Skip to content

Create ghas-bootcamp-codeql-cli-example-00.yml #24

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 151 commits into
base: main
Choose a base branch
from

Conversation

nicolaswill
Copy link

This workflow is a rough work-in-progress demonstration of using the CodeQL CLI directly within GitHub Actions rather than using the provided codeql-action init and analyze actions. I wrote this workflow for analyzing the ghas-bootcamp repo, with the goal of demonstrating to customers how to integrate the CodeQL CLI into third-party CI/CD tools without using a wrapper. GitHub Actions, in my opinion, is the logical platform for hosting and running an interactive demo of this sort.

This specific workflow does not create a database cluster but uses categories for each language analyzed.

I raised this PR to start some discussion around where we can potentially build out a more hands-on ghas-bootcamp style approach to demonstrating various approaches to using the CodeQL CLI in build pipelines.

Relevant resources / other work to reference or consolidate:
https://github.com/advanced-security/gh-codeql-scan
https://github.com/david-wiggs/codeql-anywhere
https://github.com/advanced-security/monorepo-filtering-workaround

Chelsea Boling and others added 30 commits October 15, 2021 12:17
Update advanced-security-reporting.md
A reusable workflow for Code Scanning dispatching to the right tool, based on the programming languages present in the repo.
…g/update-links

Update advanced-security-material.md
leftrightleft and others added 29 commits June 15, 2023 17:01
…-dep-quickstart

add link to new Dependabot quickstart guide
…-troubleshooting-golang

GO Compiled lang troubleshooting
…-ghes-links

update all links to GHES instead of GHEC@latest
…atrix-39-to-latest

update links from 3.9 to (latest)
…eatures-codeql-versions

GHES + Codeql Versions
…webgoat

Create owasp-webgoat CodeQL Workflow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.