Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge main into v1 #616

Merged
merged 26 commits into from
Jul 12, 2021
Merged
Changes from 4 commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
7c391e9
Update readme to include section on missing analysis
aeisenberg Jun 25, 2021
571fe40
Merge branch 'main' into aeisenberg/readme-missing-analysis
aeisenberg Jun 28, 2021
d11b2ce
Update changelog and version after v1.0.4
invalid-email-address Jun 28, 2021
5c3c29f
1.0.5
invalid-email-address Jun 28, 2021
3a8e184
Merge pull request #599 from github/aeisenberg/readme-missing-analysis
aeisenberg Jun 28, 2021
8cccc06
Merge branch 'main' into mergeback/v1.0.4-to-main-03450ff6
edoardopirovano Jun 28, 2021
1e61ecb
Merge pull request #603 from github/mergeback/v1.0.4-to-main-03450ff6
edoardopirovano Jun 28, 2021
ef852c0
Support splitting of DB creation and query execution
edoardopirovano Jun 28, 2021
a689115
Allow to be run on workflow_dispatch
aeisenberg Jun 28, 2021
4a7cc17
Merge pull request #605 from github/aeisenberg/pr-checks-dispatch
edoardopirovano Jun 28, 2021
9547001
Run tests against nightly CLI bundles
edoardopirovano Jun 25, 2021
24ef87c
Merge pull request #600 from edoardopirovano/integration-test
edoardopirovano Jun 28, 2021
8f4c2c7
Allow local instead of downloaded CodeQL
edoardopirovano Jun 28, 2021
93214ec
Merge branch 'main' into split-create-analysis
edoardopirovano Jun 28, 2021
53cf5d9
Merge pull request #602 from edoardopirovano/split-create-analysis
edoardopirovano Jun 28, 2021
a7dac5c
Address PR comment.
edoardopirovano Jun 28, 2021
d9050f4
Merge branch 'main' into local-bundle
edoardopirovano Jun 28, 2021
c357ca7
Merge pull request #606 from edoardopirovano/local-bundle
edoardopirovano Jun 28, 2021
68f742b
Clarify missing LoC baseline message
aeisenberg Jun 30, 2021
d939c4b
Update CHANGELOG
aeisenberg Jun 30, 2021
c6b33b9
Merge pull request #608 from github/aeisenberg/baseline-message
aeisenberg Jun 30, 2021
0792832
Remove a TODO and use defautl tools option
aeisenberg Jun 30, 2021
fd614e5
Merge pull request #609 from github/aeisenberg/use-default-tools
aeisenberg Jun 30, 2021
870e8e3
Update CodeQL bundle to 20210702 / 2.5.7
hmakholm Jul 2, 2021
1c26d40
Merge pull request #613 from github/hmakholm/pr/2.5.7
hmakholm Jul 2, 2021
aa03f9b
1.0.5
invalid-email-address Jul 12, 2021
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -128,3 +128,11 @@ By default, this will override any queries specified in a config file. If you wi
## Troubleshooting

Read about [troubleshooting code scanning](https://help.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/troubleshooting-code-scanning).

### Note on "missing analysis" message

The very first time code scanning is run and if it is on a pull request, you will probably get a message mentioning a "missing analysis". This is expected.

After code scanning has analyzed the code in a pull request, it needs to compare the analysis of the topic branch (the merge commit of the branch you used to create the pull request) with the analysis of the base branch (the branch into which you want to merge the pull request). This allows code scanning to compute which alerts are newly introduced by the pull request, which alerts were already present in the base branch, and whether any existing alerts are fixed by the changes in the pull request. Initially, if you use a pull request to add code scanning to a repository, the base branch has not yet been analyzed, so it's not possible to compute these details. In this case, when you click through from the results check on the pull request you will see the "Missing analysis for base commit SHA-HASH" message.

For more information and other causes of this message, see [Reasons for the "missing analysis" message](https://docs.github.com/en/code-security/secure-coding/automatically-scanning-your-code-for-vulnerabilities-and-errors/setting-up-code-scanning-for-a-repository#reasons-for-the-missing-analysis-message)