open-telemetry / sig-security

Apache License 2.0
7 stars 8 forks source link

Add recommendation around CodeQL #15

Closed codeboten closed 9 months ago

codeboten commented 10 months ago

The following question came up in https://github.com/open-telemetry/opentelemetry-js/issues/4101

Are there any specific recommendations from the Security SIG on running CodeQL? Ours runs once a day, but both the collector and java seem to run on every PR and push to main - should we change our workflow to do the same?

Creating this issue to document the recommendation in this repository

codeboten commented 10 months ago

From a discussion in the #otel-sig-security slack channel, the proposal is to recommend running CodeQL on pushes to main and on every PR