-
Notifications
You must be signed in to change notification settings - Fork 2k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
C++: Fix This PR does not need a change note
NameQualifyingElement db inconsistency
C++
no-change-note-required
#21968
opened Jun 10, 2026 by
jketema
Contributor
Loading…
Java: convert all qlref tests to inline expectation tests using postprocessing
Java
no-change-note-required
This PR does not need a change note
#21966
opened Jun 10, 2026 by
owen-mc
Contributor
Loading…
Go: convert all qlref tests to inline expectation tests using postprocessing
Go
no-change-note-required
This PR does not need a change note
#21965
opened Jun 10, 2026 by
owen-mc
Contributor
Loading…
Add experimental C# query: SSRF host guard missing IPv6-transition unwrap (CWE-918/CWE-1389)
C#
documentation
#21964
opened Jun 10, 2026 by
tonghuaroot
Contributor
Loading…
Unified: More work on AST and Swift mappings
no-change-note-required
This PR does not need a change note
Go: fix
DataFlow::ResultNode and some related things
documentation
Go
#21957
opened Jun 8, 2026 by
owen-mc
Contributor
Loading…
Cfg: Fold getTryInit into indexed getBody.
C#
Java
no-change-note-required
This PR does not need a change note
#21955
opened Jun 8, 2026 by
aschackmull
Contributor
Loading…
[Javascript] Prompt Injection queries
documentation
javascript
Pull requests that update Javascript code
JS
Python
#21953
opened Jun 8, 2026 by
BazookaMusic
Contributor
•
Draft
Kotlin: Add support for Kotlin 2.4.0
documentation
Java
Kotlin
#21952
opened Jun 8, 2026 by
andersfugmann
Contributor
•
Draft
Go: Improve precision of
go/unhandled-writable-file-close
documentation
Go
#21940
opened Jun 4, 2026 by
owen-mc
Contributor
Loading…
YAML: Extract comments
Actions
Analysis of GitHub Actions
depends on internal PR
This PR should only be merged in sync with an internal Semmle PR
javascript
Pull requests that update Javascript code
JS
no-change-note-required
This PR does not need a change note
Python
QL-for-QL
Ruby
Rust
Pull requests that update Rust code
#21935
opened Jun 3, 2026 by
MathiasVP
Contributor
Loading…
Shared CFG: add defaulted getWhileElse/getForeachElse to AstSig
#21931
opened Jun 2, 2026 by
yoff
Contributor
Loading…
Python: inline init_module_submodule_defn into ImportResolution
documentation
Python
#21930
opened Jun 2, 2026 by
yoff
Contributor
Loading…
Python: add new shared-CFG-backed control flow graph (additive)
documentation
Go
Python
Ruby
Rust
Pull requests that update Rust code
Python: qualify Flow.qll's AST references with Py:: prefix
no-change-note-required
This PR does not need a change note
Python
#21920
opened Jun 1, 2026 by
yoff
Contributor
Loading…
Python: deprecate AstNode.getAFlowNode() and rewrite callers
documentation
Python
#21919
opened Jun 1, 2026 by
yoff
Contributor
Loading…
Kotlin: Fix findTopLevelPropertyOrWarn for K2 compiler
documentation
Java
Kotlin
#21915
opened May 30, 2026 by
david-allison
Loading…
C#: Refactor- and rename operation expressions.
C#
#21909
opened May 29, 2026 by
michaelnebel
Contributor
•
Draft
C++: Proper indirection in all QL models
C++
no-change-note-required
This PR does not need a change note
Previous Next
ProTip!
Follow long discussions with comments:>50.