githubsatelliteworkshops / codeql
GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.
☆210Updated 5 months ago
Alternatives and similar repositories for codeql:
Users that are interested in codeql are comparing it to the libraries listed below
- My CodeQL queries collection☆96Updated last year
- When MVC magic turns black☆291Updated 4 years ago
- A static byte code analyzer for Java deserialization gadget research☆241Updated 7 years ago
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆115Updated last year
- An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations…☆25Updated 2 years ago
- ☆71Updated 2 years ago
- GreHack 2021 CodeQL for Java workshop☆75Updated 3 years ago
- Personal CodeQL queries☆61Updated this week
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Updated 5 years ago
- Java taint propagation for java. Define tainted sources, sanitizer methods and sinks via aspects.☆28Updated 6 years ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆248Updated 4 months ago
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆82Updated 10 months ago
- Ready to use docker image for CodeQL☆89Updated last year
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- Finding Java gadget chains with CodeQL☆167Updated 2 months ago
- Compiled dataset of Java deserialization CVEs☆61Updated 4 years ago
- ☆184Updated 4 months ago
- Starter workspace to use with the CodeQL extension for Visual Studio Code.☆515Updated last week
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆347Updated 2 years ago
- A vulnerable application exposing Spring Boot Actuators☆121Updated 6 years ago
- Deprecated: Please visit https://github.com/github/codeql instead.☆81Updated 2 years ago
- Sample Spring Boot App Demonstrating RCE via Exposed env Actuator and H2 Database☆104Updated 5 years ago
- Intentionally vulnerable Go web app.☆43Updated last month
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- Grammar-based HTTP/2 fuzzer with mutation ability☆43Updated 2 years ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated last year
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆58Updated last week
- cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vul…☆140Updated 3 years ago
- Insecure programming functions database☆105Updated last year
- A Node.js vulnerability finding tool.☆96Updated 4 years ago