-
Notifications
You must be signed in to change notification settings - Fork 2k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Javascript: Regex Global Flag in Test Function
documentation
external-contribution
JS
#15163
opened Dec 19, 2023 by
aydinnyunus
Contributor
•
Draft
C#: New query for detecting Command Injection bugs in console applications (Local sources)
C#
documentation
#13551
opened Jun 24, 2023 by
cldrn
Contributor
Loading…
JS: Web Cache Deception Express
documentation
external-contribution
JS
#15180
opened Dec 20, 2023 by
aydinnyunus
Contributor
•
Draft
Actions: improve improper access control query
Actions
Analysis of GitHub Actions
documentation
#20904
opened Nov 25, 2025 by
redsun82
Contributor
Loading…
Rust: Exclude self parameter accesses from rust/access-after-lifetime-ended
documentation
Rust
Pull requests that update Rust code
#21155
opened Jan 12, 2026 by
geoffw0
Contributor
Loading…
3 tasks done
Java: Check whether there are internal files in the App that can be read and written by any other App
documentation
Java
#11016
opened Oct 27, 2022 by
kangr0
Loading…
Java: Deprecate
PrimitiveType.getADefaultValue()
documentation
Java
#6796
opened Oct 2, 2021 by
Marcono1234
Contributor
Loading…
[Java]: Best Practice InterruptedException handling
documentation
Java
#8469
opened Mar 16, 2022 by
JLLeitschuh
Contributor
Loading…
actions: Add some missing permissions
Actions
Analysis of GitHub Actions
documentation
#19357
opened Apr 23, 2025 by
yoff
Contributor
Loading…
Handling of axios in functions and making axios create function recur…
documentation
JS
#19337
opened Apr 19, 2025 by
rotem-cider
Loading…
Test: Simple change to Java folder
documentation
Java
WIP
This is a work-in-progress, do not merge yet!
#4248
opened Sep 10, 2020 by
adityasharad
Collaborator
•
Draft
Java: Timing attack
documentation
Java
#8686
opened Apr 7, 2022 by
ahmed-farid-dev
Contributor
Loading…
Go: Improve diagnostics when no packages are extracted
documentation
Go
#17674
opened Oct 7, 2024 by
mbg
Member
Loading…
Java: Fix
ClassInstanceExpr::isDiamond not working for anonymous classes
documentation
Java
#15429
opened Jan 24, 2024 by
Marcono1234
Contributor
Loading…
Rust: Add AlertSuppression.ql for inline suppression comments
documentation
Rust
Pull requests that update Rust code
#21638
opened Apr 2, 2026 by
cnuss
Loading…
5 tasks done
Actions: Removed a false positive injection sink model for theAnalysis of GitHub Actions
documentation
veracode/veracode-sca action.
Actions
#21604
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
Add Microsoft to trusted actions owner
Actions
Analysis of GitHub Actions
documentation
#19450
opened May 1, 2025 by
felickz
Contributor
Loading…
Java: Introduce Freemarker for SSTI queries
documentation
Java
#6320
opened Jul 18, 2021 by
japroc
Contributor
Loading…
ProTip!
no:milestone will show everything without a milestone.