-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(build): add vulnerability codeql scanning #2879
Conversation
de4d88a
to
507e29b
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
BTW/FYI we cannot see this url. https://github.com/runatlantis/atlantis/security/code-scanning?query=pr%3A2879+tool%3ACodeQL+is%3Aopen
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
as long as this work based on the files included on PRs and not the whole project then it LGTM.
I can see it, maybe this need to be setup as repo level. |
@krrrr38 Perhaps only maintainers can see this? I created this ticket for now and i expand on it if you'd like to work on it #2884. @jamengual since we have the associated ticket. We can dismiss the current issues as non-issues (even tho they are real issues) and associate the ticket in the message. Then we can merge this with passing pr checks so future prs that are contributed will pass or fail depending on the contributed code. |
what
why
references