-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Treat zap custom encoders as sanitizers for log-injection checks
Go
#20912
opened Nov 25, 2025 by
danielriddell21
•
Draft
JS: Fix project layout detection for Next.js apps
documentation
JS
#20911
opened Nov 25, 2025 by
asgerf
Loading…
C/C++ overlay: Add basic This PR should only be merged in sync with an internal Semmle PR
no-change-note-required
This PR does not need a change note
Overlay.qll file
C++
depends on internal PR
#20909
opened Nov 25, 2025 by
IdrissRio
Loading…
Fix KeyError: 'name' in python/extractor/imp.py on Python 3.14
Python
#20908
opened Nov 25, 2025 by
akoeplinger
Loading…
Rust: Add predicates for fieldless and unit-only enums
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
#20906
opened Nov 25, 2025 by
paldepind
Loading…
Actions: improve improper access control query
Actions
Analysis of GitHub Actions
documentation
#20904
opened Nov 25, 2025 by
redsun82
Loading…
Rust: Add new query for XSS vulnerabilities
documentation
ready-for-doc-review
This PR requires and is ready for review from the GitHub docs team.
Rust
Pull requests that update Rust code
#20902
opened Nov 24, 2025 by
paldepind
Loading…
Rust: Jump-to-def for operations and indexing
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
#20900
opened Nov 24, 2025 by
hvitved
Loading…
C++: Ignore non-type template parameters when matching signatures in MaD
C++
no-change-note-required
This PR does not need a change note
#20899
opened Nov 24, 2025 by
MathiasVP
Loading…
Rust: Improve handling of implicit derefs/borrows in data flow
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
Add ECB and CBC block mode test cases for BrokenCryptoAlgorithm query
Rust
Pull requests that update Rust code
#20887
opened Nov 21, 2025 by
Copilot
AI
Loading…
JS: Split module exports into a local and global variant
JS
no-change-note-required
This PR does not need a change note
#20885
opened Nov 21, 2025 by
asgerf
Loading…
Rust: Lift content reads as taint steps
Rust
Pull requests that update Rust code
#20879
opened Nov 20, 2025 by
paldepind
Loading…
Python: Add models for websocket handlers for Tornado
documentation
Python
#20877
opened Nov 20, 2025 by
joefarebrother
Loading…
Java: Add support for data flow through thrown exceptions.
Java
#20867
opened Nov 19, 2025 by
aschackmull
•
Draft
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.