forked from github/codeql
-
Notifications
You must be signed in to change notification settings - Fork 0
Pull requests: mrigankpawagi/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Java: Exclude JUnit test methods from log injection
Java
#24
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Python: Add shlex.quote as command injection sanitizer
Python
#23
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
JavaScript: Reduce FPs in missing-regexp-anchor for intentional partial matching
JS
#22
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
C#: Add EF Core interpolated SQL methods as SQL injection sanitizers
C#
#21
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Java: Exclude internal logging from stack trace exposure
Java
#20
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Python: Add json.dumps() as XSS sanitizer
Python
#19
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Java: Add URL.getHost() to SSRF host validation sanitizer
Java
#18
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
JavaScript: Reduce FPs in incomplete-sanitization for bracket pair removal
JS
#17
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Python: Exclude dotted module paths from hardcoded credentials
Python
#16
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Python: Add Django safe_join as path injection sanitizer
Python
#15
opened Jun 23, 2026 by
mrigankpawagi
Owner
Loading…
Java: Improve java/log-injection with DEBUG/TRACE exclusion, URLEncoder sanitizer, and test file exclusion
Java
#13
opened Jun 15, 2026 by
mrigankpawagi
Owner
Loading…
Java: Improve saneString in java/concatenated-command-line using controlledString + test exclusion
documentation
Improvements or additions to documentation
Java
#12
opened Jun 15, 2026 by
mrigankpawagi
Owner
Loading…
JavaScript: Reduce FPs in js/incomplete-sanitization for regex escaping
JS
#9
opened Jun 14, 2026 by
kiro-agent
Bot
Loading…
Java: Exclude test files from java/concatenated-sql-query
Java
#8
opened Jun 14, 2026 by
kiro-agent
Bot
Loading…
JavaScript: Reduce false positives in js/regex/missing-regexp-anchor for non-URL patterns
documentation
Improvements or additions to documentation
JS
#6
opened Jun 14, 2026 by
mrigankpawagi
Owner
Loading…
JavaScript: Exclude debug npm package from js/log-injection sinks
JS
#3
opened Jun 10, 2026 by
kiro-agent
Bot
Loading…
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.