-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Bump github.com/go-git/go-git/v5 from 5.1.0 to 5.17.1 in /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp in the go_modules group across 1 directory
dependencies
Pull requests that update a dependency file
documentation
Go
#21617
opened Mar 30, 2026 by
dependabot
bot
Loading…
C#: Fix inconsistent casing of Cs/CS.
C#
no-change-note-required
This PR does not need a change note
#21613
opened Mar 30, 2026 by
aschackmull
Loading…
C#: Taint members of types in ASP.NET user context.
C#
#21612
opened Mar 30, 2026 by
michaelnebel
•
Draft
Narrow ZipSlip sinks to file write operations, excluding read-only paths
documentation
Java
#21609
opened Mar 28, 2026 by
MarkLee131
Loading…
Actions: Removed a false positive injection sink model for theAnalysis of GitHub Actions
documentation
veracode/veracode-sca action.
Actions
#21604
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
Actions: Add taint summary for suisei-cn/actions-download-file url input
Actions
Analysis of GitHub Actions
documentation
#21600
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
C#: Simplify the ConstantCondition query.
C#
documentation
#21599
opened Mar 27, 2026 by
aschackmull
•
Draft
Python: Port ShouldUseWithStatement.ql
no-change-note-required
This PR does not need a change note
Python
#21598
opened Mar 27, 2026 by
tausbn
Loading…
Data flow: Add hook for preventing lambda dispatch in source call contexts
C#
DataFlow Library
no-change-note-required
This PR does not need a change note
#21592
opened Mar 26, 2026 by
hvitved
Loading…
Python: Improve "bind all interfaces" query
documentation
Python
#21590
opened Mar 26, 2026 by
tausbn
Loading…
Rust: Fix performance issue associated with neutral models
no-change-note-required
This PR does not need a change note
Rust
Pull requests that update Rust code
Shared: update code comments explaining models-as-data format to include barriers and barrier guards
C#
C++
DataFlow Library
Go
Java
JS
no-change-note-required
This PR does not need a change note
Python
Ruby
Rust
Pull requests that update Rust code
Swift
#21584
opened Mar 26, 2026 by
owen-mc
Loading…
Kotlin: update to 2.3.20
depends on internal PR
This PR should only be merged in sync with an internal Semmle PR
documentation
Java
Kotlin
Go: fix bad join order
Go
no-change-note-required
This PR does not need a change note
#21576
opened Mar 25, 2026 by
owen-mc
Loading…
Remove false positive injection sink models for Analysis of GitHub Actions
documentation
docker/build-push-action and step-security/harden-runner
Actions
#21574
opened Mar 25, 2026 by
redsun82
Loading…
C#: Replace CFG with the shared implementation
C#
Java
#21565
opened Mar 24, 2026 by
aschackmull
•
Draft
C++: Disable cpp/implicit-function-declaration on build mode none databases
C++
documentation
#21553
opened Mar 23, 2026 by
geoffw0
Loading…
Previous Next
ProTip!
What’s not been updated in a month: updated:<2026-02-28.