Skip to content

Pull requests: github/codeql

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Java: treat hash/encrypt/digest methods as sensitive-log sanitizers documentation Java
#21654 by MarkLee131 Contributor was merged Apr 30, 2026 Loading… updated Apr 30, 2026
C#: Include parameters and their defaults in the CFG C# Java no-change-note-required This PR does not need a change note
#21759 by hvitved Contributor was merged Apr 30, 2026 Loading… updated Apr 30, 2026
Java: add RegexpCheckBarrier to trust-boundary-violation sanitizers documentation Java
#21656 by MarkLee131 Contributor was merged Apr 29, 2026 Loading… updated Apr 29, 2026
Move generated MaDs into modelgenerator/ C# C++ Java no-change-note-required This PR does not need a change note Rust Pull requests that update Rust code
#21751 by jacknojo Contributor was merged Apr 29, 2026 Loading… updated Apr 29, 2026
Post-release preparation for codeql-cli-2.25.3 Actions Analysis of GitHub Actions C# C++ DataFlow Library Go Java JS no-change-note-required This PR does not need a change note Python Ruby Rust Pull requests that update Rust code Swift
#21761 by codeql-ci Collaborator was merged Apr 27, 2026 Loading… updated Apr 27, 2026
Release preparation for version 2.25.3 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21760 by codeql-ci Collaborator was merged Apr 27, 2026 Loading… updated Apr 27, 2026
Revert "Release preparation for version 2.25.3" Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21758 by mbg Member was merged Apr 27, 2026 Loading… updated Apr 27, 2026
Add Hibernate SQL injection sink models and coverage documentation Java
#21749 by Copilot AI was merged Apr 24, 2026 Loading… updated Apr 24, 2026
C#: Move handling of callables into shared control flow library C# Java no-change-note-required This PR does not need a change note
#21743 by hvitved Contributor was merged Apr 23, 2026 Loading… updated Apr 23, 2026
Java: recognize Path.toRealPath() as path normalization sanitizer documentation Java
#21652 by MarkLee131 Contributor was merged Apr 23, 2026 Loading… updated Apr 23, 2026
C#: Replace CFG with the shared implementation C# documentation Java
#21565 by aschackmull Contributor was merged Apr 21, 2026 Loading… updated Apr 21, 2026
Document models-as-data barriers and barrier guards and add change notes C# C++ documentation Go Java JS Python ready-for-doc-review This PR requires and is ready for review from the GitHub docs team. Ruby Rust Pull requests that update Rust code
#21523 by owen-mc Contributor was merged Apr 21, 2026 Loading… updated Apr 21, 2026
Java: reduce false positives in sensitive-log documentation Java
#21650 by MarkLee131 Contributor was merged Apr 21, 2026 Loading… updated Apr 21, 2026
Post-release preparation for codeql-cli-2.25.3 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21737 by codeql-ci Collaborator was merged Apr 21, 2026 Loading… updated Apr 21, 2026
Java: fix bug in partial path traversal documentation Java
#21734 by owen-mc Contributor was merged Apr 20, 2026 Loading… updated Apr 20, 2026
Release preparation for version 2.25.3 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21736 by codeql-ci Collaborator was merged Apr 20, 2026 Loading… updated Apr 20, 2026
Java: Add XXE sink model for Woodstox WstxInputFactory documentation Java
#21718 by chmodxxx Contributor was merged Apr 17, 2026 Loading… updated Apr 17, 2026
Post-release preparation for codeql-cli-2.25.2 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21658 by codeql-ci Collaborator was merged Apr 14, 2026 Loading… updated Apr 14, 2026
Merge rc/3.20 into main Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21156 by igfoo Contributor was merged Jan 13, 2026 Loading… updated Apr 14, 2026
Shared: update code comments explaining models-as-data format to include barriers and barrier guards C# C++ DataFlow Library Go Java JS no-change-note-required This PR does not need a change note Python Ruby Rust Pull requests that update Rust code Swift
#21584 by owen-mc Contributor was merged Apr 14, 2026 Loading… updated Apr 14, 2026
Java: Accept new test results after JDK 26 extractor upgrade depends on internal PR This PR should only be merged in sync with an internal Semmle PR Java Kotlin no-change-note-required This PR does not need a change note
#21494 by IdrissRio Contributor was merged Apr 7, 2026 Loading… updated Apr 7, 2026
Release preparation for version 2.25.2 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21657 by codeql-ci Collaborator was merged Apr 6, 2026 Loading… updated Apr 6, 2026
Kotlin: update to 2.3.20 depends on internal PR This PR should only be merged in sync with an internal Semmle PR documentation Java Kotlin
#21583 by redsun82 Contributor was merged Apr 2, 2026 Loading… updated Apr 2, 2026
Post-release preparation for codeql-cli-2.25.1 Actions Analysis of GitHub Actions C# C++ DataFlow Library documentation Go Java JS Python Ruby Rust Pull requests that update Rust code Swift
#21579 by codeql-ci Collaborator was merged Mar 30, 2026 Loading… updated Mar 30, 2026
Exclude bounds-check arithmetic from tainted-arithmetic sinks documentation Java
#21608 by MarkLee131 Contributor was merged Mar 29, 2026 Loading… updated Mar 29, 2026
ProTip! What’s not been updated in a month: updated:<2026-03-30.