has been updated if necessary.
  • Confirm the changelog has been updated if necessary.