Skip to content

Enable CodeQL Advanced Security Scanning - #2

Open
ghas-management[bot] wants to merge 1 commit into
masterfrom
ghas-codeql-advanced-setup-20260502-030530
Open

Enable CodeQL Advanced Security Scanning#2
ghas-management[bot] wants to merge 1 commit into
masterfrom
ghas-codeql-advanced-setup-20260502-030530

Conversation

@ghas-management

Copy link
Copy Markdown

CodeQL Advanced Security Scanning

Hi, this is a PR from EE AppSec @ Springer Nature
This PR adds CodeQL security scanning to your repository.

What's Included

  • Automated scanning on daily schedule (can be changed to scan on push and pull requests by uncommenting the relevant lines in the workflow)
  • Security alerts will appear in the Security tab

Language Coverage

Covered by this workflow: Actions

Not supported by CodeQL: Dockerfile, Io, Shell

Already Have a Working Workflow?

If you already have a working CodeQL workflow in place, you can continue using it. See our FAQ for more details.

Next Steps

  1. Review the workflow configuration
  2. Merge this PR to enable CodeQL scanning
  3. If you keep the workflow scheduled for daily runs, you can use workflow dispatch to trigger the first scan
  4. Check security findings in the Security tab

This PR was automatically created by EE AppSec @ Springer Nature.

More details about EE AppSec can be found here. If you have any questions, please reach out to us via EE Teams/Slack channels or tag us with @ee-security in this PR.

If you believe your repository does not require automated security scanning, see our FAQ for guidance on how to proceed.

Adds CodeQL workflow for security scanning
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant