statuses
statuses copied to clipboard
chore: add codeql pipeline
Main Changes
This change includes the addition of CodeQL as the SAST tool for the project. It will run an analysis every day-
Impact on the OSSF Scorecard
Context
Changes related
Team discussion related
- Ref: https://github.com/expressjs/security-wg/issues/2
- Report: https://kooltheba.github.io/openssf-scorecard-api-visualizer/#/projects/github.com/jshttp/statuses/commit/454ceb6e0bfea4f889be244de2538df8afb4dc2a