Skip to content

Add CodeQL Analysis workflow#222

Merged
SomkaPe merged 1 commit intoAzureAD:devfrom
jhutchings1:codeql
May 5, 2020
Merged

Add CodeQL Analysis workflow#222
SomkaPe merged 1 commit intoAzureAD:devfrom
jhutchings1:codeql

Conversation

@jhutchings1
Copy link
Copy Markdown
Contributor

Adds a GitHub Actions workflow that runs CodeQL on every push, and on a daily schedule.

Code scanning looks for vulnerabilities, such as XSS, SQL injection, etc., in your code. If it finds any new vulnerabilities it surfaces them in the PR as check annotations, and blocks the build until they’re fixed or marked as false positives. If it finds any on the repo’s default branch it displays them in the security tab.

For now you also need to be feature flagged individually to see results in the security tab (as well as having write permission on this repo) - if you drop an email to [email protected] I can get anyone you need added.

Finally, this is an early access program that has not been released yet, so please don't share before May 6th when we’re unveiling it at GitHub Satellite.

Cc: @greysteil

@sangonzal sangonzal requested review from Avery-Dunn and SomkaPe April 29, 2020 20:27
@SomkaPe SomkaPe merged commit 9479deb into AzureAD:dev May 5, 2020
SomkaPe pushed a commit that referenced this pull request May 5, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants