github / github/codeql

Clarification on CodeQL CLI Licensing for On-Premise Azure DevOps Usage

未关闭
#21,487 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Hello,

I've reviewed the CodeQL CLI LICENSE.md (https://github.com/github/codeql-cli-binaries/blob/main/LICENSE.md), which states that local analysis of non-open-source codebases requires a paid GitHub Advanced Security (GHAS) license.

My questions:

1. Can the CodeQL CLI be used legally for local analysis (database creation/analysis) on private enterprise code hosted in on-premise Azure DevOps Server (not Azure DevOps Services/GitHub)? Or I must host my code in the cloud?

2. Does a standard GHAS license (via GitHub Enterprise Cloud/Server) cover this scenario, or is additional licensing required for Azure DevOps on-prem integration?

贡献指南

打开贡献指南

调研方向

Start with LICENSE.md and the CodeQL CLI licensing terms referenced in the issue. Verify whether local analysis of private code on on-premise Azure DevOps Server is covered and whether GHAS licensing addresses it. Done means providing an authoritative clarification or updating the relevant licensing documentation.

由索引模型根据 Issue 内容生成。

评估

领域
documentation, security
Issue 类型
文档
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。