Notifications
Clear all
GitHub Advanced Security Reviews
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
20/07/2026 11:41 am
We pushed CodeQL to 20 repos last quarter. It broke our CI builds immediately. False positives everywhere, scan times through the roof, and a couple of real issues buried in the noise.
Had to roll back and start over. Key fixes: tuned the query suites to security-only, set up custom configs for our legacy frameworks, and excluded auto-generated code. Scans are now under 10 minutes and we actually look at the alerts. Still not cheap, but at least it's working.