Explore tweets tagged as #CodeQL
Join us this Saturday as we explore API Security with GitHub CodeQL with Emmanuella Okorie (@pentester__), an amazing Software Engineer 🔥. Date: This Saturday.Topic: API Security with GitHub CodeQL.Time: 6 PM WAT. Come ready to learn, ask questions, and level up your API
3
15
26
Implementing a custom #CodeQL extractor + libs for an unsupported language is pure torture but hey I found some bugs already so I guess it’s worth it
1
1
15
Happy to share that @pwntester and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at @BarcelonaBsides, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
0
6
25
Next week I'll be at @ekoparty talking about vulnerabilities in GitHub Actions and how I extended CodeQL to find them at scale. I've wanted to go to Eko for years - it's a dream come true, and on their 20th anniversary no less! So excited!
2
6
48
How to secure your GitHub Actions workflows with CodeQL. Dive into this actionable supply chain security research from @pwntester . This work resulted in dozens of high impact supply chain findings and, most importantly, added CodeQL support for your GitHub workflows!
6
15
54
Last year I played Realworld CTF and solved "Protected by JavaSE" together with I-Al-Istannen. We exploited XXE in @github's CodeQL using the unintended CVE-2024-25129. I wrote about the (un)intended solution and how to use CodeQL to find bugs in CodeQL 😂.
0
11
41
La semana que viene estare por la @ekoparty hablando de vulnerabilidades en GitHub Actions y como extendi CodeQL para encontrarlas a escala. Llevo años queriendo ir a la Eko, sueño cumplido y encima en su 20 aniversario! Muchas ganas!
1
5
26
Another day, another secret in an artifact leads to potential doom. @Praetorian_Labs found a token valid for only 1 SECOND in a @GitHub CodeQL debug artifact. They raced it, got write perms, and could've poisoned the v3 tag used by HUNDREDS OF THOUSANDS of repos. 🔗👇
2
12
74
さっそくGitHub Advanced SecurityのCode scanning alertsのCodeQL使ってみた!.✅セキュリティタブ.✅Code scanning alerts.✅CodeQL analysisでAdvancedを選択.✅ワークフローをコミット.でいけました!!!.次は脆弱性をあえて作って実験してみたい
おお、Github純正のコードレビューツール嬉しい.脆弱性チェックだけならCodeRabbitと併用して強強レビュワー作れるかな. あとOSS開発者には無料らしい💪. GitHub、コードの脆弱性を自動的に見つけてCopilotが修正案まで示す「Copilot Autofix」正式サービスに - Publickey
0
1
6