GitHub now allows developers to scan their code for the “default setup” repository, hopefully helping them to spot any security issues before they escalate.
With this new feature, Github says developers (opens in new tab) will be able to configure the repository automatically, and with as little effort as possible.
Simplifying bug hunting
Those looking to test out the new feature should open up their repository’s settings, navigate to “Code security and analysis”, and click the “Set up” drop-down menu. There, they’ll find the “Default” option.
"When you click on 'Default,' you'll automatically see a tailored configuration summary based on the contents of the repository," Chabbott said in the blog post. "This includes the languages detected in the repository, the query packs that will be used, and the events that will trigger scans. In the future, these options will be customizable."
Once “Enable CodeQL” is turned on, the feature will automatically start looking for flaws in the repository.
The CodeQL code analysis engine, BleepingComputer reminds, was added to the GitHub platform in September 2019, following the latter’s acquisition.
After a year in beta testing, general availability was announced in September 2020. During the beta stage, the tool scanned more than 12,000 repositories, 1.4 million times, and found more than 20,000 security vulnerabilities. Some of these were of high severity, including remote code execution (RCE), SQL injection, and cross-site scripting (XSS).
Scanning the code is free of charge for all, the publication added, stressing that Enterprise users can also benefit from it, via the GitHub Advanced Security for GitHub Enterprise.
- Here are the best firewalls (opens in new tab) right now
Via: BleepingComputer (opens in new tab)