CodeQL: Stub
Actively maintainedgithub/codeql-action · MIT
Actions for running CodeQL analysis
★ 1.6k starsLast commit yesterdayLatest v4.37.4
C
65
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentNo
Immutable releasesEnabled
Known vulnerabilities1 advisory(ies)
- CVE-2025-24362high
GitHub PAT written to debug artifacts
Published Jan 24, 2025
How to use it safely
Recommended: pin to commit SHA
uses: github/codeql-action@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4Mutable tags like v4.37.4 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: github/codeql-action@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
Score breakdown
Security (35%)40
Popularity (20%)67
Maintenance (30%)100
Reliability (15%)50