Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

nealfennimore/codeql-docker

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

48 Commits
 
 
 
 
 
 

Repository files navigation

Docker CodeQL

Versioned CodeQL and CodeQL CLI container.

See CodeQL CLI Manual for commands.

Installation

# Using uncompiled base
docker pull ghcr.io/nealfennimore/codeql:latest

# Using compiled language (cpp, csharp, csv, go, html, java, javascript, properties, python, xml supported)
docker pull ghcr.io/nealfennimore/codeql:javascript
docker pull ghcr.io/nealfennimore/codeql:go
docker pull ghcr.io/nealfennimore/codeql:cpp

Building Locally

If you prefer to build locally instead of using a precompiled image

docker build . \
    --build-arg CLI_VERSION=2.7.0 \
    --build-arg CODE_LANGUAGE=$CODE_LANGUAGE \
    --tag ghcr.io/nealfennimore/codeql:$CODE_LANGUAGE

Usage

Shell

To drop to shell to work with codeql directly

docker run --rm -it \
    -v ~/code/db:/tmp/db \
    -v ~/code/src:/tmp/src \
    -v ~/code/output:/tmp/output \
    ghcr.io/nealfennimore/codeql:$CODE_LANGUAGE bash

# Then proceed to create database for the language:
codeql database create --language=$CODE_LANGUAGE --source-root /tmp/src /tmp/db

# Analyze source code and generate report:
codeql database analyze /tmp/db $CODE_LANGUAGE-lgtm.qls --format=sarif-latest --output=/tmp/output/results.sarif

Database

Creation

docker run --rm -it \
    -v ~/code/db:/tmp/db \
    -v ~/code/src:/tmp/src \
    ghcr.io/nealfennimore/codeql:$CODE_LANGUAGE \
    codeql database create --language=$CODE_LANGUAGE --source-root /tmp/src /tmp/db

Analyzing Source Code

docker run --rm -it \
    -v ~/code/db:/tmp/db \
    -v ~/code/src:/tmp/src \
    -v ~/code/output:/tmp/output \
    ghcr.io/nealfennimore/codeql:$CODE_LANGUAGE \
    codeql database analyze /tmp/db $CODE_LANGUAGE-lgtm.qls \ # Analyze with default query suites
        --format=sarif-latest \
        --output=/tmp/output/results.sarif

Packages

 
 
 
Morty Proxy This is a proxified and sanitized view of the page, visit original site.