Skip to content

Pull requests: github/codeql

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Fix/path injection read subkind documentation Java
#21741 opened Apr 21, 2026 by MarkLee131 Contributor Loading… updated Apr 30, 2026
5 tasks done
docs: Add 'Customizing library models for Rust' documentation documentation ready-for-doc-review This PR requires and is ready for review from the GitHub docs team.
#21727 opened Apr 17, 2026 by coadaflorin Contributor Loading… updated Apr 29, 2026
Actions: Add experimental prompt injection queries for CWE 1427 Actions Analysis of GitHub Actions documentation
#21675 opened Apr 9, 2026 by data-douser Contributor Draft updated Apr 23, 2026
Actions: Add experimental queries for AI output validation CWE 1426 Actions Analysis of GitHub Actions documentation
#21678 opened Apr 9, 2026 by data-douser Contributor Draft updated Apr 23, 2026
Just: introduce common "verbs" Actions Analysis of GitHub Actions C# C++ documentation Go Java JS Kotlin Python Ruby Rust Pull requests that update Rust code Swift
#19978 opened Jul 4, 2025 by redsun82 Contributor Loading… updated Apr 15, 2026
Add docs comment about deduplicating query rows documentation
#21693 opened Apr 10, 2026 by k4lizen Loading… updated Apr 10, 2026
Actions: Add workflow_dispatch and workflow_call input sources for code injection Actions Analysis of GitHub Actions documentation
#21660 opened Apr 6, 2026 by tspascoal Contributor Loading… updated Apr 7, 2026
Rust: Add AlertSuppression.ql for inline suppression comments documentation Rust Pull requests that update Rust code
#21638 opened Apr 2, 2026 by cnuss Loading… updated Apr 7, 2026
5 tasks done
Actions: Add four experimental queries Actions Analysis of GitHub Actions documentation
#21624 opened Mar 31, 2026 by JamieMagee Loading… updated Apr 2, 2026
Actions: Add new query actions/code-injection/low for code injection with step outputs Actions Analysis of GitHub Actions documentation
#20974 opened Dec 5, 2025 by owen-mc Contributor Loading… updated Mar 30, 2026
Actions: Removed a false positive injection sink model for theveracode/veracode-sca action. Actions Analysis of GitHub Actions documentation
#21604 opened Mar 27, 2026 by XinyuZhangXvX Loading… updated Mar 27, 2026
Actions: Add taint summary for suisei-cn/actions-download-file url input Actions Analysis of GitHub Actions documentation
#21600 opened Mar 27, 2026 by XinyuZhangXvX Loading… updated Mar 27, 2026
Qlucie trigger documentation
#21524 opened Mar 20, 2026 by sam-robson Loading… updated Mar 20, 2026
Actions: improve improper access control query Actions Analysis of GitHub Actions documentation
#20904 opened Nov 25, 2025 by redsun82 Contributor Loading… updated Mar 3, 2026
Actions: Update reference link Actions Analysis of GitHub Actions documentation
#21295 opened Feb 8, 2026 by thatrobotdev Loading… updated Feb 8, 2026
JS: Only exclude JS files in the tsconfig outDir documentation JS
#21121 opened Jan 8, 2026 by asgerf Contributor Draft updated Jan 19, 2026
Rust: Exclude self parameter accesses from rust/access-after-lifetime-ended documentation Rust Pull requests that update Rust code
#21155 opened Jan 12, 2026 by geoffw0 Contributor Loading… updated Jan 16, 2026
3 tasks done
Bump the go_modules group across 2 directories with 3 updates dependencies Pull requests that update a dependency file documentation Go
#20608 opened Oct 9, 2025 by dependabot Bot Loading… updated Nov 25, 2025
Rust: Improve models for conversions documentation Rust Pull requests that update Rust code
#20875 opened Nov 19, 2025 by geoffw0 Contributor Draft updated Nov 24, 2025
1 of 4 tasks
C#: Overlay annotations. C# documentation
#20756 opened Nov 4, 2025 by michaelnebel Contributor Draft updated Nov 4, 2025
Crypto: Add BouncyCastle signatures and block cipher modes documentation Java
#20575 opened Oct 2, 2025 by nicolaswill Contributor Loading… updated Oct 2, 2025
Python: Refine the location of flask.request flow sources documentation Python
#20281 opened Aug 25, 2025 by tausbn Contributor Draft updated Sep 24, 2025
JS: Module system refactoring documentation JS
#20414 opened Sep 11, 2025 by asgerf Contributor Draft updated Sep 22, 2025
JS: Deprecate getAnExportedSymbol() and remove DubiousImport.ql documentation JS
#20412 opened Sep 11, 2025 by asgerf Contributor Draft updated Sep 11, 2025
C#: Insecure Certificate Validation. C# documentation
#17603 opened Sep 27, 2024 by michaelnebel Contributor Draft updated Jul 17, 2025
ProTip! Adding no:label will show everything without a label.