-
Notifications
You must be signed in to change notification settings - Fork 1
Pull requests: CodeVigilant/codevigilant_semgrep_rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(java): detect unescaped dataset-derived value embedded in chart tooltip/URL image-map generators (CWE-79)
#163
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect HTTP client request to a non-literal URL with attached credentials (CWE-918/522)
#162
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect uncontained FilePath(base, rel) path construction (CWE-22)
#161
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect messaging ConnectionFactory constructed from a non-literal URL (SSRF, CWE-918)
#160
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect non-literal value concatenated into a JS template-literal in served HTML (CWE-79)
#159
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect cloud agent provisioning in pipeline Steps without an ACL permission check (CWE-862)
#158
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect secret/token-returning method results passed directly to a logger (CWE-532)
#157
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect content-security-policy response header set to an empty value on a served entrypoint (CWE-693/79)
#156
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect unescaped raw() of non-literal values in Groovy/Stapler view templates (CWE-79)
#155
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect Jenkins item resolution via getItem(...) without an explicit permission argument (CWE-862)
#154
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect Jenkins Secret credential getter returning plaintext via getPlainText() (CWE-522)
#153
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect unescaped concatenated string built into request/execution JSON payload (CWE-94)
#152
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect SSH ServerHostKeyVerifier that always returns true (CWE-295)
#151
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect JSON-serialized object passed directly to a logger (CWE-532)
#150
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect HTTP client TLS certificate validation disabled (CWE-295)
#149
opened Aug 28, 2026 by
ai-anant
Loading…
feat(yaml): detect ${{ github.<context> }} expression inside run/script steps — command injection (CWE-78)
#148
opened Aug 28, 2026 by
ai-anant
Loading…
feat(go): detect non-constant argument to template.HTML(...) — html/template escaping bypass (CWE-79)
#147
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect credential constructors hardcoding CredentialsScope.GLOBAL (CWE-269)
#146
opened Aug 28, 2026 by
ai-anant
Loading…
feat(bash): detect hardcoded credential/token literals (CWE-798)
#145
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect ProcessBuilder command/arguments built from macro/override-expanded values (CWE-88)
#144
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect hardcoded credential/token literals (CWE-798)
#143
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect CredentialsStore authorizing via global ACL or forced SYSTEM auth (CWE-862)
#142
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect HTTP client base URL set from a config-driven/non-literal expression via ApiClient.setBasePath (CWE-918)
#141
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect secret-typed Jenkins config fields stored as plain String instead of hudson.util.Secret (CWE-256)
#140
opened Aug 28, 2026 by
ai-anant
Loading…
feat(java): detect Kong Unirest HTTP requests to a non-literal URL (CWE-918)
#139
opened Aug 28, 2026 by
ai-anant
Loading…
Previous Next
ProTip!
What’s not been updated in a month: updated:<2026-07-28.