We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A static code analysis tool could alert us quicker on things that circular dependencies, syntax errors, code quality, and best practices.
(optional) A clear and concise description of any alternative solutions or features you've considered.
Add any other context or screenshots about the feature request here.
The text was updated successfully, but these errors were encountered:
Internal blog post about running SAST locally. Mention of CodeQL and SemGrep.
We already use CodeQL, maybe we can revisit the configuration. Grype does vulnerability scanning for us.
Sorry, something went wrong.
This points to a broader organization topic about what tooling belongs across common CI/CD pipelines. Coda page here and a slack thread here.
I'll opt for some of the low-hanging fruit while we figure out broader policies.
Security scanning:
0d3a5b2
samayer12
Successfully merging a pull request may close this issue.
Is your feature request related to a problem? Please describe.
A static code analysis tool could alert us quicker on things that circular dependencies, syntax errors, code quality, and best practices.
Describe the solution you'd like
Describe alternatives you've considered
(optional) A clear and concise description of any alternative solutions or features you've considered.
Additional context
Add any other context or screenshots about the feature request here.
The text was updated successfully, but these errors were encountered: