Skip to content

Does the license allow us to generate CodeQL databases for bug hunting? #12401

Answered by tausbn
tyage asked this question in Q&A
Discussion options

You must be logged in to vote

As far as I can tell, as long as you are only analysing OSS codebases, then it's perfectly fine to use the CodeQL CLI to generate new databases (e.g. if you want to analyse a historic commit that contained a known vulnerability).

If you're using CodeQL for bug hunting, you may also want to join the GitHub Security Lab Slack instance.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@tyage
Comment options

@intrigus-lgtm
Comment options

@tyage
Comment options

Answer selected by tyage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants