Scheduled code scanning skips inactive repositories
Summary
Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of… The post Scheduled code scanning skips inactive repositories appeared first on The GitHub Blog .
Original Text
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd"> Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of scan as recent activity.
Previously, activity for a repository was based on any unscheduled scan, including the one-time validation scan that runs when you first enable default setup and scans triggered by a change in detected languages. That meant enabling default setup or rolling out a security configuration across many repositories at once could make a dormant repository look active for another six months and trigger weekly scheduled scans you didn’t expect.
The current behavior is as follows:
Enabling default setup still runs an initial validation scan and populates findings right away.
Weekly scheduled scanning only begins once a push or pull request triggers an analysis.
This determination is based on analysis history, not on Git activity from before scanning was enabled.
Activity continues to be shared between code scanning and Code Quality.
If you manage code scanning or Code Quality across many repositories, you should see fewer unexpected weekly scans on repositories that haven’t had recent development activity. This makes scanning behavior more predictable when you apply security configurations at scale. No configuration change is needed on your part.
This applies to GitHub Enterprise Cloud today and will be supported in GitHub Enterprise Server 3.24. Learn more about configuring default setup for code scanning.
The post Scheduled code scanning skips inactive repositories appeared first on The GitHub Blog.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.