Skip to main content
GitHub Docs
Version:
Enterprise Server 3.8
Search GitHub Docs
Code security
/
Security advisories
Home
Code security
Getting started
GitHub security features
Dependabot quickstart
Secure your repository
Secure your organization
Add a security policy
Audit security alerts
Prevent data leaks
Adopting GHAS at scale
Introduction
1. Align on strategy
2. Preparation
3. Pilot programs
4. Create internal documentation
5. Rollout code scanning
6. Rollout secret scanning
Secret scanning
About secret scanning
Configure secret scans
Define custom patterns
Manage secret alerts
Secret scanning patterns
Push protection for repositories
Push a blocked branch
Troubleshoot secret scanning
Code scanning
Introduction
About code scanning
About CodeQL code scanning
Create workflow code scanning
Configure code scanning
Customize code scanning
CodeQL for compiled languages
CodeQL code scanning at scale
Hardware resources for CodeQL
Code scanning in a container
Manage alerts
About code scanning alerts
Manage alerts
Triage alerts in pull requests
Manage code scanning
View code scanning logs
Integrate with code scanning
About integration
Using code scanning with your existing CI system
Upload a SARIF file
SARIF support
Troubleshooting code scanning
Advanced Security must be enabled
Alerts in generated code
Analysis takes too long
Automatic build failed
Cannot enable CodeQL in a private repository
Extraction errors in the database
Fewer lines scanned than expected
Logs not detailed enough
No source code seen during build
Not recognized
Out of disk or memory
Some languages not analyzed
Unnecessary step found
CodeQL CLI
Getting started
About the CodeQL CLI
Setting up the CodeQL CLI
Preparing code for analysis
Analyzing code
Uploading results to GitHub
Customizing analysis
Advanced functionality
Advanced setup of the CodeQL CLI
About CodeQL workspaces
Using custom queries with the CodeQL CLI
Creating CodeQL query suites
Testing custom queries
Testing query help files
Creating and working with CodeQL packs
Publishing and using CodeQL packs
Specifying command options in a CodeQL configuration file
Query reference files
CodeQL CLI SARIF output
CodeQL CLI CSV output
Extractor options
Exit codes
CodeQL CLI manual
bqrs decode
bqrs diff
bqrs hash
bqrs info
bqrs interpret
database add-diagnostic
database analyze
database bundle
database cleanup
database create
database export-diagnostics
database finalize
database import
database index-files
database init
database interpret-results
database print-baseline
database run-queries