Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable scans and notifications by default #16348

Open
mcandre opened this issue Apr 26, 2024 · 1 comment
Open

Enable scans and notifications by default #16348

mcandre opened this issue Apr 26, 2024 · 1 comment
Labels
question Further information is requested

Comments

@mcandre
Copy link

mcandre commented Apr 26, 2024

Please enable CodeQL SAST scans and notifications by default on all GitHub repositories, like Dependabot. There are millions of projects with vulnerabilities that the owners and downstream users are unaware of. Let's try harder to keep the Internet safe.

@mcandre mcandre added the question Further information is requested label Apr 26, 2024
@turbo
Copy link
Member

turbo commented May 3, 2024

Hi Andrew,

Thank you for your question. It is indeed a request we often get, and something we're definitely interested in long-term, but don't have any immediate plans for. The main reason is that we want developers to have the best experience possible, and there are several things we're actively addressing that can potentially enable an opt-out configuration in the future, but we're not quite there yet. Some of those include: setup (and build configuration where needed), alert level configuration (Default vs. Extended), and performance (both in terms of waiting time at the PR and investment in Actions for GitHub).

Should we decide to implement this at some point in the future, there will be a corresponding item on our public roadmap some time before it is implemented.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants