CuraDevOps

Plan active

GitHub code scanning default setup now supports custom CodeQL config at scale

2026-08-06 12:51 UTC · GitHub Changelog · read the source ↗ #github-actions#code-scanning#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Plan: If your org uses GitHub code scanning default setup, evaluate adopting the new github-codeql-config-file repository property to standardize CodeQL scan behavior across repos without per-repo overrides.
  • Leader — Plan: This enables centralized enforcement of code scanning standards across the org’s repositories — worth incorporating into the golden path or security policy for teams already on GitHub Advanced Security.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.