Code security
Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase.
Guides
View allCode examples
CodeQL code scanning at Microsoft
Example code scanning workflow for the CodeQL action from the Microsoft Open Source repository.
CodeQLCode scanningGitHub ActionsAdversarial Robustness Toolbox (ART) CodeQL code scanning
Example code scanning workflow for the CodeQL action from the Trusted AI repository.
CodeQLCode scanningGitHub ActionsMicrosoft security policy template
Example security policy
Security policyElectron security policy
Example security policy
Security policySecurity advisory for Rails
Security advisory published by Rails for CVE-2020-15169.
Security advisory
Guides
Configuring secret scanning for your repositories
You can configure how GitHub scans your repositories for secrets that match advanced security patterns.
Uploading a SARIF file to GitHub
You can upload SARIF files generated outside GitHub and see code scanning alerts from third-party tools in your repository.
Using CodeQL code scanning with your existing CI system
You can run CodeQL analysis in your existing CI system and upload the results to GitHub AE for display as code scanning alerts.
Securing your end-to-end supply chain
Introducing best practice guides on complete end-to-end supply chain security including personal accounts, code, and build processes.

