github / github/codeql

Implement queries to detect Trojan Source

Open
#7,037 3 comments 3 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Does CodeQL have plans to implement automated detection of attempts to exploit the Trojan Source vulnerabilities that have been recently publicized?

https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/

For instance, it seems right now that CodeQL with `security-and-quality` enabled does not raise any issues on the proof of concept repository for this security research paper: https://github.com/nickboucher/trojan-source

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.