Problem
This public source repository has GitHub native secret scanning, push protection, dependency alerts, and protected-default-branch controls, but CodeQL code scanning is not configured. The repository contains JavaScript, which is supported by the current CodeQL release.
Scope
Enable GitHub's managed Default setup only. Use GitHub-hosted standard runners; do not configure self-hosted or larger runners, do not add secrets, and do not change repository visibility, source history, or release workflows.
Acceptance criteria
Safety boundary
A zero-step billing/runner failure is not a passing scan. Do not add private credentials or access private repositories from code scanning.
Problem
This public source repository has GitHub native secret scanning, push protection, dependency alerts, and protected-default-branch controls, but CodeQL code scanning is not configured. The repository contains JavaScript, which is supported by the current CodeQL release.
Scope
Enable GitHub's managed Default setup only. Use GitHub-hosted standard runners; do not configure self-hosted or larger runners, do not add secrets, and do not change repository visibility, source history, or release workflows.
Acceptance criteria
Safety boundary
A zero-step billing/runner failure is not a passing scan. Do not add private credentials or access private repositories from code scanning.