Codegarden 2024: GitHub CodeQL, query your source code and find vulnerabilities

Опубликовано: 19 Октябрь 2024
на канале: Umbraco HQ
73
0

CodeQL is a static analysis engine you can use to find vulnerabilities and bugs in source code. It works by processing your code with a special compiler that emits a database and letting you query that database with either pre-defined or custom queries. The query language is rich enough for deep security analysis and abstract enough to support code reuse at the scale of 100,000s of lines of query code. This talk will dive into how that all works and how it can be applied to Umbraco and its ecosystem.

Learn more about Umbraco on our website https://umbraco.com
Discover our Umbraco Community: https://community.umbraco.com/
Find the Umbraco source code on Github: https://github.com/umbraco/Umbraco-CMS
Visit the Umbraco Documentation: https://docs.umbraco.com