Issues: github/codeql
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
python taint tracking doesn't work with namespace packages properly
bug
Something isn't working
Python
#11780
opened Dec 21, 2022 by
amammad
I have setup a project to test the capability of CodeQL,to test taint tracking ablitity
C++
question
Further information is requested
#11752
opened Dec 20, 2022 by
hatface
[UX] How to run the ql tutorials in VS Code
question
Further information is requested
#11746
opened Dec 19, 2022 by
intrigus-lgtm
Explanation of ”Comparison result is always the same“ in PR is technically correct, but unclear
C++
question
Further information is requested
#11744
opened Dec 19, 2022 by
ryao
C/CPP: TaintTracking on a huge database and never terminates..
question
Further information is requested
#11688
opened Dec 14, 2022 by
iiins0mn1a
[bug] codeql duplicates some graph nodes in bqrs while generating cpp AST using a kind=graph query
question
Further information is requested
#11685
opened Dec 14, 2022 by
fullwaywang
ImproperCodeSanitization is much slower than other queries
question
Further information is requested
#11679
opened Dec 13, 2022 by
jakebailey
Go: go/log-injection produces false positives for logrus when sanitising formatters are used
false-positive
Go
#11657
opened Dec 12, 2022 by
mbg
[Java] "Deserialization of user-controlled data" is overly broad to be useful to end users
question
Further information is requested
#11603
opened Dec 7, 2022 by
JLLeitschuh
Ruby: Traditional if-else not detected as Further information is requested
StringConstArrayInclusionCallBarrier compared to conditional assignment.
question
#11558
opened Dec 4, 2022 by
intrigus-lgtm
False positives - cpp/unbounded-write
acknowledged
GitHub staff acknowledges this issue
C++
false-positive
#11557
opened Dec 4, 2022 by
ryao
False positive: Multiplication result converted to larger type
acknowledged
GitHub staff acknowledges this issue
false-positive
#11556
opened Dec 3, 2022 by
robn
False positive: "File is not always closed" (Python)
false-positive
#11533
opened Dec 1, 2022 by
SnoopJ
Local variable address stored in non-local memory (False positive)
false-positive
not security
This issue does not relate to a security query
#11528
opened Dec 1, 2022 by
uNetworkingAB
Code Scanning support for SARIF message string lookup in uploaded logs
question
Further information is requested
#11512
opened Dec 1, 2022 by
EasyRhinoMSFT
General issue (No source code was seen and extracted to C:\***\DB-codeql)
question
Further information is requested
#11476
opened Nov 29, 2022 by
FaiqueAli
Java: Some expressions have Further information is requested
<any> as type
question
#11442
opened Nov 27, 2022 by
Marcono1234
Can Codeql be used to extract backward slice for Java?
question
Further information is requested
#11440
opened Nov 26, 2022 by
smith-co
CodeQL is missing an inline mechanism to suppress warnings
question
Further information is requested
#11427
opened Nov 25, 2022 by
bryevdv
[False positive] GitHub staff acknowledges this issue
false-positive
not security
This issue does not relate to a security query
Python
py/call-to-non-callable on _decorated_ __call__ magic methods
acknowledged
#11408
opened Nov 24, 2022 by
amotl
[False positive] GitHub staff acknowledges this issue
false-positive
not security
This issue does not relate to a security query
Python
py/unused-local-variable on SQLAlchemy model definition classes
acknowledged
#11407
opened Nov 24, 2022 by
amotl
False positive – "Statement has no effect" for Python type hint ellipsis
false-positive
#11351
opened Nov 21, 2022 by
maxfischer2781
CodeQL: False positive for uninitialized variable (via import) in Python
acknowledged
GitHub staff acknowledges this issue
false-positive
Python
#11313
opened Nov 16, 2022 by
pyrito
Java: For some projects JDK classes have location under GitHub staff acknowledges this issue
Java
question
Further information is requested
sourceLocationPrefix
acknowledged
#11265
opened Nov 15, 2022 by
Marcono1234
Previous Next
ProTip!
Find all open issues with in progress development work with linked:pr.