Skip to content

Enable CodeQL security scanner#12101

Merged
alexey-milovidov merged 1 commit intomasterfrom
codeql-analysis
Jul 3, 2020
Merged

Enable CodeQL security scanner#12101
alexey-milovidov merged 1 commit intomasterfrom
codeql-analysis

Conversation

@blinkov
Copy link
Contributor

@blinkov blinkov commented Jul 3, 2020

Changelog category (leave one):

  • Build/Testing/Packaging Improvement

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):
Daily check by GitHub CodeQL security analysis tool that looks for CWE.

Detailed description / Documentation draft:
On ClickHouse fork found 175 instances of 7 different CWE (including contrib). Takes 10+ hours, so can't be run frequently.

@blinkov blinkov added the pr-build Pull request with build/testing/packaging improvement label Jul 3, 2020
@alexey-milovidov
Copy link
Member

On ClickHouse fork found 175 instances of 7 different CWE (including contrib).

Could you please post a list of them here?

@blinkov
Copy link
Contributor Author

blinkov commented Jul 3, 2020

@alexey-milovidov no, security issues are not supposed to be published before fixes.

@alexey-milovidov
Copy link
Member

@blinkov You can publish all of them here without any worries.

@alexey-milovidov alexey-milovidov self-assigned this Jul 3, 2020
@alexey-milovidov alexey-milovidov merged commit d4d9de2 into master Jul 3, 2020
@alexey-milovidov alexey-milovidov deleted the codeql-analysis branch July 3, 2020 12:50
@alexey-milovidov
Copy link
Member

@blinkov If it is not possible to disable scanning of subdirectories (contrib), you should create an issue in the repository of "CodeQL security scanner" with a link to this PR.

@alexey-milovidov
Copy link
Member

Screenshot_20200705_011740

@alexey-milovidov
Copy link
Member

CodeQL is useful, one bug has been found: #12138

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-build Pull request with build/testing/packaging improvement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants