Files
probo/controls/application-security/source-code/APP-SRC-002_enable_code_scanning.md
gearnode 02aee195b9 Rename files
Signed-off-by: Bryan Frimin <bryan@frimin.fr>
2025-01-07 19:30:11 +01:00

33 lines
832 B
Markdown

---
id: "APP-SRC-002"
category: "application-security/source-code"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
## Purpose
It ensures that potential security flaws are detected early. This
proactive approach strengthens your security posture and helps
maintain high code quality.
## Implementation
### Github
1. Go to the "Security" tab of your repository.
2. Click on "Set up code scanning".
3. Select "Set up this workflow" under "CodeQL Analysis".
4. Review the YAML file and commit it to your repository.
Code scanning will now run every time code is pushed to the
repository, and results will appear in the Security tab.
## Evidence
- Screenshot of code scanning results from Security tab
- Sample of resolved security alerts