This workflow uses GitHub's CodeQL analysis tool to perform static code analysis, identifying potential security vulnerabilities and coding errors. It supports multiple languages and can be configured for various code scanning needs.
name: CodeQL
on:
pull_request:
branches: [main, develop]
push:
branches: [main, develop]
schedule:
- cron: '0 0 * * 0' # Weekly on Sunday
jobs:
analyze:
name: CodeQL Analysis
secrets: inherit
uses: bfra-me/.github/.github/workflows/codeql-analysis.yaml@v2.3.5| Parameter | Description | Required | Default |
|---|---|---|---|
secrets: inherit |
Inherits secrets from the caller workflow | Yes | - |
No additional parameters are required for basic usage. Advanced configurations are defined in the workflow template variables.
- Pull Request: Runs on pull requests to specified branches
- Push: Runs on pushes to specified branches
- Schedule: Runs on a defined schedule (default: weekly)
The workflow requires the following permissions:
security-events: write- For uploading results to code-scanning dashboardactions: read- For private repositoriescontents: read- For accessing repository contentpackages: read- For fetching internal or private CodeQL packs
CodeQL Analysis supports scanning code written in:
- C/C++ (use
c-cpp) - C# (use
csharp) - Go (use
go) - Java/Kotlin (use
java-kotlin) - JavaScript/TypeScript (use
javascript-typescript) - Python (use
python) - Ruby (use
ruby) - Swift (use
swift)
The workflow detects languages automatically based on the repository content.
jobs:
run-codeql:
uses: bfra-me/.github/.github/workflows/codeql-analysis.yaml@v2.3.5on:
schedule:
- cron: '0 0 1 * *' # Monthly on the 1st
jobs:
run-codeql:
uses: bfra-me/.github/.github/workflows/codeql-analysis.yaml@v2.3.5on:
pull_request:
branches: [main, release/*]
push:
branches: [main, release/*]
jobs:
run-codeql:
uses: bfra-me/.github/.github/workflows/codeql-analysis.yaml@v2.3.5-
Security Vulnerability Detection
- Identifies common security vulnerabilities
- Detects unsafe coding patterns
- Finds potential injection points
-
Code Quality Analysis
- Identifies code quality issues
- Detects potential bugs and errors
- Finds performance issues
-
Language-Specific Analysis
- Customized analysis for each supported language
- Language-specific vulnerability detection
- Tailored code quality checks
CodeQL supports different build modes depending on the language:
-
Automatic Build
- Default for most languages
- CodeQL automatically attempts to build the code
- Works for many standard project configurations
-
Manual Build
- For projects with custom build systems
- Requires specifying build commands
- Provides more control over the analysis process
-
No Build
- For interpreted languages like JavaScript, Python
- No build step required
- Analysis runs directly on source code
The workflow provides the following outputs:
- Code scanning alerts in the GitHub Security tab
- SARIF format analysis results
- Detailed information about each identified issue
- Suggestions for fixing detected problems
-
Custom Queries
- name: Initialize CodeQL uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality
-
Custom Build Commands
- if: matrix.build-mode == 'manual' run: | make bootstrap make release
-
Database Path Customization
- name: Initialize CodeQL uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} db-location: /tmp/codeql-db
Common errors and solutions:
-
Build Failures
- Check if the correct build mode is selected
- Verify build dependencies are installed
- Consider switching to manual build mode
-
Memory Issues
- Increase runner memory if available
- Break analysis into smaller parts
- Exclude large generated files
-
Timeout Issues
- Optimize build process
- Use caching for build artifacts
- Consider breaking analysis into steps
-
Performance Optimization
- Use path filters to exclude irrelevant files
- Cache build artifacts when possible
- Schedule resource-intensive analysis outside peak hours
-
Integration
- Set as a required check for pull requests
- Review alerts regularly
- Prioritize fixing high-severity issues
-
Maintenance
- Keep CodeQL version updated
- Review false positives and adjust configuration
- Document custom configurations and exclusions
-
Unable to Automatically Build
- Switch to manual build mode
- Provide explicit build commands
- Check for missing dependencies
-
Analysis Taking Too Long
- Exclude large generated files
- Use path filters to focus analysis
- Split analysis across multiple runners
-
False Positives
- Customize query suites
- Add inline suppressions with comments
- Create custom CodeQL queries
For additional support:
- Check the troubleshooting guide
- Review existing issues
- Visit the GitHub CodeQL documentation
- Create a new issue with:
- Workflow version
- Language and build system details
- Error messages
- Steps to reproduce