æ¥æ¬èª
Code security
- Get started
- Account and profile
- Authentication
- Repositories
- GitHub
- Enterprise administrators
- Billing and payments
- Organizations
- Code security
- Pull requests
- GitHub Issues
- GitHub Actions
- GitHub Codespaces
- GitHub Packages
- Search on GitHub
- Developers
- REST API
- GraphQL API
- GitHub CLI
- GitHub Discussions
- GitHub Sponsors
- Building communities
- GitHub Pages
- Education
- GitHub Desktop
- GitHub Support
- Atom
- Electron
- CodeQL
- npm
GitHub AE
æ¥æ¬èª
Code security
Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase.
ã¬ã€ã
View allã³ãŒãäŸ
Microsoftã«ãããCodeQLã®Code Scanning
Microsoftã®ãªãŒãã³ãœãŒã¹ãªããžããªããã®CodeQLã¢ã¯ã·ã§ã³ã®ããã®Code Scanningã¯ãŒã¯ãããŒã®äŸã
CodeQLCode scanningGitHub ActionsAdversarial Robustness Toolbox (ART) CodeQL Code Scanning
Trusted AIãªããžããªããã®CodeQLã¢ã¯ã·ã§ã³ã®ããã®Code Scanningã¯ãŒã¯ãããŒã®äŸã
CodeQLCode scanningGitHub ActionsMicrosoftã»ãã¥ãªãã£ããªã·ãŒ
ã»ãã¥ãªãã£ããªã·ãŒã®äŸ
ã»ãã¥ãªãã£ããªã·ãŒElectronã®ã»ãã¥ãªãã£ããªã·ãŒ
ã»ãã¥ãªãã£ããªã·ãŒã®äŸ
ã»ãã¥ãªãã£ããªã·ãŒRailsã®ããã®ã»ãã¥ãªãã£ã¢ããã€ã¶ãª
Railsã«ãã£ãŠå ¬éãããCVE-2020-15169ã®ããã®ã»ãã¥ãªãã£ã¢ããã€ã¶ãª
ã»ãã¥ãªãã£ã¢ããã€ã¶ãª
ã¬ã€ã
Configuring secret scanning for your repositories
You can configure how GitHub scans your repositories for secrets.
Uploading a SARIF file to GitHub
ãµãŒãããŒãã£ã®éçè§£æããŒã«ããGitHubã«SARIFãã¡ã€ã«ãã¢ããããŒããããªããžããªå ã§ãããã®ããŒã«ããã®code scanningã¢ã©ãŒããèŠãããšãã§ããŸãã
æ¢åã® CI ã·ã¹ãã ã§ CodeQL Code scanningã䜿çšãã
æ¢åã®CIã·ã¹ãã å ã§CodeQLåæãå®è¡ããçµæãGitHub AEã«ã¢ããããŒãããŠcode scanningã¢ã©ãŒããšããŠè¡šç€ºãããããšãã§ããŸãã
ãããã®ããã¥ã¡ã³ããçŽ æŽããããã®ã«ããã®ãæäŒã£ãŠãã ããïŒ
GitHubã®ãã¹ãŠã®ããã¥ã¡ã³ãã¯ãªãŒãã³ãœãŒã¹ã§ããééã£ãŠããããã¯ã£ããããªããšããããããŸãããïŒPull Requestããéããã ããã
ã³ã³ããªãã¥ãŒã·ã§ã³ãè¡ãOR, ã³ã³ããªãã¥ãŒã·ã§ã³ã®æ¹æ³ãåŠãã§ãã ããã