├── Dockerfile.example ├── GHAS-on-GHES-feature-matrix.md ├── README.md ├── advanced-security-material.md ├── advanced-security └── training-agenda.md ├── code-scanning-guides ├── integrations │ └── code-scanning-third-party-integrations.md ├── sandwich-tracing.md ├── setup-codeql-cli.md ├── synthetic-applications │ ├── README.md │ ├── juice-shop.md │ ├── juice-shop.yml │ ├── owasp-webgoat.md │ └── owasp-webgoat.yml └── uploading-pr-analysis.md ├── code-scanning-scripts ├── README.md ├── combine-n-databases.sh ├── get-languages.sh └── run-pr-codeql-analysis.sh ├── code-scanning-workflows ├── azure-pipeline-00.yml └── reusable_code_scanning-00.yml ├── codeql ├── JSP-scanning.md ├── ast-graph-generation.md └── uniform-setup-for-cli-and-vs-code.md ├── reporting ├── advanced-security-reporting.md ├── ghes-mysql-connect.md └── issues_csv │ ├── README.md │ ├── code_scanning.jq │ ├── dependabot.jq │ ├── reporting.ps1 │ └── secret_scanning.jq ├── secret-scanning ├── secret-scanning-rollout-guidance.md └── user-defined-patterns-considerations.md └── troubleshooting ├── codeql-builds ├── bazel.md ├── compiled-languages-cpp.md ├── compiled-languages-csharp.md ├── compiled-languages-go.md ├── compiled-languages-java.md ├── compiled-languages-swift.md ├── compiled-languages.md ├── interpreted-languages-javascript.md ├── interpreted-languages-python.md └── interpreted-languages.md ├── dependabot └── failed-codeql-analysis.md └── sarif-upload └── troubleshooting.md /Dockerfile.example: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/Dockerfile.example -------------------------------------------------------------------------------- /GHAS-on-GHES-feature-matrix.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/GHAS-on-GHES-feature-matrix.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/README.md -------------------------------------------------------------------------------- /advanced-security-material.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/advanced-security-material.md -------------------------------------------------------------------------------- /advanced-security/training-agenda.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/advanced-security/training-agenda.md -------------------------------------------------------------------------------- /code-scanning-guides/integrations/code-scanning-third-party-integrations.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/integrations/code-scanning-third-party-integrations.md -------------------------------------------------------------------------------- /code-scanning-guides/sandwich-tracing.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/sandwich-tracing.md -------------------------------------------------------------------------------- /code-scanning-guides/setup-codeql-cli.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/setup-codeql-cli.md -------------------------------------------------------------------------------- /code-scanning-guides/synthetic-applications/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/synthetic-applications/README.md -------------------------------------------------------------------------------- /code-scanning-guides/synthetic-applications/juice-shop.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/synthetic-applications/juice-shop.md -------------------------------------------------------------------------------- /code-scanning-guides/synthetic-applications/juice-shop.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/synthetic-applications/juice-shop.yml -------------------------------------------------------------------------------- /code-scanning-guides/synthetic-applications/owasp-webgoat.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/synthetic-applications/owasp-webgoat.md -------------------------------------------------------------------------------- /code-scanning-guides/synthetic-applications/owasp-webgoat.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/synthetic-applications/owasp-webgoat.yml -------------------------------------------------------------------------------- /code-scanning-guides/uploading-pr-analysis.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-guides/uploading-pr-analysis.md -------------------------------------------------------------------------------- /code-scanning-scripts/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-scripts/README.md -------------------------------------------------------------------------------- /code-scanning-scripts/combine-n-databases.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-scripts/combine-n-databases.sh -------------------------------------------------------------------------------- /code-scanning-scripts/get-languages.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-scripts/get-languages.sh -------------------------------------------------------------------------------- /code-scanning-scripts/run-pr-codeql-analysis.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-scripts/run-pr-codeql-analysis.sh -------------------------------------------------------------------------------- /code-scanning-workflows/azure-pipeline-00.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-workflows/azure-pipeline-00.yml -------------------------------------------------------------------------------- /code-scanning-workflows/reusable_code_scanning-00.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/code-scanning-workflows/reusable_code_scanning-00.yml -------------------------------------------------------------------------------- /codeql/JSP-scanning.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/codeql/JSP-scanning.md -------------------------------------------------------------------------------- /codeql/ast-graph-generation.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/codeql/ast-graph-generation.md -------------------------------------------------------------------------------- /codeql/uniform-setup-for-cli-and-vs-code.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/codeql/uniform-setup-for-cli-and-vs-code.md -------------------------------------------------------------------------------- /reporting/advanced-security-reporting.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/advanced-security-reporting.md -------------------------------------------------------------------------------- /reporting/ghes-mysql-connect.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/ghes-mysql-connect.md -------------------------------------------------------------------------------- /reporting/issues_csv/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/issues_csv/README.md -------------------------------------------------------------------------------- /reporting/issues_csv/code_scanning.jq: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/issues_csv/code_scanning.jq -------------------------------------------------------------------------------- /reporting/issues_csv/dependabot.jq: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/issues_csv/dependabot.jq -------------------------------------------------------------------------------- /reporting/issues_csv/reporting.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/issues_csv/reporting.ps1 -------------------------------------------------------------------------------- /reporting/issues_csv/secret_scanning.jq: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/reporting/issues_csv/secret_scanning.jq -------------------------------------------------------------------------------- /secret-scanning/secret-scanning-rollout-guidance.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/secret-scanning/secret-scanning-rollout-guidance.md -------------------------------------------------------------------------------- /secret-scanning/user-defined-patterns-considerations.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/secret-scanning/user-defined-patterns-considerations.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/bazel.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/bazel.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages-cpp.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages-cpp.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages-csharp.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages-csharp.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages-go.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages-go.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages-java.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages-java.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages-swift.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages-swift.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/compiled-languages.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/compiled-languages.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/interpreted-languages-javascript.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/interpreted-languages-javascript.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/interpreted-languages-python.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/interpreted-languages-python.md -------------------------------------------------------------------------------- /troubleshooting/codeql-builds/interpreted-languages.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/codeql-builds/interpreted-languages.md -------------------------------------------------------------------------------- /troubleshooting/dependabot/failed-codeql-analysis.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/dependabot/failed-codeql-analysis.md -------------------------------------------------------------------------------- /troubleshooting/sarif-upload/troubleshooting.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/advanced-security/advanced-security-material/HEAD/troubleshooting/sarif-upload/troubleshooting.md --------------------------------------------------------------------------------