Enable CodeQL Advanced Security Scanning#162
Open
ghas-management[bot] wants to merge 2 commits intomainfrom
Open
Enable CodeQL Advanced Security Scanning#162ghas-management[bot] wants to merge 2 commits intomainfrom
ghas-management[bot] wants to merge 2 commits intomainfrom
Conversation
Adds CodeQL workflow for security scanning
Automated workflow update
|
Template update squashed initial comment unintentionally, please check edit versions for comment history |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CodeQL Workflow Update
This PR replaces your CodeQL workflow with a freshly generated version from the latest managed template (v1.1).
What triggered this update
How to review
The Files Changed tab shows the full diff between your current workflow and the new template-generated one.
Any customisations you had (custom steps, container image, build command, cron schedule, extra env vars, etc.) will appear as removed lines in the diff. Re-apply the ones you want to keep directly in this PR or after merging, the same way you would resolve a merge conflict.
Why a full replacement?
Workflow updates are intentionally delivered as a fresh workflow rather than a surgical patch. This gives you full visibility into what changed and avoids hidden conflicts between your customisations and the new template.
Next Steps
This PR was automatically created by the GHAS management tool.
More details about EE AppSec can be found here. If you have any questions, please reach out to us via EE Teams/Slack channels or tag us with @ee-security in this PR.
If you believe your repository does not require automated security scanning, see our FAQ for guidance on how to proceed.