GeekMasher / security-codeqlLinks
CodeQL Security Queries
☆27Updated last week
Alternatives and similar repositories for security-codeql
Users that are interested in security-codeql are comparing it to the libraries listed below
Sorting:
- Source Code Vulnerability Detection Tools(SCVDT)provides a vulnerable code database, vulnerability detection service for Java and C/C++ p…☆117Updated 4 years ago
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆85Updated last year
- CodeQL zero to hero blog post series challenges☆144Updated 2 weeks ago
- Codyze is a static analyzer for Java, C, C++ based on code property graphs☆89Updated 8 months ago
- Collection of community-driven CodeQL query, library and extension packs☆187Updated last month
- Testability Pattern Catalogs for SAST☆31Updated 7 months ago
- Soot-based taint analysis with internal Java fluent interface for security specifications in fluentTQL implemented with MagpieBridge to s…☆18Updated 8 months ago
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications (NDSS 2022)☆25Updated last year
- VulZoo: A Comprehensive Vulnerability Intelligence Dataset | ASE 2024 Demo☆64Updated 6 months ago
- A set of Code-ql/Joern queries to find vulnerabilities☆64Updated 4 years ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various gr…☆75Updated 11 months ago
- ☆29Updated 5 months ago
- Works about detecting vulnerable using ML.☆87Updated 5 years ago
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆181Updated last year
- A curated list of awesome CodeQL resources.☆51Updated last month
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆133Updated this week
- 🪐 A Database of Existing Security Vulnerabilities Patches to Enable Evaluation of Techniques (single-commit; multi-language)☆41Updated 5 months ago
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning☆24Updated 3 years ago
- CodeQL library and queries for iterator invalidation☆22Updated 4 years ago
- CodeQL workshops for GitHub Universe☆96Updated 2 years ago
- A technique for developing Fortify structural rules and characterization rules.☆14Updated 5 years ago
- ☆10Updated 5 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆155Updated last year
- Witcher is the first framework for using AFL to fuzz web applications.☆95Updated last year
- ☆17Updated 2 years ago
- Python library for CPGQL server☆33Updated last year
- ☆104Updated last year
- A GPT-Based Fuzz Driver Generator☆48Updated last year
- ObjLupAnsys is a tool to detect prototype pollution vulnerabilities in Node.js packages. This project is written in Python and JavaScript…☆24Updated 3 years ago
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆73Updated last year