4Configure and Use Code Security
- 4.1Code Security Approaches and Setup
Understand native (CodeQL) vs third-party code scanning, choosing between CodeQL and third-party analysis, SARIF ingestion and interoperability, and enabling via GitHub Actions or external CI with workflow templates, matrix builds, and scan frequency.
- 4.2Analyzing, Triaging, and Optimizing Results
Understand reviewing scan results (including dataflow insights), the alert lifecycle and autofix/remediation workflows, dismissing alerts and managing severity/category, and advanced configuration plus troubleshooting scan failures/performance.

