#codeql#security#github-actions#code-scanning#sast

CodeQL Code Scanning

Independent PiSkill directory guide. The original skill remains hosted by GitHub Awesome Copilot.

What is CodeQL Code Scanning?

Guides CodeQL code scanning through GitHub Actions and the CodeQL CLI, including workflow setup, language configuration, query suites, SARIF output, monorepos, and troubleshooting.

What does CodeQL Code Scanning do?

CodeQL Code Scanning is a GitHub Awesome Copilot skill for setting up and troubleshooting static security analysis with CodeQL. It covers GitHub Actions workflows, default versus advanced setup, language and build-mode configuration, query suites, the CodeQL CLI, SARIF output and monorepo scanning.

Who is CodeQL Code Scanning best for?

  • Teams enabling GitHub code scanning
  • Security engineers customizing CodeQL workflows
  • Developers troubleshooting CodeQL builds
  • Monorepos that need language- or component-specific analysis

Common use cases

  • Create a CodeQL GitHub Actions workflow
  • Choose languages, build modes and query suites
  • Run CodeQL locally with the CLI
  • Generate or upload SARIF security results

How does CodeQL Code Scanning work?

The skill chooses between default and advanced setup, configures workflow triggers and least-privilege permissions, defines the language matrix and build mode, initializes and runs analysis, and helps separate results for monorepos. It also covers creating local CodeQL databases and analyzing them with the CLI.

Key benefits

  • Supports both GitHub Actions and local CLI workflows
  • Covers multiple major programming languages
  • Handles monorepo and custom query scenarios
  • Connects scanning output to SARIF-based security workflows

Things to know

  • CodeQL only analyzes supported languages and query coverage
  • Static analysis can produce false positives or miss runtime flaws
  • Compiled languages may require project-specific build setup

Compatible tools

GitHub Copilot

Frequently asked questions

What does the CodeQL Code Scanning skill help configure?
It helps configure CodeQL in GitHub Actions or the CLI, including languages, build modes, query suites, permissions, SARIF output and monorepo analysis.
Can CodeQL scan JavaScript and TypeScript together?
Yes. CodeQL uses a combined JavaScript/TypeScript language identifier for analysis of those codebases.
← Back to Skills Directory