Search results for #CodeQL
Second blog post by Clément Hurlin on #CodeQL. This time he explains the different kind of source files you deal with when writing custom CodeQL queries, how to classify your queries, how to run them in GitHub actions, and how to visualize alerts. tweag.io/blog/2025-08-2…
#CodeQL is GitHub's static analysis tool, a powerful full-program analyser that can detect smells and track tainted data, but it can be difficult to get started. Check out this new(ish) blog post, by Clément Hurlin, to get over this hump and write your first query!…
🚨 BREAKING: Unleashing the power of CodeQL to unearth hidden security flaws in CORS frameworks! Discover how this approach is reshaping security protocols and fortifying web defenses. 🔍 🔗 #CyberSecurity #CodeQL github.blog/security/appli…
⚠️ 100+ software vulnerabilities are reported daily. Who has time to fix them all? Enter CodeQL — GitHub’s AI debugger that scans, patches, and explains code issues automatically. projectosint.com/codeql-ai-debu… #CodeQL #AIDebugging #GitHubTools #SecureDev #AIinTech
Implementing a custom #CodeQL extractor + libs for an unsupported language is pure torture but hey I found some bugs already so I guess it’s worth it
Evaluate custom ratings windshock.github.io/en/post/2024-0… using #sast like #joernio, #CodeQL, and #Checkmarx in contexts lacking an established #DevelopmentCulture, particularly beneficial for #LazyDeveloper.
The risks of GitHub Actions: Researcher describes severe potential of CodeQL vulnerability, now fixed: #GitHubActions #CodeQL #SecurityVulnerability #CyberSecurity #DevOps #GitHubSecurity @d3vclass devclass.com/2025/04/02/the… devclass.com/2025/04/02/the…
Wrote a MCP server for #CodeQL, tried it out with Cursor and it's quite fun so far! I think the next step would be adding support for query-models. Allowing an LLM to easily add sources/sinks to existing queries could be very promising😁 github.com/JordyZomer/cod…
GitHub’s Product Security Engineering team is securing the code behind #GitHub with tools like #CodeQL, detecting and fixing vulnerabilities at scale. Now, they’re sharing their insights to help organizations strengthen their own codebases: bit.ly/4j6GMoe #InfoQ
How #GitHub uses #CodeQL to secure GitHub github.blog/engineering/ho…
How GitHub uses CodeQL to secure GitHub #secure #CodeQL buff.ly/3ExDETv
Had an interesting discussion today while comparing code-pathfinder to #CodeQL. I ran the numbers and found that it already covers 15% of CodeQL’s Java support—way more than I expected 🤯 vs the amount of time invested. Even more surprising? code-pathfinder now supports over 30%…
Finding Bugs in Chrome with CodeQL #ChromeBugs #CodeQL #SecurityFlaws #BugHunting #WebDevelopment bughunters.google.com/blog/508511148…
Just managed to solve all #CodeQL warnings for @MahoCommerce! The only 4 left are within #prototypejs, which will go away for good as soon as possible #ecommerce #php #magento #openmage #js
Has anyone implemented an end-to-end project for CodeQL analysis? Ideally, such an analysis would not only include code-level security but also demonstrate how to trigger related vulnerabilities in a real environment (usually an HTTP message). #CodeQL #StaticAnalysis…
🔍@g3rzi uncovered 2 vulnerabilities in #Portainer! 🛡️ Learn how #CodeQL helped identify a blind SSRF and insecure encryption in this popular container management tool. Read the full analysis here: cyberark.com/resources/thre…

intrigus @intrigus_
266 Followers 184 Following I create and break stuff. GitHub ⭐. @KITCTF. #Java, #CodeQL and #V8. Github: https://t.co/2eJKNdhQaV Security stuff: https://t.co/eg564HmccR
CodeQL @code_ql
8 Followers 0 Following
Semmle @Semmle
2K Followers 20 Following Semmle has joined GitHub. Finding zero-days and automating variant analysis | Creators of CodeQL and @LGTM
CODEQL REFERENCE DOCS @CodeqlD
3 Followers 52 Following https://t.co/OeU55iBT0Qไม่สามารถลงชื่อเข้าใช้บัญชี-google-ได้ใช่ไหม?hl=th&msgid=43655112
codeql @codeqlll
0 Followers 17 Following