Skip to content

Conversation

@robertbrignull
Copy link
Contributor

I don't think we want to be analyzing the lib directory as that's all generated code and we're currently getting some duplicate alerts showing up.

It'll theoretically also show up alerts from dependencies, although I can't actually see any such alerts right now. Although this could be informative, it's not the way that codeql is meant to be used. It'll be more useful to rely on things like CVEs and dependabot to find out about vulnerabilities in dependencies.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Confirm the readme has been updated if necessary.

@robertbrignull robertbrignull changed the title Update codeql-config.yml Exclude lib directory from analysis Jul 7, 2020
@robertbrignull
Copy link
Contributor Author

Good, this reports 1 fix as I would expect
https://github.com/github/codeql-action/pull/102/checks?check_run_id=845489749

Copy link
Contributor

@chrisgavin chrisgavin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants