github / github/codeql

Implement queries to detect Trojan Source

オープン
#7,037 コメント 3 件 リアクション 3 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Does CodeQL have plans to implement automated detection of attempts to exploit the Trojan Source vulnerabilities that have been recently publicized?

https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/

For instance, it seems right now that CodeQL with `security-and-quality` enabled does not raise any issues on the proof of concept repository for this security research paper: https://github.com/nickboucher/trojan-source

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。