1
0
mirror of synced 2025-12-20 10:28:40 -05:00
Files
docs/content/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/built-in-codeql-query-suites.md
2023-07-18 13:58:29 +00:00

3.8 KiB

title, shortTitle, intro, product, versions, type, topics
title shortTitle intro product versions type topics
Built-in CodeQL query suites Built-in CodeQL query suites You can choose from different built-in {% data variables.product.prodname_codeql %} query suites to use in your {% data variables.product.prodname_codeql %} {% data variables.product.prodname_code_scanning %} setup. {% data reusables.gated-features.code-scanning %}
feature
code-scanning-without-workflow
reference
Code scanning
CodeQL

About {% data variables.product.prodname_codeql %} query suites

With {% data variables.product.prodname_codeql %} {% data variables.product.prodname_code_scanning %}, you can select a specific group of {% data variables.product.prodname_codeql %} queries, called a {% data variables.product.prodname_codeql %} query suite, to run against your code. The following built-in query suites are available through {% data variables.product.prodname_dotcom %}:

  • the default query suite.
  • the security-extended query suite.

Currently, both the default query suite and the security-extended query suite are available for default setup for {% data variables.product.prodname_code_scanning %}. For more information on default setup, see "AUTOTITLE."

To use a custom query suite, you must configure advanced setup for {% data variables.product.prodname_codeql %} {% data variables.product.prodname_code_scanning %}. For more information on advanced setups and creating a query suite, see "AUTOTITLE" and "AUTOTITLE."

Built-in {% data variables.product.prodname_codeql %} query suites

The built-in {% data variables.product.prodname_codeql %} query suites, default and security-extended, are created and maintained by {% data variables.product.prodname_dotcom %}. Both of these query suites are available for every {% data variables.product.prodname_codeql %}-supported language. For more information on {% data variables.product.prodname_codeql %}-supported languages, see "AUTOTITLE."

default query suite

  • The default query suite is the group of queries run by default in {% data variables.product.prodname_codeql %} {% data variables.product.prodname_code_scanning %} on {% data variables.product.prodname_dotcom %}.
  • The queries in the default query suite are highly precise and return few false positive {% data variables.product.prodname_code_scanning %} results. Relative to the security-extended query suite, the default suite returns fewer low-confidence {% data variables.product.prodname_code_scanning %} results.
  • This query suite is available for use with default setup for {% data variables.product.prodname_code_scanning %}.

security-extended query suite

  • The security-extended query suite consists of all the queries in the default query suite, plus additional queries with slightly lower precision and severity.
  • Relative to the default query suite, the security-extended suite may return a greater number of false positive {% data variables.product.prodname_code_scanning %} results.
  • This query suite is available for use with default setup for {% data variables.product.prodname_code_scanning %}.

Further reading