Skip to content

[Bug] CodeQL not surfacing alert in Security and quality tab > Code scanning #77

Description

@FaithOmbongi

Summary

At Step 3 of this exercise, CodeQL failed to surface the detected vulnerability on the Security and quality tab > Code scanning page. Although the github-advanced-security[bot] commented on the PR to highlight the alert, the Code scanning dashboard remained empty. I reproduced this issue twice on separate days using fresh copies of the template repo and am unsure whether the bug lies within the exercise configuration or CodeQL itself.

The bot comment

Image

vs the Code scanning page showing no alerts

Image

How to reproduce

  1. Copy the exercise
  2. Complete Steps 1 and 2
  3. Observe that the github-advanced-security[bot] comments on the PR with the vulnerability alert, but no alerts appear on the Code scanning dashboard.

See above

Additional context

N/A

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions