False Negative with https://github.com/robmoffat/codeql-vuln-blog
未關閉
Python
question
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the issue**
I forked the repo: https://github.com/robmoffat/codeql-vuln-blog
and then added the CodeQL GH action, but no vulnerabilities are reported.
Reviewing the python code in the repo, it seems ripe with SQL injection possibilities.
What am I doing wrong?
thanks
貢獻指南
研究方向
Start by reproducing the report in the forked robmoffat/codeql-vuln-blog repository with the added CodeQL GitHub Action. Inspect the action configuration and the Python code described as containing SQL-injection possibilities, then compare the analysis results with the expected findings. Done means explaining why no vulnerabilities are reported and identifying the required configuration or query change.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- github-actions, python, sql
- 領域
- ci-cd, security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 需要釐清
- 新手友好度
- 25/100