-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Actions: Add new query Analysis of GitHub Actions
documentation
actions/code-injection/low for code injection with step outputs
Actions
#20974
opened Dec 5, 2025 by
owen-mc
Loading…
Rust: Do not dispatch to all implementations when trait target is accurate
documentation
Rust
Pull requests that update Rust code
#20969
opened Dec 5, 2025 by
paldepind
Loading…
Rust: Fix FPs from rust/access-after-lifetime-ended
documentation
Rust
Pull requests that update Rust code
#20966
opened Dec 4, 2025 by
geoffw0
Loading…
C#: Fix NuGet version bug and a .NET10 compatibility issue.
C#
documentation
#20964
opened Dec 4, 2025 by
michaelnebel
Loading…
Rust: Include more calls in DB quality metrics
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
#20954
opened Dec 2, 2025 by
hvitved
Loading…
Rust: Model more data flow constructs as calls using MaD
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
#20953
opened Dec 2, 2025 by
hvitved
Loading…
Python: Model remote flow sources for the
websockets library
documentation
Python
#20945
opened Dec 1, 2025 by
joefarebrother
Loading…
Rust: Reduce the number of sinks in Pull requests that update Rust code
DereferenceSink
documentation
Rust
#20941
opened Dec 1, 2025 by
paldepind
Loading…
JS: Skip minified file if avg line length > 200
documentation
JS
#20940
opened Dec 1, 2025 by
asgerf
Loading…
JS: Add use cache directives from Next.js 16
documentation
JS
#20938
opened Nov 29, 2025 by
tesseractjh
Loading…
Java: add more Spring RestTemplate request forgery sinks
documentation
Java
#20930
opened Nov 28, 2025 by
owen-mc
Loading…
Go: fix small issues highlighted by data flow consistency checks
documentation
Go
no-change-note-required
This PR does not need a change note
#20929
opened Nov 27, 2025 by
owen-mc
Loading…
C#: Replace initializer splitting with an ObjectInitMethod.
C#
#20922
opened Nov 26, 2025 by
aschackmull
Loading…
JS: Handle default 'content-type' header in Response() objects
documentation
JS
#20918
opened Nov 26, 2025 by
asgerf
Loading…
JS: Handle Next.js files named 'page' or 'route'
documentation
JS
#20916
opened Nov 26, 2025 by
asgerf
Loading…
Treat zap custom encoders as sanitizers for log-injection checks
Go
#20912
opened Nov 25, 2025 by
danielriddell21
•
Draft
Previous Next
ProTip!
Updated in the last three days: updated:>2025-12-02.