Commit to add CodeQL workflow for Static App Security Testing.
Description
Commit to add CodeQL workflow for Static App Security Scanning.
Motivation and Context
This commit allows us to run Github CodeQl as Github Actions and use CodeQL as a Static Application Security Testing tool to identify security vulnerabilities in code before it gets merged to master and deployments made.
Acceptance Criteria
Screenshots (if appropriate)
Types of changes
[ ] Bug fix (non-breaking change which fixes an issue)
[x] New feature (non-breaking change which adds functionality)
[ ] Breaking change (fix or feature that would cause existing functionality to change)
Checklist
[x] My pull request addresses exactly one patch/feature.
[x] I have created a branch for this patch/feature.
[x] Each individual commit in the pull request is meaningful. (Please rebase, removing useless commits if not)
[ ] I have added tests to cover my changes.
[ ] All new and existing tests passed.
[x] My code follows the code style of this project.
[ ] My change requires change(s) to the environment.
Setup CodeQL for SAST
Commit to add CodeQL workflow for Static App Security Testing.
Description
Commit to add CodeQL workflow for Static App Security Scanning.
Motivation and Context
This commit allows us to run Github CodeQl as Github Actions and use CodeQL as a Static Application Security Testing tool to identify security vulnerabilities in code before it gets merged to
master
and deployments made.Acceptance Criteria
Screenshots (if appropriate)
Types of changes
Checklist