aboutcode-org / aboutcode-org/vulnerablecode

Collect CodeQL queries for detecting specific vulnerabilities

Abierto
#215 3 comentarios 1 reacción 0 asignados Ver en GitHub
Data collection
Lenguaje dominante
Python
Estrellas
702
Forks
328
Merge medio
3 d 8 h
PR fusionados (30 d)
3

Descripción

https://github.com/github/codeql is a project by GitHub which is to put it simply is SQL for codebases. CodeQL queries are used by LGTM for static analysis of bad code practices.

The more interesting use of CodeQL is in finding security vulnerabilities, the way this works is you run a query designed to find say `CVE-a` on any codebase, and CodeQL determines whether the query is satisfied by the codebase(if yes than the codebase is vulnerable to `CVE-a` ).

Check this tweet.
https://twitter.com/ghsecuritylab/status/1258077647030022144

We should collect such queries and link them to `Vulnerability` objects.
See https://github.com/github/codeql/tree/master/python/ql/src/Security/CVE-2018-1281 , https://github.com/github/codeql/tree/master/java/ql/src/Security/CWE,
https://blog.mozilla.org/security/2019/11/14/adding-codeql-and-clang-to-our-bug-bounty-program/

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.