cFS icon indicating copy to clipboard operation
cFS copied to clipboard

Add codeql configuration files to LGTM setup for better visualization

Open astrogeco opened this issue 3 years ago • 0 comments

Checklist (Please check before submitting)

  • [ x] I reviewed the Contributing Guide.
  • [ x] I performed a cursory search to see if the bug report is relevant, not redundant, nor in conflict with other tickets.

Describe the bug The setup for .lgtm.yml doesn't use the coding standard or security configuration files that we're using for github actions. Figure out how to reference them in the setup

Code snips If applicable, add references to the software.

System observed on: lgtm.com

Context

LGMT.com uses CodeQL as its backend. Although we already run these analyses on github, LGTM provides a more visual layout and dashboard to the findings report AND it is public, which increases transparency to stakeholders.

Alternatives Remove .lgtm.yml and stop using that dashboard. Figure out how to export sarif files from github runs and have LGTM read them.

astrogeco avatar Jul 14 '21 13:07 astrogeco