Skip to main content
GitHub Docs
All products
Code security
Getting started
GitHub security features
Secure your repository
Secure your organization
Add a security policy
Adopting GHAS at scale
Introduction
1. Align on strategy
2. Preparation
3. Pilot programs
4. Create internal documentation
5. Rollout code scanning
6. Rollout secret scanning
Secret scanning
About secret scanning
Configure secret scans
Define custom patterns
Manage secret alerts
Secret scanning patterns
Code scanning
Scan code automatically
About code scanning
About code scanning alerts
Triage alerts in pull requests
Configure code scanning
Manage alerts
Customize code scanning
Code scanning with CodeQL
Hardware resources for CodeQL
Configure compiled languages
Troubleshoot CodeQL workflow
Code scanning in a container
View code scanning logs
Integrate with code scanning
About integration
Upload a SARIF file
SARIF support
Using the CodeQL CLI
About the CodeQL CLI
Getting started
Creating CodeQL databases
Extractor options
Analyzing databases
Using custom queries with the CodeQL CLI
Creating CodeQL query suites
Testing query help files
Specifying command options in a CodeQL configuration file
CodeQL CLI reference
Query reference files
CodeQL CLI SARIF output
Exit codes
Use CodeQL in CI system
Code scanning in your CI