CodeQL is a static analysis tool that can scan your code for vulnerabilities. CodeQL lets you query code as though it was data. By writing queries you can find variants of a vulnerability. The easiest way to try out CodeQ is by enabling the code scanning with CodeQL GitHub Action.
3 Comments
Sort: