github / github/codeql-cli-binaries

codeql cli to get the list of issues based on severity after analyze

オープン
#88 コメント 5 件 リアクション 0 件 担当者 0 名 GitHub で見る
CLI
主要言語
言語のデータがありません
スター
1k
フォーク
184
PR マージ指標
30日以内にマージされた PR はありません

説明

Hi, We just started using codeql cli for our code scanning.

I am looking for a codeql cli to give the list of issues based on severity once we run codeql analyze. I have checked the codeql cli manual and am unable to find anything. I understand codeql cli will produce SARIF output file when we run analyze but it is too big with lot of details which I don't want. I am just looking for a simplified result to get the list of issues based on severity. I can write a parser to parse the SARIF file, but before that just want to know if any cli is already available to do give me the result what I am looking for.

Thanks in advance.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

CodeQL CLI analyze コマンドとその SARIF 出力から始め、次に CLI マニュアルを確認して、severity によるフィルタリングまたはレポート作成のための簡略化されたエントリーポイントがあるか調べます。既存のコマンドを文書化したもの、または要求された severity ベースの issue リストを生成するための、範囲が明確な提案があれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github
領域
cli, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
20/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。