advanced-security / awesome-codeql
A curated list of awesome CodeQL resources.
☆33Updated last month
Alternatives and similar repositories for awesome-codeql:
Users that are interested in awesome-codeql are comparing it to the libraries listed below
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆82Updated 10 months ago
- GH CLI CodeQL Scan Extension☆19Updated 5 months ago
- Collection of community-driven CodeQL query, library and extension packs☆144Updated 2 weeks ago
- Action to retrofit a CodeQL bundle with additional queries, libraries, and customizations☆25Updated 10 months ago
- CodeQL Security Queries☆25Updated this week
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆58Updated last week
- An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations…☆25Updated 2 years ago
- CLI to build a custom CodeQL bundle☆10Updated this week
- CodeQL zero to hero blog post series challenges☆115Updated 3 months ago
- Original workshops and staging area for new ones☆13Updated 5 months ago
- Integrate CodeQL into CI/CD pipelines, using the CodeQL CLI Bundle for Automated Code Scanning☆19Updated last week
- CodeQL database manager☆48Updated last week
- ☆71Updated 2 years ago
- A CodeQL workshop covering CVE-2021-21380☆12Updated 3 months ago
- My CodeQL queries collection☆96Updated last year
- GitHub Advanced Security Python Toolkit☆13Updated this week
- Custom / Experimental CodeQL queries☆37Updated 2 years ago
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆115Updated last year
- CodeQL queries developed by Trail of Bits☆89Updated 3 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- Proof of Concepts for unsafe deserialization in Ruby☆17Updated 5 months ago
- ☆184Updated 4 months ago
- ☆70Updated last month
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated last year
- Grab some/all of CodeQL CLI binary, QL library, VSCode starter workspace, VSCode and VSCode QL extension☆10Updated 10 months ago
- Testability Pattern Catalogs for SAST☆29Updated last month
- Intentionally vulnerable Go web app.☆43Updated last month
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆18Updated 3 years ago
- CodeQL workshops for GitHub Universe☆93Updated 2 years ago
- *Unofficial* lgtm.com CLI — Use at your own risk. Also don't add more than 3K projects to "My projects" list.☆13Updated 3 years ago