GitHub Code Scanning Generally Available
Written by Kay Ewbank   
Wednesday, 30 September 2020

Github's code analysis technology based on CodeQL, which it acquired as part of its purchase of Semmie in 2019, is now out of beta and generally available.

The new natively integrated code scanning is based on the CodeQL technology. CodeQL is a tool many security research teams around the world use to perform semantic analysis of code, and was made open source by GitHub once Semmie was acquired.

githubdeklogo

The aim of the new facility is to help developers prevent security issues in code. The code scanning doesn't make linting suggestions, and the scanning runs only the actionable security rules by default to prevent developers being overwhelmed by suggestions.

The scanning integrates with GitHub Actions or with CI/CD environments. It scans code as it’s created and creates security reviews with suggested actions within pull requests to automate security as a part of your workflow. The aim is to make sure vulnerabilities never make it to production in the first place. 

The underlying CodeQL code analysis engine has more than 2,000 CodeQL queries created by GitHub and the community, and developers can also create custom queries.

The scanning is based on the open SARIF (Static Analysis Results Interchange Format) standard that is an interoperability standard for detecting software defects and vulnerabilities. The scanning is extensible so you can include open source and commercial static application security testing (SAST) solutions within the same GitHub-native experience. Developers can also integrate third-party scanning engines.

GitHub says that since introducing the beta in May, 12,000 repositories have been scanned 1.4 million times, and more than 20,000 security issues have been found and fixed, including remote code execution (RCE), SQL injection, and cross site scripting (XSS) vulnerabilities.

Code scanning is free for public repositories. Private repositories can be scanned using GitHub Enterprise through GitHub Advanced Security.

githubdeklogo 

More Information

GitHub code scanning

Related Articles

GitHub Strengthens Team Working

The Trap Snaps Shut - GitHub Codespaces

New From GitHub Universe

GitHub Launches Actions

Microsoft Buys GitHub - Get Ready For a Bigger Devil

To be informed about new articles on I Programmer, sign up for our weekly newsletter, subscribe to the RSS feed and follow us on Twitter, Facebook or Linkedin.

Banner


Ruby On Rails Adds Kamal And Thruster Support
17/12/2024

Ruby on Rails 8 has been released. The new version comes preconfigured with Kamal 2 for application deployment, a new proxy called Thruster, and a trio of SQLite database-backed adapters named Solid C [ ... ]



Amazon Adds Agents To Q Developer
05/12/2024

Amazon has announced enhancements to Amazon Q Developer, including agents that automate unit testing, documentation generation, code reviews, and a capability to help users "address operational issues [ ... ]


More News

espbook

 

Comments




or email your comment to: comments@i-programmer.info

Last Updated ( Wednesday, 30 September 2020 )