#CodeQL

2025-04-30

[Перевод] Как GitHub использует CodeQL для обеспечения безопасности

Что происходит, когда GitHub берётся за собственную безопасность? Они пишут код для защиты кода — и активно используют для этого CodeQL. В этой статье команда Product Security Engineering рассказывает, как настроить масштабный автоматический анализ уязвимостей, зачем создавать свои пакеты запросов и как с помощью CodeQL находить ошибки, которые невозможно поймать обычным поиском по коду.

habr.com/ru/companies/otus/art

#CodeQL #github #безопасность_кода #уязвимости #GitHub_Advanced_Security #пакет_запросов #вариантный_анализ #cicd #анализ_уязвимостей

Andrew Eisenberg 🍁🍁aeisenberg@cosocial.ca
2025-03-26

I worked on the remediation of this vulnerability. It’s not great that we let this slip through, and it took two weeks of work to verify that nothing bad had been leaked. But overall, it was a good process, the disclosure process made sure we fixed the bug quickly, and I learned a lot.

Also, the reporter walked away with a tidy sum of $$$.

praetorian.com/blog/codeqleake

#github #codeql #security

2025-03-08
Created a #CodeQL Cheat Sheet to document what I struggled with recently:

https://scrapco.de/codeql-cheat-sheet/cpp/cpp-conditionals-cfg/

Will push updates as they pop to my mind. Contributions/ideas are also most welcome!

https://github.com/v-p-b/codeql-cheat-sheet
2025-03-07
I got badly nerd sniped by Qualys:

Dreams in #CodeQL - Quest for the Perfect GOTO

https://scrapco.de/blog/dreams-in-codeql-quest-for-the-perfect-goto.html
Andrew Eisenberg 🍁🍁aeisenberg@cosocial.ca
2025-01-09

I'm pleased with how this turned out. For the past few months with a lot of other people, I've been working on making #GitHub #Actions workflows are more secure using CodeQL. Here are the results:

github.blog/security/applicati

Now all public repositories on GitHub can opt in and make their code more secure with almost no effort.

#github #actions #security #CodeQL

2024-10-31

🔍Researcher Eviatar Gerzi uncovered 2 vulnerabilities in #Portainer! 🛡️

Learn how #CodeQL helped identify a blind SSRF and insecure encryption in this popular container management tool.

Read the full analysis here:

cyberark.com/resources/threat-

2024-08-21

GitHubs CodeQL action is quite finicky. It raises an error if it cannot analyze one of the languages it has initialized. Using the detected languages might pick up a language you're not going to build. Specifying all languages you might build will include some you will not build.

Ended up doing a continue-on-error:true for the analysis step as a workaround.

I don't think the action design is correct here.

#github #codeql

2024-07-09

Hey #PowerShell people: Want #GitHub #CodeQL to support PowerShell?

Let your voices be heard:

github.com/github/codeql-actio

2024-06-04

[Перевод] Устранение уязвимостей в системе безопасности с помощью искусственного интеллекта

В ноябре 2023 года GitHub объявил о запуске Code Scanning Autofix , который с помощью искусственного интеллекта предлагает исправления уязвимостей безопасности в кодовых базах пользователей. В этой статье мы расскажем о том, как работает Autofix, а также о системе оценки, которую мы используем для тестирования.

habr.com/ru/companies/otus/art

#codeql #уязвимости #github #безопасность

Gabriel Schneider - גבריאל שניידרgbrls@infosec.exchange
2024-05-16

#codeql is really cool, and they have a bug bounty program :)

Veit Schiele 🔜 GPNveit
2024-05-01

In an example project, we have significantly expanded the GitHub CI pipeline – it now includes
• pre-commit hooks
• building of Python packages
• testing against the built wheels
• determining the test coverage
• building the documentation
• checking the code quality

github.com/veit/items/actions/

CI pipeline with pre-commit, building and inspecting Python packages, testing against multiple Python versions, building docs, test coverage.
TheTransmittedthetransmitted
2024-03-22

Нещодавній запуск публічної бета-версії функції автоматичного виправлення вразливостей при скануванні коду на GitHub став справжнім проривом у сфері цифрової безпеки та розробки програмного забезпечення.

thetransmitted.com/ai/github-p

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2024-03-21

#GitHub’s new #AI-powered tool auto-fixes #vulnerabilities in your code
Known as Code Scanning Autofix and powered by #GitHubCopilot and #CodeQL, deal with over 90% of alert types in #JavaScript, #Typescript, #Java, and #Python. "When a vulnerability is discovered in a supported language, fix suggestions will include a natural language explanation of the suggested fix, together with a preview of the code suggestion that the developer can accept, edit, or dismiss"-GitHub
bleepingcomputer.com/news/secu

Wallywally19
2024-03-21

It's really impressive what has achieved in the past 2 years.

From creating the obvious AI brain to assist developers on daily tasks to, recently announced and introduced, autofix code security scanning.

I can't wait to see what's next for tooling and developer experience.

A way to keep an eye on what's coming is to visit github next at githubnext.com/

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst