github / github/codeql

Implement queries to detect Trojan Source

未關閉
#7,037 3 則留言 3 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Does CodeQL have plans to implement automated detection of attempts to exploit the Trojan Source vulnerabilities that have been recently publicized?

https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/

For instance, it seems right now that CodeQL with `security-and-quality` enabled does not raise any issues on the proof of concept repository for this security research paper: https://github.com/nickboucher/trojan-source

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。