-
Notifications
You must be signed in to change notification settings - Fork 2k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Python: Remove imprecise container steps
Awaiting evaluation
Do not merge yet, this PR is waiting for an evaluation to finish
Python
Shared: Make UniversalFlow overlay-aware.
C++
Java
#20884
opened Nov 21, 2025 by
aschackmull
Contributor
•
Draft
JavaScript: Add setHTMLUnsafe and parseHTMLUnsafe as XSS sinks
JS
#21648
opened Apr 3, 2026 by
sunnyeo
Loading…
C#: Make NuGet feed reachability more conservative,
C#
#20836
opened Nov 14, 2025 by
michaelnebel
Contributor
•
Draft
Crypto: Alert fatigue remediation (legacy queries)
C++
Python
#20566
opened Oct 1, 2025 by
unprovable
Contributor
Loading…
ruby: test
rb/uninitialized-local-variable
Ruby
#19247
opened Apr 8, 2025 by
yoff
Contributor
Loading…
Avoid inconsistent implicit This PR does not need a change note
toString on potential string subtypes
DataFlow Library
no-change-note-required
#21318
opened Feb 12, 2026 by
ginsbach
Contributor
Loading…
Rust: Add AlertSuppression.ql for inline suppression comments
documentation
Rust
Pull requests that update Rust code
#21638
opened Apr 2, 2026 by
cnuss
Loading…
5 tasks done
Java: Add test showing missing dispatch for incomplete parameterised type
Java
no-change-note-required
This PR does not need a change note
#19543
opened May 20, 2025 by
aschackmull
Contributor
Loading…
Update supported language codes
documentation
#10480
opened Sep 19, 2022 by
rvermeulen
Contributor
Loading…
Go: Remove toolchain directive from This PR does not need a change note
go/extractor/go.mod
Go
no-change-note-required
#21307
opened Feb 11, 2026 by
owen-mc
Contributor
Loading…
C#: Make a more principled fix in ConstantCondition.
C#
no-change-note-required
This PR does not need a change note
#21272
opened Feb 5, 2026 by
aschackmull
Contributor
•
Draft
Bump buildifier_prebuilt from 6.4.0 to 8.5.1.2
bazel
Pull requests that update bazel code
dependencies
Pull requests that update a dependency file
#21676
opened Apr 9, 2026 by
dependabot
Bot
Loading…
Bump rules_shell from 0.7.1 to 0.8.0
bazel
Pull requests that update bazel code
dependencies
Pull requests that update a dependency file
#21716
opened Apr 16, 2026 by
dependabot
Bot
Loading…
Actions: Removed a false positive injection sink model for theAnalysis of GitHub Actions
documentation
veracode/veracode-sca action.
Actions
#21604
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
Add
client-response Threat Model and update JS ClientsRequests
documentation
JS
#19656
opened Jun 3, 2025 by
GeekMasher
Contributor
Loading…
Python: Initial version of the Model Generator Lib and Queries
Python
#19131
opened Mar 27, 2025 by
GeekMasher
Contributor
Loading…
Previous Next
ProTip!
Updated in the last three days: updated:>2026-04-27.