Code scanning finds vulnerable patterns in source code and shows them as alerts on the Security and quality tab and as annotations on pull requests. GitHub 29 's own engine, CodeQL 29 (https://github.com/github/codeql 10,133 ), compiles the code into a relational database and runs queries over it, tracing data from sources (a request parameter) to sinks (a SQL string, a shell command, eval). It is free for public repositories. Default setup needs no workflow file: GitHub detects the languages and runs its own analysis:
gh api -X PATCH repos/{owner}/{repo}/code-scanning/default-setup -f state=configured
gh api repos/{owner}/{repo}/code-scanning/default-setup --jq '{state, languages, schedule}'{"run_id":36149512735,"run_url":"https://api.github.com/repos/binarybehemoth/booknest/actions/
runs/36149512735"}{"languages":["actions","javascript","javascript-typescript","typescript"],
"schedule":"weekly","state":"configured"}Default setup found JavaScript and TypeScript, and actions: the workflow files themselves, where CodeQL looks for script injection, untrusted checkouts and cache poisoning. It analyzes pushes to main, pull requests, and once a week; the first run logged "CodeQL scanned 14 out of 14 GitHub Actions 29 files, 6 out of 6 JavaScript files and 1 out of 1 HTML files". When a build needs customizing, or you want extra query packs such as security-extended, advanced setup commits a codeql.yml using github/codeql-action's init, autobuild and analyze. CodeQL on private code needs Code Security (Advanced Security).