Skip to content

Conversation

nicolaswill
Copy link

This workflow is a rough work-in-progress demonstration of using the CodeQL CLI directly within GitHub Actions rather than using the provided codeql-action init and analyze actions. I wrote this workflow for analyzing the ghas-bootcamp repo, with the goal of demonstrating to customers how to integrate the CodeQL CLI into third-party CI/CD tools without using a wrapper. GitHub Actions, in my opinion, is the logical platform for hosting and running an interactive demo of this sort.

This specific workflow does not create a database cluster but uses categories for each language analyzed.

I raised this PR to start some discussion around where we can potentially build out a more hands-on ghas-bootcamp style approach to demonstrating various approaches to using the CodeQL CLI in build pipelines.

Relevant resources / other work to reference or consolidate:
https://github.com/advanced-security/gh-codeql-scan
https://github.com/david-wiggs/codeql-anywhere
https://github.com/advanced-security/monorepo-filtering-workaround

Chelsea Boling and others added 30 commits October 15, 2021 12:17
Update advanced-security-reporting.md
A reusable workflow for Code Scanning dispatching to the right tool, based on the programming languages present in the repo.
…g/update-links

Update advanced-security-material.md
leftrightleft and others added 29 commits June 15, 2023 17:01
…-dep-quickstart

add link to new Dependabot quickstart guide
…-troubleshooting-golang

GO Compiled lang troubleshooting
…-ghes-links

update all links to GHES instead of GHEC@latest
…atrix-39-to-latest

update links from 3.9 to (latest)
…eatures-codeql-versions

GHES + Codeql Versions
…webgoat

Create owasp-webgoat CodeQL Workflow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.