github / github/codeql

Questions to workflow integration

未關閉
#4,426 4 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Hi CodeQL people!

Regarding CodeQL@GitHUB via Workflows/Actions, I have four questions that I hope you can help answer, or direct me to the right place to ask these questions.

1) Is it possible to exclude a rule?

The use-case is that a project might disagree with some style-recommendations, e.g. "cpp/trivial-switch".
Would it be possible to have a config along the lines of:

```
name: "CodeQL config"

disable-default-queries: false

queries:
- uses: security-and-quality
exclude: cpp/trivial-switch
```

Is something like that possible?

One can go and filter out "post-scan" by setting to "won't fix", however, that can be very cumbersome when a project generally disagree on certain code-styles and dogmas.

2) Adding the above question, is there an extensive documentation on all options of the CodeQL config-file somewhere?

3) Is it possible to ignore parts of a statically compiled codebase?

When adding "paths" and "paths-ignore", the scanner informs that those options are only for interpreted languages.
Is there any way to have the same functionality for static compiled languages?

The use-case is that a project might have third-party code, possibly via submodules, or code for which scanning is not wanted.
One can go and filter out "post-scan" by setting to "won't fix", however, that can be very cumbersome especially when contributions arrive via PR which the scanner rejects due to some completely unrelated third-party code already known to the project maintainer.

4) When using CodeQL via lgtm.com one could get a neat "code-quality" badge to put on the project README.
Is a similar thing available with the security scans?

Thanks!
Simon

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。