dotnet / docker-tools

This is a repo to house some common tools for our various docker repos.
MIT License
122 stars 46 forks source link

Add CodeQL 3000 Scanning #1120

Closed lbussell closed 1 year ago

lbussell commented 1 year ago

With this change, the CodeQL tasks capture and upload a snapshot that will be analyzed by CodeQL 3000. Then, the results of the scan will be filed as work items under the areaPath on devdiv.visualstudio.com. Here is an example of the scan [internal Microsoft link]. That scan had the issue-filing turned off before we confirm what area path to use.

I added as much as possible to eng/common for re-use in the other .NET Docker repos.

dotnet-issue-labeler[bot] commented 1 year ago

I couldn't figure out the best area label to add to this PR. If you have write-permissions please help me learn by adding exactly one area label.