Summary
At Step 3 of this exercise, CodeQL failed to surface the detected vulnerability on the Security and quality tab > Code scanning page. Although the github-advanced-security[bot] commented on the PR to highlight the alert, the Code scanning dashboard remained empty. I reproduced this issue twice on separate days using fresh copies of the template repo and am unsure whether the bug lies within the exercise configuration or CodeQL itself.
The bot comment
vs the Code scanning page showing no alerts
How to reproduce
- Copy the exercise
- Complete Steps 1 and 2
- Observe that the
github-advanced-security[bot] comments on the PR with the vulnerability alert, but no alerts appear on the Code scanning dashboard.
See above
Additional context
N/A
Summary
At Step 3 of this exercise, CodeQL failed to surface the detected vulnerability on the Security and quality tab > Code scanning page. Although the
github-advanced-security[bot]commented on the PR to highlight the alert, the Code scanning dashboard remained empty. I reproduced this issue twice on separate days using fresh copies of the template repo and am unsure whether the bug lies within the exercise configuration or CodeQL itself.The bot comment
vs the Code scanning page showing no alerts
How to reproduce
github-advanced-security[bot]comments on the PR with the vulnerability alert, but no alerts appear on the Code scanning dashboard.See above
Additional context
N/A