aboutcode-org / aboutcode-org/vulnerablecode
Collect CodeQL queries for detecting specific vulnerabilities
- 主要语言
- Python
- 星标
- 702
- 派生
- 328
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 3
描述
https://github.com/github/codeql is a project by GitHub which is to put it simply is SQL for codebases. CodeQL queries are used by LGTM for static analysis of bad code practices.
The more interesting use of CodeQL is in finding security vulnerabilities, the way this works is you run a query designed to find say `CVE-a` on any codebase, and CodeQL determines whether the query is satisfied by the codebase(if yes than the codebase is vulnerable to `CVE-a` ).
Check this tweet.
https://twitter.com/ghsecuritylab/status/1258077647030022144
We should collect such queries and link them to `Vulnerability` objects.
See https://github.com/github/codeql/tree/master/python/ql/src/Security/CVE-2018-1281 , https://github.com/github/codeql/tree/master/java/ql/src/Security/CWE,
https://blog.mozilla.org/security/2019/11/14/adding-codeql-and-clang-to-our-bug-bounty-program/
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。