Add CodeQL static analysis workflow
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 72/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- github-actions, typescript
Research direction
Start by reviewing .github/dependabot.yml and existing files under .github/workflows to understand the repository's GitHub Actions conventions. Add a CodeQL workflow for javascript-typescript on pushes and pull requests targeting main, plus a weekly schedule. Confirm the workflow runs green on main and that alerts appear in Security → Code scanning; update TRIAGE.md only if needed.
Written by the indexing model from the issue text.
Description
Summary
Gap: CodeQL is still not configured; tracked as a follow-up so static analysis covers more than dependency alerts.
Context
We now have Dependabot active for npm + GitHub Actions, and npm audit on main is down to 0 after recent remediation work. Dependency scanning alone is not enough — CodeQL would add SAST coverage for the website (JS/TS) and workflow/config surfaces.
Related recent work:
- Dependabot remediation: https://github.com/IntersectMBO/developer-experience/pull/286 · https://github.com/IntersectMBO/developer-experience/issues/285
- Remaining
image-sizepatch: https://github.com/IntersectMBO/developer-experience/pull/295 · https://github.com/IntersectMBO/developer-experience/issues/294 - Dependabot config: https://github.com/IntersectMBO/developer-experience/blob/main/.github/dependabot.yml
Proposal
- Add a GitHub Actions CodeQL workflow under
.github/workflows/(e.g.codeql.yml). - Enable analysis for
javascript-typescript(primary stack forwebsite/). - Run on:
pushtomainpull_requesttargetingmain- weekly
schedule(recommended default)
- Confirm results appear under the repo Security → Code scanning tab.
- Optionally tune query suite (
security-extended/ default) once baseline noise is understood.
Acceptance criteria
- CodeQL workflow merged and running green on
main - Code scanning alerts visible in GitHub Security
- Docs/notes updated if triage process should mention CodeQL alongside Dependabot (
TRIAGE.mdif appropriate)
Priority
Medium — closes a known maintainer security gap after dependency remediation.
- Dominant language
- TypeScript
- Stars
- 13
- Forks
- 22
- Avg merge
- 19h 1m
- Merged PRs (30d)
- 10
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from IntersectMBO/developer-experience
-
documentation good first issue
Difficulty 3/5 1-2 days Newbie friendliness 70/100
IntersectMBO/developer-experience#302 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 58/100
IntersectMBO/developer-experience#301 ·
Maintainers usually reply within 1 day
-
The component & design-token baseline for human and agentic developers (spacing, typography, theme, etc)Possibly taken @IanoNjuguna claimed this 17 days ago. Open
IntersectMBO/developer-experience#300 · 1 assignee ·
Maintainers usually reply within 1 day
-
documentation enhancement good first issue Medium Priority stale
Difficulty 3/5 1-2 days Newbie friendliness 70/100
IntersectMBO/developer-experience#265 · 1 comment ·
Maintainers usually reply within 1 day
-
documentation enhancement High Priority stale
Difficulty 3/5 1-2 days Newbie friendliness 68/100
IntersectMBO/developer-experience#264 · 1 comment ·
Maintainers usually reply within 1 day
All issues in IntersectMBO/developer-experience
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Doist/todoist-cli#576 ·
Maintainers usually reply within 1 day
-
feature
Difficulty 1/5 Under an hour Newbie friendliness 72/100
vercel-labs/skills#2370 ·
Maintainers usually reply within 1 day
-
🐛 Bug supabase/cli
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
CopilotKit/aimock#491 ·
Maintainers usually reply within 1 day