New GitHub code scanning tech should make it easier to spot security flaws

Computer programming source code. Programming code abstract technology background of software developer and Computer script.
(Image credit: Shutterstock/BEST-BACKGROUNDS)

GitHub now allows developers to scan their code for the “default setup” repository, hopefully helping them to spot any security issues before they escalate.

With this new feature, Github says developers will be able to configure the repository automatically, and with as little effort as possible. 

GitHub’s code scanning is powered by its CodeQL engine, and while it supports a wide variety of compilers, so far the feature is only available for Python, JavaScript, and Ruby. That should change soon, said GitHub’s Walker Chabbott, as the company now seeks to expand the support to additional languages by summer.

Simplifying bug hunting

Those looking to test out the new feature should open up their repository’s settings, navigate to “Code security and analysis”, and click the “Set up” drop-down menu. There, they’ll find the “Default” option.

"When you click on 'Default,' you'll automatically see a tailored configuration summary based on the contents of the repository," Chabbott said in the blog post. "This includes the languages detected in the repository, the query packs that will be used, and the events that will trigger scans. In the future, these options will be customizable."

Once “Enable CodeQL” is turned on, the feature will automatically start looking for flaws in the repository.

The CodeQL code analysis engine, BleepingComputer reminds, was added to the GitHub platform in September 2019, following the latter’s acquisition. 

After a year in beta testing, general availability was announced in September 2020. During the beta stage, the tool scanned more than 12,000 repositories, 1.4 million times, and found more than 20,000 security vulnerabilities. Some of these were of high severity, including remote code execution (RCE), SQL injection, and cross-site scripting (XSS).

Scanning the code is free of charge for all, the publication added, stressing that Enterprise users can also benefit from it, via the GitHub Advanced Security for GitHub Enterprise.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
Latest in Security
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Latest in News
An image of the Nintendo Switch 2
Nintendo Switch 2 pre-orders will start on April 2 according to Best Buy Canada
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long
Screenshot from action RPG soulslike Lies of P
Lies of P Overture won't elaborate on the game's eyebrow-raising post-credits twist, and I think that's good news
Nintendo Switch 2
The Switch 2 launching with a Mario Kart game 'is very unlike Nintendo' compared to the original Switch releasing with Breath of the Wild, says former marketing leads: 'That's what's gonna make you want to buy the new hardware'