-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Merge pull request #5747 from rdmarsh2/rdmarsh2/cpp/deprecate-return-stack-allocated-object
#5750
opened Apr 22, 2021 by
huzaifanabeel
Loading…
JS: Exclude patched libraries from
xml-bomb
sink
documentation
JS
Python
#20048
opened Jul 15, 2025 by
Napalys
Loading…
Java: CWE-378: Temp Directory Hijacking Race Condition Vulnerability
documentation
Java
#4473
opened Oct 14, 2020 by
JLLeitschuh
Loading…
Ruby: Avoid a forced CP.
no-change-note-required
This PR does not need a change note
Ruby
#18927
opened Mar 4, 2025 by
alexet
Loading…
Add lodash GroupBy as taint step
JS
no-change-note-required
This PR does not need a change note
#19768
opened Jun 13, 2025 by
Vasco-jofra
Loading…
Improve data flow in the This PR does not need a change note
async
package
JS
no-change-note-required
#19770
opened Jun 15, 2025 by
Vasco-jofra
Loading…
actions: Add some missing permissions
Actions
Analysis of GitHub Actions
documentation
#19357
opened Apr 23, 2025 by
yoff
Loading…
Java: QL Query to Detect Security Sensitive non-CSPRNG usage
Java
#2694
opened Jan 24, 2020 by
JLLeitschuh
Loading…
CS: Adding DecryptWithoutHash and CertificateValidationDisabled queries
#1622
opened Jul 22, 2019 by
denislevin
Loading…
C++: Improve alias analysis for indirections
C++
#1736
opened Aug 14, 2019 by
dave-bartolomeo
•
Draft
[CPP-435] Calls to
memset
and ZeroMemory
may be deleted by the compiler
C++
#1933
opened Sep 13, 2019 by
zlaski-semmle
•
Draft
C++/C#: Remove
Instruction::getResultType()
and friends
C#
C++
#2217
opened Oct 28, 2019 by
dave-bartolomeo
Loading…
C++: Use TaintTracking::Configuration in TaintedAllocationSize
C++
depends on internal PR
This PR should only be merged in sync with an internal Semmle PR
#3519
opened May 19, 2020 by
rdmarsh2
Loading…
JS: add new query: js/unclosed-stream
Awaiting evaluation
Do not merge yet, this PR is waiting for an evaluation to finish
documentation
JS
Java: Arbitrary user-controlled read/write on user-controlled path
Java
#3794
opened Jun 24, 2020 by
intrigus-lgtm
•
Draft
Previous Next
ProTip!
What’s not been updated in a month: updated:<2025-07-14.