Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MS Learn Module Update Request: Identify security vulnerabilities in your codebase with CodeQL #107

Open
1 of 4 tasks
knewbury01 opened this issue Sep 25, 2023 · 1 comment

Comments

@knewbury01
Copy link

knewbury01 commented Sep 25, 2023

Which of the MS Learn modules from the dropdown are you submitting an update request?

GitHub administration for GitHub Advanced Security

Additional information

  • Fix a broken user experience (broken links, exercise error, etc.)
  • Update incorrect information
  • Add new content to the module
  • Some other request

Information about the requested update

  1. in Unit 2 under header "Download the CodeQL CLI zip package" -
    there is a duplicated sentence across 2 sequential paragraphs - "Alternatively, you can download the codeql.zip file that contains the CLI for all supported platforms."
    Remove one of the sentences

  2. in Unit 2 under header "Obtain a local copy of the CodeQL queries"-
    the info on the Go repo should be updated, it used to be in a separate repo but has since all been moved to the same one as the other languages
    there is a similar update that should be made in the Module "Code scanning with GitHub CodeQL " Unit 2 under "Query Language (QL) packs" about the (now deprecated) separation of the Go repo

  3. in Unit 2 under header "Potential CodeQL shortfalls" -
    unsure about why it says: "Analysis of compiled languages, other than Go, will fail unless you supply explicit commands" ? this is false, autobuild will not always fail on compiled languages.

  4. in Unit 3 under the header "Upload 3rd party SARIF results" -
    in the sentence "Fingerprint data is included in SARIF files created by the CodeQL analysis workflow or using the CodeQL runner."
    the runner is deprecated, probably ought to remove mention of it

@Chukslord1
Copy link
Collaborator

Hi @knewbury01 ,

Thank you so much for submitting this issue and we apologize for your inconvenient experience. Our team is in the process of revising and updating the MS Learn modules for GitHub Advanced Security, and we assure you that your feedback will be incorporated into the upcoming updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants