binkley / modern-java-practices

Modern Java/JVM Build Practices
The Unlicense
920 stars 69 forks source link

Talk about CodeQL from GitHub #564

Open binkley opened 3 days ago

binkley commented 3 days ago

We have this turned on in GitHub actions. It is a checkbox to enable, but no one is sure what it does, or how to see reports.

Add writing to discuss alongside other quality features like Spotless, etc.

CodeQL is a feature from GitHub enabled in https://github.com/binkley/modern-java-practices/settings/security_analysis. Image