CodeQL in Github not showing found issues for custom queries
Jan 14, 2025 · I am running CodeQL inside a private organization with advanced security enabled. It is working good for default queries. The queries security-extended and security-and-quality …
codeql - How does the autobuild step work in Github Advanced …
Jan 17, 2024 · Correct. CodeQL Autobuild is documented for each language on the GitHub docs "About autobuild for CodeQL". You need to specify.net build steps manually as you would in …
How can I run multiple CodeQL query suites in a single GitHub …
Nov 4, 2025 · My goal is to run multiple CodeQL query packs and suites (like security-extended and audit) in one GitHub Action workflow, and ideally merge the results into one SARIF file for …
Is there a way to exclude files from CodeQL scanning on GitHub
Oct 11, 2022 · Is there a way to exclude files from CodeQL scanning on GitHub Asked 3 years, 2 months ago Modified 10 months ago Viewed 8k times
Newest 'codeql' Questions - Stack Overflow
Nov 4, 2025 · I have a CodeQL CLI bundle (v2.13.5) stored on an on-prem Artifactory repository. I want to fetch this, store it using the tool-cache action and then run the CodeQL action on …
Errors with Setting Up custom CodeQL queries - Stack Overflow
Apr 27, 2025 · I have tried setting my custom queries in /opt/CodeQL/queries My packages of cpp were installed in /home/kali/.codeql/packages I have tried bringing the ql file within the …
CodeQL: Setting paths in Github Advanced Security for Devops
Dec 17, 2024 · By default the codeql task will scan the ENTIRE code base. Which is not what I want. How can I configure Github advanced security to only scan one project?For example the …
Why does codeql create database run into issue?
Apr 5, 2023 · It's my first time using codeql,the dir demo contains a simple cpp file,i tried to run a demo like this codeql database create ./demo-db -s . --language=cpp . However,it ran into …
Validating file paths to satisfy GitHub CodeQL's "Uncontrolled data ...
Aug 16, 2024 · I'm writing functions for a Python package to register files from a file system to an SQL database, and GitHub's CodeQL has flagged that the file paths are a potential security risk. …
CodeQL analyzer not working - Stack Overflow
Oct 2, 2023 · Find an example repo here: ghas-demo designed for GitHub workflows. However, it also applies to Azure DevOps. Just import the repo to DevOps, then create a Yaml pipeline by …