Fallout-build / Fallout-build/Fallout

Add CodeQL workflow for security scanning

Open
#7 0 comments 0 reactions 0 assignees View on GitHub
good first issue target/vCurrent
Dominant language
C#
Stars
154
Forks
19
Avg merge
1d 22h
Merged PRs (30d)
15

Description

## Why
The only static analysis today is Qodana (code quality, not security). For enterprise positioning we need a SAST scanner that lands findings in the GitHub Security tab. CodeQL is the GitHub-native option, free for public repos, and supports C# (the bulk of this codebase).

## Scope
- Add `.github/workflows/codeql.yml` — checkout, init CodeQL, build, analyze.
- Languages: `csharp` (primary). Maybe add `javascript` later if the docs site moves into this repo.
- Schedule: on push to main + PRs targeting main, plus a weekly cron for advisory-database refresh.
- Ignore generated files: `source/Nuke.Common/Tools/**/*.Generated.cs`, `build/_build/**/obj/**`, `build/Build.CI.*.cs` (auto-generated).

## Done when
- [ ] CodeQL workflow committed
- [ ] First scan completes green (or findings triaged)
- [ ] GitHub Security tab populated

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.