Skip to main content

Esta versão do GitHub Enterprise Server será descontinuada em 2026-03-17. Nenhum lançamento de patch será feito, mesmo para questões críticas de segurança. Para obter melhor desempenho, segurança aprimorada e novos recursos, atualize para a última versão do GitHub Enterprise Server. Para obter ajuda com a atualização, entre em contato com o suporte do GitHub Enterprise.

CodeQL pull request alert metrics

Understand CodeQL's performance in pull requests across your organizations.

Quem pode usar esse recurso?

O acesso requer:

  • Exibições da organização: acesso para gravação a repositórios na organização
  • Exibições corporativas: proprietários da organização e gerentes de segurança

Organizações pertencentes a uma conta do GitHub Team com o GitHub Advanced Security, ou pertencentes a uma conta do GitHub Enterprise com GitHub Advanced Security

Neste artigo

Overview

The metrics overview for CodeQL pull request alerts on security overview helps you understand how well CodeQL is preventing vulnerabilities in pull requests in your organization or across organizations in your enterprise. You can view the entire dataset or filter for specific criteria, making it easy to identify repositories where you may need to take action to find and reduce security risks.

Available metrics

The overview shows you a summary of how many vulnerabilities prevented by CodeQL have been caught in pull requests. The metrics are only tracked for pull requests that have been merged into the default branches of repositories in your organizations.

You can also find more granular metrics, such as how many alerts were fixed, how many were unresolved and merged, and how many were dismissed as false positive or risk accepted.

You can also view:

  • The rules that are causing the most alerts, and how many alerts each rule is associated with.

  • The number of alerts that were merged into the default branch without resolution, and the number of alerts dismissed as an acceptable risk.

Observação

Metrics for Copilot Autofix are omitted because Copilot Autofix is available only on GitHub cloud platforms.

Visibility

You can see code scanning metrics for a repository if you have:

  • The admin role for the repository
  • A custom repository role with the "View code scanning alerts" fine-grained permissions for the repository
  • Access to alerts for the repository

Next steps

To find your pull request alert metrics, see Visualizar métricas para alertas de pull request.