github / github/codeql

False Negative with https://github.com/robmoffat/codeql-vuln-blog

未關閉
#8,880 6 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Python question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the issue**

I forked the repo: https://github.com/robmoffat/codeql-vuln-blog

and then added the CodeQL GH action, but no vulnerabilities are reported.

Reviewing the python code in the repo, it seems ripe with SQL injection possibilities.

What am I doing wrong?

thanks

貢獻指南

開啟貢獻指南

研究方向

Start by reproducing the report in the forked robmoffat/codeql-vuln-blog repository with the added CodeQL GitHub Action. Inspect the action configuration and the Python code described as containing SQL-injection possibilities, then compare the analysis results with the expected findings. Done means explaining why no vulnerabilities are reported and identifying the required configuration or query change.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github-actions, python, sql
領域
ci-cd, security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
需要釐清
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。