-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Python: Model remote flow sources for the
websockets library
documentation
Python
#20945
opened Dec 1, 2025 by
joefarebrother
Loading…
Rust: Add barriers for Pull requests that update Rust code
rust/access-invalid-pointer
Rust
#20941
opened Dec 1, 2025 by
paldepind
Loading…
Rust: Add heuristic sinks for passwords, initialization vectors etc
documentation
Rust
Pull requests that update Rust code
#20939
opened Dec 1, 2025 by
geoffw0
Loading…
JS: Add use cache directives from Next.js 16
documentation
JS
#20938
opened Nov 29, 2025 by
tesseractjh
Loading…
Actions: fix filtering of code injection results between medium and critical version of query
Actions
Analysis of GitHub Actions
documentation
#20937
opened Nov 28, 2025 by
owen-mc
Loading…
C#: Gracefully handle
dotnet --info exit code 143.
C#
#20936
opened Nov 28, 2025 by
michaelnebel
•
Draft
C#: Invoke the extractor after the compiler to ensure that source generators have been executed.
C#
#20933
opened Nov 28, 2025 by
michaelnebel
•
Draft
Java: add more Spring RestTemplate request forgery sinks
documentation
Java
#20930
opened Nov 28, 2025 by
owen-mc
Loading…
C#: Replace initializer splitting with an ObjectInitMethod.
C#
#20922
opened Nov 26, 2025 by
aschackmull
•
Draft
Python: detecting header splitting in synthetic app
documentation
Python
#20919
opened Nov 26, 2025 by
yoff
Loading…
JS: Handle default 'content-type' header in Response() objects
documentation
JS
#20918
opened Nov 26, 2025 by
asgerf
Loading…
Go: enable data flow consistency checks
DataFlow Library
documentation
Go
#20917
opened Nov 26, 2025 by
owen-mc
Loading…
JS: Handle Next.js files named 'page' or 'route'
documentation
JS
#20916
opened Nov 26, 2025 by
asgerf
Loading…
Shared: Improvements to content-sensitive model generation
DataFlow Library
Rust
Pull requests that update Rust code
Python: Add models for socketio
documentation
Python
#20914
opened Nov 25, 2025 by
joefarebrother
Loading…
Treat zap custom encoders as sanitizers for log-injection checks
Go
#20912
opened Nov 25, 2025 by
danielriddell21
•
Draft
Actions: improve improper access control query
Actions
Analysis of GitHub Actions
documentation
#20904
opened Nov 25, 2025 by
redsun82
Loading…
Rust: Jump-to-def for operations and indexing
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
#20900
opened Nov 24, 2025 by
hvitved
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.