Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Add CodeQL static analysis workflow

Open
#298 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
72/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
github-actions, typescript
Domain
ci-cd, security

Research direction

Start by reviewing .github/dependabot.yml and existing files under .github/workflows to understand the repository's GitHub Actions conventions. Add a CodeQL workflow for javascript-typescript on pushes and pull requests targeting main, plus a weekly schedule. Confirm the workflow runs green on main and that alerts appear in Security → Code scanning; update TRIAGE.md only if needed.

Written by the indexing model from the issue text.

Description

Summary

Gap: CodeQL is still not configured; tracked as a follow-up so static analysis covers more than dependency alerts.

Context

We now have Dependabot active for npm + GitHub Actions, and npm audit on main is down to 0 after recent remediation work. Dependency scanning alone is not enough — CodeQL would add SAST coverage for the website (JS/TS) and workflow/config surfaces.

Related recent work:

Proposal

  1. Add a GitHub Actions CodeQL workflow under .github/workflows/ (e.g. codeql.yml).
  2. Enable analysis for javascript-typescript (primary stack for website/).
  3. Run on:
    • push to main
    • pull_request targeting main
    • weekly schedule (recommended default)
  4. Confirm results appear under the repo Security → Code scanning tab.
  5. Optionally tune query suite (security-extended / default) once baseline noise is understood.

Acceptance criteria

  • CodeQL workflow merged and running green on main
  • Code scanning alerts visible in GitHub Security
  • Docs/notes updated if triage process should mention CodeQL alongside Dependabot (TRIAGE.md if appropriate)

Priority

Medium — closes a known maintainer security gap after dependency remediation.

Dominant language
TypeScript
Stars
13
Forks
22
Avg merge
19h 1m
Merged PRs (30d)
10

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from IntersectMBO/developer-experience

All issues in IntersectMBO/developer-experience

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.