codethesaurus/codethesaur.us

Add CodeQL scan to CI/CD

Closed this issue · 1 comments

Description

CodeQL can help scan for code vulnerabilities. This should add that in.

See: https://docs.github.com/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning-at-scale#eligible-repositories-for-codeql-default-setup

Where: https://github.com/codethesaurus/codethesaur.us/settings/security_analysis#code_scanning_settings

Requirements

A CodeQL scan can run upon pull requests or pushes to main

Additional Notes

This might be a thing @geekygirlsarah will have to set up.