> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/codeql-scanner-reference.md).

# CodeQL step configuration

You can ingest scan results from [CodeQL](https://codeql.github.com/) into Harness STO. The following steps outline the basic workflow:

{% hint style="info" %}
The **CodeQL** step supports only **Ingestion** scan mode, refer to [GitHub Advanced Security step documentation](/security-testing-orchestration/use-sto/sto-scanner-configuration/github-advanced-security.md) for **Orchestration** and other GHAS tools such as **Dependabot**, **Secret Scanning**.
{% endhint %}

1. Run a CodeQL scan, either externally or as part of a Run step, and publish the results to SARIF.
2. Add the SARIF data to your pipeline. If you ran the scan outside the pipeline, do the following:
   1. In the stage where you ingest the results, go to **Overview** > **Shared Paths** and create a folder under `/shared` such as `/shared/scan_results`.
   2. Use a Run step to add your scan results to the shared folder.
3. Use a [CodeQL](#codeql-step-configuration) step to ingest the results.

This topic includes an [end-to-end YAML pipeline](#yaml-pipeline-example) that illustrates this workflow.

### Important notes for running CodeQL scans in STO <a href="#important-notes-for-running-codeql-scans-in-sto" id="important-notes-for-running-codeql-scans-in-sto"></a>

#### Root access requirements <a href="#root-access-requirements" id="root-access-requirements"></a>

#### For more information <a href="#for-more-information" id="for-more-information"></a>

### CodeQL step settings for STO scans <a href="#codeql-step-settings-for-sto-scans" id="codeql-step-settings-for-sto-scans"></a>

The recommended workflow is to add a CodeQL step to a Security or Build stage and then configure it as described below.

#### Scan <a href="#scan" id="scan"></a>

#### Scan mode <a href="#scan-mode" id="scan-mode"></a>

**Scan configuration**

#### Target <a href="#target" id="target"></a>

**Type**

**Target and Variant Detection**

**Name**

**Variant**

#### Ingestion file <a href="#ingestion-file" id="ingestion-file"></a>

#### Log Level <a href="#log-level" id="log-level"></a>

#### Additional CLI flags <a href="#additional-cli-flags" id="additional-cli-flags"></a>

Use this field to run the [CodeQL scanner binary](https://codeql.github.com/docs/) with additional flags.

#### Fail on Severity <a href="#fail-on-severity" id="fail-on-severity"></a>

#### Settings <a href="#settings" id="settings"></a>

#### Additional Configuration <a href="#additional-configuration" id="additional-configuration"></a>

#### Advanced settings <a href="#advanced-settings" id="advanced-settings"></a>

### CodeQL pipeline example <a href="#codeql-pipeline-example" id="codeql-pipeline-example"></a>

The following pipeline illustrates a simple ingestion scan. It consists of two steps. A Run step generates an example CodeQL data file in SARIF format. A CodeQL step then ingests the data.

```yaml

pipeline:
  projectIdentifier: STO
  orgIdentifier: default
  tags: {}
  stages:
    - stage:
        name: ingestion
        identifier: ingestion
        type: SecurityTests
        spec:
          cloneCodebase: false
          infrastructure:
            type: KubernetesDirect
            spec:
              connectorRef: K8S_DELEGATE_CONNECTOR
              namespace: harness-delegate-ng
              automountServiceAccountToken: true
              nodeSelector: {}
              os: Linux
          execution:
            steps:
              - step:
                  type: Run
                  name: create codeql sarif
                  identifier: create_codeql_sarif
                  spec:
                    connectorRef: CONTAINER_IMAGE_REGISTRY_CONNECTOR
                    image: alpine
                    shell: Sh
                    command: |-
                      pwd
                      echo '{
                          "$schema": "",
                          "version": "sarif-2.1.0",
                          "runs": [
                            {
                              "tool": {
                                "driver": {
                                  "name": "CodeQL",
                                  "version": "2.5.7",
                                  "semanticVersion": "2.5.7+1234567890",
                                  "informationUri": "https://github.com/github/codeql",
                                  "properties": {
                                    "analysisTarget": "myproject",
                                    "analysisTimestamp": "2023-04-03T14:00:00Z",
                                    "analysisDuration": 120000,
                                    "query": "detect-external-libs.ql",
                                    "queryUrl": "https://github.com/github/codeql/blob/master/javascript/ql/src/semmle/javascript/Security/CWE/CWE-094/ExternalLibraries.ql"
                                  }
                                }
                              },
                              "results": [
                                {
                                  "ruleId": "js/detect-external-libs",
                                  "message": {
                                    "text": "The following external libraries were found: jQuery, Lodash"
                                  },
                                  "locations": [
                                    {
                                      "physicalLocation": {
                                        "artifactLocation": {
                                          "uri": "/path/to/myproject/js/script.js"
                                        },
                                        "region": {
                                          "startLine": 10,
                                          "startColumn": 1,
                                          "endLine": 10,
                                          "endColumn": 15
                                        }
                                      }
                                    }
                                  ],
                                  "level": "warning",
                                  "properties": {
                                    "severity": "high",
                                    "confidence": "medium"
                                  }
                                }
                              ]
                            }
                          ]
                        }'> codeql.sarif
                      ls
              - step:
                  type: CodeQL
                  name: CodeQL_1
                  identifier: CodeQL_1
                  spec:
                    mode: ingestion
                    config: default
                    target:
                      name: login_microservice
                      type: repository
                      variant: my_hotfix_branch
                    advanced:
                      log:
                        level: info
                      fail_on_severity: critical
                    ingestion:
                      file: /harness/codeql.sarif
          sharedPaths:
            - /var/run
            - /shared/scan_results/
  identifier: codeql_ingestion
  name: codeql ingestion 

```
