-- [Configure and Use Code Scanning]
After investigating a code scanning alert related to injection, you determine that the input is properly sanitized using custom logic. What should be your next step?
When you identify that a code scanning alert is a false positive---such as when your code uses a custom sanitization method not recognized by the analysis---you should dismiss the alert with the reason 'false positive.' This action helps improve the accuracy of future analyses and maintains the relevance of your security alerts.
As per GitHub's documentation:
'If you dismiss a CodeQL alert as a false positive result, for example because the code uses a sanitization library that isn't supported, consider contributing to the CodeQL repository and improving the analysis.'
By dismissing the alert appropriately, you ensure that your codebase's security alerts remain actionable and relevant.
Nelida
2 months agoJin
2 months agoPolly
2 months agoEzekiel
3 months agoOmega
3 months agoMicaela
3 months agoMing
4 months agoWai
4 months agoLavonda
4 months agoLeandro
4 months agoDaniel
4 months agoJanine
5 months agoAja
5 months agoThora
5 months agoYong
6 months agoNaomi
2 months agoKeena
2 months agoRodrigo
3 months agoElsa
3 months agoReynalda
7 months agoDalene
7 months agoNickie
7 months agoCharolette
6 months agoEladia
7 months agoLonny
7 months ago