Sage-Bionetworks / Genie

Validation and processing of GENIE files
https://genie.synapse.org/
MIT License
12 stars 9 forks source link

[IBCDPE-219] Create codeql.yml action #471

Closed thomasyu888 closed 2 years ago

thomasyu888 commented 2 years ago

This PR does code scanning of the GENIE codebase. The reason for this is to reduce code security issues because this is a project that touches phi data. This is part of best practices of application security.

thomasyu888 commented 2 years ago

Unsure if using LGTM or using codeQL as a github action is a better practice.

thomasyu888 commented 2 years ago

My initial thought is that LGTM takes way too long and codeQL is really fast - will set this as a standard