Skip to content

DIGITAL-392: Add codeql.yml for code security - #197

Closed
nick-mon1 wants to merge 3 commits into
developfrom
feature/DIGITAL-392-enable-codeql
Closed

nick-mon1 wants to merge 3 commits into
developfrom
feature/DIGITAL-392-enable-codeql

Conversation

@nick-mon1

@nick-mon1 nick-mon1 commented Feb 20, 2025 •

Copy link
Copy Markdown
Contributor

Jira ticket

DIGITAL-392

Purpose

Turns on code scanning for javascript. PHP is not yet a supported language for codeQL.

Includes the following PRs that must be merged first

Deployment and testing

Local Setup

QA/Testing instructions

Checklist for the Developer

  • A link to the JIRA ticket has been included above.
  • No merge conflicts exist with the target branch.
  • Automated tests have passed on this PR.
  • A reviewer has been designated.
  • Deployment and testing steps have been documented above, if applicable.

Checklist for the Peer Reviewers

  • The file changes are relevant to the task objective.
  • Code is readable and includes appropriate commenting.
  • Code standards and best practices are followed.
  • QA/Test steps were successfully completed, if applicable.
  • Applicable logs are free of errors.

@nick-mon1 nick-mon1 self-assigned this Feb 20, 2025
@github-advanced-security

Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@nick-mon1
nick-mon1 requested a review from mattsqd February 20, 2025 18:44
@akf

akf commented Jan 13, 2026

Copy link
Copy Markdown
Contributor

I'm going to close this one. CodeQL is producing this message:

Error: Code Scanning could not process the submitted SARIF file:
CodeQL analyses from advanced configurations cannot be processed when the default setup is enabled

Looking at the history on this, this PR was created before CodeQL was turned on globally for the GSA github org. The CodeQL tests this change would have enabled (Javascript/Typescript) are already running as part of the default setup.

@akf akf closed this Jan 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants