envoyproxy/envoy

Apply CodeQL/LGTM/Semmle static analysis to Envoy code base

Open

#9,485 opened on Dec 26, 2019

 (6 comments) (0 reactions) (0 assignees)C++ (5,373 forks)batch import
area/securityhelp wanted

Repository metrics

Stars
 (27,997 stars)
PR merge metrics
 (PR metrics pending)

Description

GitHub now has CodeQL for OSS projects (https://securitylab.github.com/tools/codeql). This is Semmle (lgtm.com), a fairly powerful static analysis tool. We should look at setting this up for Envoy, analyzing reports and adding custom queries.

Contributor guide