#codeql — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #codeql, aggregated by home.social.
-
It's the silent changes... A #refactor of literally every moving part of https://github.com/madnuttah/unbound-docker took place!
Also implemented @renovatebot.com #renovate, @step_security #hardenrunners, #zizmor, #codeql & #Linting all the things.
CC @nlnetlabs 💚
#dns #dnssec #doq #quic #selfhosting #homelab #foss #opensource
-
It's the silent changes... A #refactor of literally every moving part of https://github.com/madnuttah/unbound-docker took place!
Also implemented @renovatebot.com #renovate, @step_security #hardenrunners, #zizmor, #codeql & #Linting all the things.
CC @nlnetlabs 💚
#dns #dnssec #doq #quic #selfhosting #homelab #foss #opensource
-
Prolog nezmizel. Jeho hlavní myšlenku dnes potkáváme v nástrojích, které se Prologu na první pohled nepodobají: v CodeQL pro analýzu kódu, v Rego pro policy-as-code, v Z3 pro práci s omezeními a v Leanu pro formální důkazy. Každý řeší jiný problém, ale všechny připomínají totéž: někdy je lepší popsat vztahy, pravidla, omezení nebo tvrzení než vrstvit další if.
https://zdrojak.cz/clanky/prolog-nezmizel-jen-dnes-zije-v-jinych-nastrojich/ -
#CodeQL 2.23.7 and 2.23.8 add security queries for #Go and #Rust
https://github.blog/changelog/2025-12-18-codeql-2-23-7-and-2-23-8-add-security-queries-for-go-and-rust/ -
#CodeQL 2.23.7 and 2.23.8 add security queries for #Go and #Rust
https://github.blog/changelog/2025-12-18-codeql-2-23-7-and-2-23-8-add-security-queries-for-go-and-rust/ -
GPT-5.2-Codex: nowy standard w programowaniu – bezpieczeństwo i jakość w kodzie
Czy model, który pisze kod szybciej niż junior po kawie, nauczył się wreszcie mówić „nie” wtedy, kiedy trzeba? OpenAI dorzuciło addendum do karty systemowej GPT-5.
Czytaj dalej:
https://pressmind.org/gpt-52-codex-nowy-standard-w-programowaniu-bezpieczenstwo-i-jakosc-w-kodzie/#PressMindLabs #asystentprogramisty #bezpieczenstwokodu #codeql #cwe #gpt52codex
-
Some weekend updates to my homepage:
Added a little guide to debug recursive #CodeQL predicates:
https://scrapco.de/codeql-cheat-sheet/debugging/debugging-recursion/
#Ghidra documentation now reflects the state of 11.4.3:
https://scrapco.de/ghidra_docs/ -
Some weekend updates to my homepage:
Added a little guide to debug recursive #CodeQL predicates:
https://scrapco.de/codeql-cheat-sheet/debugging/debugging-recursion/
#Ghidra documentation now reflects the state of 11.4.3:
https://scrapco.de/ghidra_docs/ -
Is it my weak search-fu again, or the new qlpack.yml format for #CodeQL is not officially documented? @GitHubSecurityLab
The best resource I could find is this one by @trailofbits:
https://appsec.guide/docs/static-analysis/codeql/advanced/#creating-new-query-packs -
Is it my weak search-fu again, or the new qlpack.yml format for #CodeQL is not officially documented? @GitHubSecurityLab
The best resource I could find is this one by @trailofbits:
https://appsec.guide/docs/static-analysis/codeql/advanced/#creating-new-query-packs -
Взгляд безопасника на ежегодный отчет Github Octoverse 2025
Взгляд безопасника на ежегодный отчет Github Octoverse 2025. Отчет 2025 выглядит как вестник новой реальности, где ИИ в разработке будет отведена ключевая роль. Постарался дать пару советов для безопасников которых ждет такое значимое изменение подходов. Давай почитаем!
-
It's the first on-location episode of #ITOps Query! At #GitHubUniverse, Katie Norton, Research Manager for IDC's #DevSecOps and #softwaresupplychainsecurity practice, explains how a new extension to GitHub's #CodeQL reflects increased awareness of security as a dimension of code quality and much more! https://youtu.be/eCU3OKgOTWY?si=ndH9I3kyYiErc2Qz
-
It's the first on-location episode of #ITOps Query! At #GitHubUniverse, Katie Norton, Research Manager for IDC's #DevSecOps and #softwaresupplychainsecurity practice, explains how a new extension to GitHub's #CodeQL reflects increased awareness of security as a dimension of code quality and much more! https://youtu.be/eCU3OKgOTWY?si=ndH9I3kyYiErc2Qz
-
[RSS] Modeling CORS frameworks with #CodeQL to find security vulnerabilities
https://github.blog/security/application-security/modeling-cors-frameworks-with-codeql-to-find-security-vulnerabilities/ -
[RSS] Modeling CORS frameworks with #CodeQL to find security vulnerabilities
https://github.blog/security/application-security/modeling-cors-frameworks-with-codeql-to-find-security-vulnerabilities/ -
[Перевод] Как GitHub использует CodeQL для обеспечения безопасности
Что происходит, когда GitHub берётся за собственную безопасность? Они пишут код для защиты кода — и активно используют для этого CodeQL. В этой статье команда Product Security Engineering рассказывает, как настроить масштабный автоматический анализ уязвимостей, зачем создавать свои пакеты запросов и как с помощью CodeQL находить ошибки, которые невозможно поймать обычным поиском по коду.
https://habr.com/ru/companies/otus/articles/905630/
#CodeQL #github #безопасность_кода #уязвимости #GitHub_Advanced_Security #пакет_запросов #вариантный_анализ #cicd #анализ_уязвимостей
-
GitHub CodeQL Actions Critical Supply Chain Vulnerability (CodeQLEAKED)
#HackerNews #GitHub #CodeQL #CodeQLEAKED #SupplyChain #Vulnerability #CyberSecurity
-
GitHub CodeQL Actions Critical Supply Chain Vulnerability (CodeQLEAKED)
#HackerNews #GitHub #CodeQL #CodeQLEAKED #SupplyChain #Vulnerability #CyberSecurity
-
I worked on the remediation of this vulnerability. It’s not great that we let this slip through, and it took two weeks of work to verify that nothing bad had been leaked. But overall, it was a good process, the disclosure process made sure we fixed the bug quickly, and I learned a lot.
Also, the reporter walked away with a tidy sum of $$$.
-
I worked on the remediation of this vulnerability. It’s not great that we let this slip through, and it took two weeks of work to verify that nothing bad had been leaked. But overall, it was a good process, the disclosure process made sure we fixed the bug quickly, and I learned a lot.
Also, the reporter walked away with a tidy sum of $$$.
-
Created a #CodeQL Cheat Sheet to document what I struggled with recently:
https://scrapco.de/codeql-cheat-sheet/cpp/cpp-conditionals-cfg/
Will push updates as they pop to my mind. Contributions/ideas are also most welcome!
https://github.com/v-p-b/codeql-cheat-sheet -
Created a #CodeQL Cheat Sheet to document what I struggled with recently:
https://scrapco.de/codeql-cheat-sheet/cpp/cpp-conditionals-cfg/
Will push updates as they pop to my mind. Contributions/ideas are also most welcome!
https://github.com/v-p-b/codeql-cheat-sheet -
I got badly nerd sniped by Qualys:
Dreams in #CodeQL - Quest for the Perfect GOTO
https://scrapco.de/blog/dreams-in-codeql-quest-for-the-perfect-goto.html -
I got badly nerd sniped by Qualys:
Dreams in #CodeQL - Quest for the Perfect GOTO
https://scrapco.de/blog/dreams-in-codeql-quest-for-the-perfect-goto.html -
Announcing #CodeQL Community Packs
https://github.blog/security/vulnerability-research/announcing-codeql-community-packs/
-
Announcing #CodeQL Community Packs
https://github.blog/security/vulnerability-research/announcing-codeql-community-packs/
-
🔍Researcher Eviatar Gerzi uncovered 2 vulnerabilities in #Portainer! 🛡️
Learn how #CodeQL helped identify a blind SSRF and insecure encryption in this popular container management tool.
Read the full analysis here:
-
🔍Researcher Eviatar Gerzi uncovered 2 vulnerabilities in #Portainer! 🛡️
Learn how #CodeQL helped identify a blind SSRF and insecure encryption in this popular container management tool.
Read the full analysis here:
-
Now available for free on all public repositories: #Copilot Autofix for #CodeQL code scanning alerts · #GitHub https://github.blog/changelog/2024-09-18-now-available-for-free-on-all-public-repositories-copilot-autofix-for-codeql-code-scanning-alerts/
-
Now available for free on all public repositories: #Copilot Autofix for #CodeQL code scanning alerts · #GitHub https://github.blog/changelog/2024-09-18-now-available-for-free-on-all-public-repositories-copilot-autofix-for-codeql-code-scanning-alerts/
-
GitHubs CodeQL action is quite finicky. It raises an error if it cannot analyze one of the languages it has initialized. Using the detected languages might pick up a language you're not going to build. Specifying all languages you might build will include some you will not build.
Ended up doing a continue-on-error:true for the analysis step as a workaround.
I don't think the action design is correct here.
-
GitHubs CodeQL action is quite finicky. It raises an error if it cannot analyze one of the languages it has initialized. Using the detected languages might pick up a language you're not going to build. Specifying all languages you might build will include some you will not build.
Ended up doing a continue-on-error:true for the analysis step as a workaround.
I don't think the action design is correct here.
-
[Перевод] Устранение уязвимостей в системе безопасности с помощью искусственного интеллекта
В ноябре 2023 года GitHub объявил о запуске Code Scanning Autofix , который с помощью искусственного интеллекта предлагает исправления уязвимостей безопасности в кодовых базах пользователей. В этой статье мы расскажем о том, как работает Autofix, а также о системе оценки, которую мы используем для тестирования.
-
#codeql is really cool, and they have a bug bounty program :)
-
Series on code static analysis using CodeQL
Credits Sylwia Budzynska"CodeQL zero to hero"
Part 1: https://github.blog/2023-03-31-codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/
Part 2: https://github.blog/2023-06-15-codeql-zero-to-hero-part-2-getting-started-with-codeql/
Part 3: https://github.blog/2024-04-29-codeql-zero-to-hero-part-3-security-research-with-codeql/ -
Series on code static analysis using CodeQL
Credits Sylwia Budzynska"CodeQL zero to hero"
Part 1: https://github.blog/2023-03-31-codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/
Part 2: https://github.blog/2023-06-15-codeql-zero-to-hero-part-2-getting-started-with-codeql/
Part 3: https://github.blog/2024-04-29-codeql-zero-to-hero-part-3-security-research-with-codeql/ -
In an example project, we have significantly expanded the GitHub CI pipeline – it now includes
• pre-commit hooks
• building of Python packages
• testing against the built wheels
• determining the test coverage
• building the documentation
• checking the code quality -
#GitHub’s new #AI-powered tool auto-fixes #vulnerabilities in your code
Known as Code Scanning Autofix and powered by #GitHubCopilot and #CodeQL, deal with over 90% of alert types in #JavaScript, #Typescript, #Java, and #Python. "When a vulnerability is discovered in a supported language, fix suggestions will include a natural language explanation of the suggested fix, together with a preview of the code suggestion that the developer can accept, edit, or dismiss"-GitHub
https://www.bleepingcomputer.com/news/security/githubs-new-ai-powered-tool-auto-fixes-vulnerabilities-in-your-code/ -
Announcing the latest addition to the Trail of Bits #Testing #Handbook: a brand new chapter on #CodeQL!
https://blog.trailofbits.com/2023/12/11/say-hello-to-the-next-chapter-of-the-testing-handbook/
See also:
https://blog.trailofbits.com/2023/12/06/publishing-trail-of-bits-codeql-queries/