Gaspare Vitta 10/6/2020

An evaluation of Github code scanning

Read Original

This article provides a technical evaluation of GitHub's newly released Code Scanning feature, which uses the CodeQL semantic analysis engine. The author sets up a test using a deliberately vulnerable C code repository (fuzzgoat) to analyze how effectively CodeQL identifies specific security flaws like use-after-free and invalid memory frees. It includes details on configuration, query sets, and an analysis of the tool's performance.

An evaluation of Github code scanning

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week