Skip to main content

Tracking code scanning alerts in issues using task lists

You can add code scanning alerts to issues using task lists. This makes it easy to create a plan for development work that includes fixing alerts.

Who can use this feature

If you have write permission to a repository you can track code scanning alerts in issues using task lists.

Code scanning は、GitHub.com のすべてのパブリック リポジトリに使用できます。 Organization によって所有されるプライベート リポジトリで code scanning を使うには、GitHub Advanced Security のライセンスが必要です。 詳細については、「GitHub Advanced Security について」を参照してください。

注: Issue の code scanning アラートの追跡はベータ版であり、変更される可能性があります。

この機能では、GitHub Actions を使用してネイティブで、または既存の CI/CD インフラストラクチャを使用して外部で分析を実行すること、およびサードパーティの code scanning ツールがサポートされていますが、サードパーティの追跡ツールはサポート されていません

About tracking code scanning alerts in issues

Code scanning アラートは GitHub Issues のタスク リストと統合されており、すべての開発タスクで簡単にアラートに優先順位を付け、追跡することができます。 issue の詳細については、「Issue について」を参照してください。

issue のコード スキャン アラートを追跡するには、issue のタスク リスト項目としてアラートの URL を追加します。 タスク リストの詳細については、「タスク リストについて」を参照してください。

You can also create a new issue to track an alert:

  • From a code scanning alert, which automatically adds the code scanning alert to a task list in the new issue. For more information, see "Creating a tracking issue from a code scanning alert" below.

  • Via the API as you normally would, and then provide the code scanning link within the body of the issue. You must use the task list syntax to create the tracked relationship:

    • - [ ] <full-URL- to-the-code-scanning-alert>
    • For example, if you add - [ ] https://github.com/octocat-org/octocat-repo/security/code-scanning/17 to an issue, the issue will track the code scanning alert that has an ID number of 17 in the "Security" tab of the octocat-repo repository in the octocat-org organization.

You can use more than one issue to track the same code scanning alert, and issues can belong to different repositories from the repository where the code scanning alert was found.

GitHub Enterprise Cloud provides visual cues in different locations of the user interface to indicate when you are tracking code scanning alerts in issues.

  • The code scanning alerts list page will show which alerts are tracked in issues so that you can view at a glance which alerts still require processing.

    Tracked in pill on code scanning alert page

  • A "tracked in" section will also show in the corresponding alert page.

    Tracked in section on code scanning alert page

  • On the tracking issue, GitHub displays a security badge icon in the task list and on the hovercard.

    Only users with write permissions to the repository will see the unfurled URL to the alert in the issue, as well as the hovercard. For users with read permissions to the repository, or no permissions at all, the alert will appear as a plain URL.

    The color of the icon is grey because an alert has a status of "open" or "closed" on every branch. The issue tracks an alert, so the alert cannot have a single open/closed state in the issue. If the alert is closed on one branch, the icon color will not change.

    Hovercard in tracking issue

The status of the tracked alert won't change if you change the checkbox state of the corresponding task list item (checked/unchecked) in the issue.

Creating a tracking issue from a code scanning alert

  1. On GitHub.com, navigate to the main page of the repository.

  2. リポジトリ名の下にある [ セキュリティ] をクリックします。 [セキュリティ] タブ

  3. 左側のサイドバーの [Code scanning alerts](コード スキャンのアラート) をクリックします。 [Code scanning alerts](コード スキャンのアラート) タブ

  4. Towards the top of the page, on the right side, click Create issue.

    Create a tracking issue for the code scanning alert

    GitHub automatically creates an issue to track the alert and adds the alert as a task list item. GitHub prepopulates the issue:

    • The title contains the name of the code scanning alert.
    • The body contains the task list item with the full URL to the code scanning alert.
  5. Optionally, edit the title and the body of the issue.

    Warning: You may want to edit the title of the issue as it may expose security information. You can also edit the body of the issue, but do not edit the task list item or the issue will no longer track the alert.

    New tracking issue for the code scanning alert

  6. Click Submit new issue.