-
Notifications
You must be signed in to change notification settings - Fork 1
Pull requests: CodeVigilant/codevigilant_semgrep_rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(html): detect HTML documents without a Content-Security-Policy meta tag (CWE-693)
#133
opened Aug 15, 2026 by
ai-anant
Loading…
feat(html): detect anchors with target=_blank lacking rel=noopener noreferrer (CWE-1022)
#132
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect Jelly form-entry title/description expressions rendered unescaped (CWE-79)
#131
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect CanonicalIdResolver subclasses resolving identities without an authorization check (CWE-290)
#130
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect setAccessible(true) reflective access on non-local members (CWE-284)
#129
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect synchronous blocking remoting calls inside RunListener callbacks (CWE-400)
#128
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect FormValidation handlers executing outbound HTTP without permission check (CWE-918)
#127
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect Stapler do* handlers emitting HttpResponses without permission check (CWE-862)
#126
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect HttpResponses.html served with non-literal content (CWE-79)
#125
opened Aug 15, 2026 by
ai-anant
Loading…
feat(java): detect FilePath.copyFrom called with a non-literal URL (CWE-918)
#124
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect passwords truncated to 72 bytes before BCrypt (CWE-916)
#123
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect JNDI LDAP referral-follow policy forwarding credentials (CWE-522)
#122
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect anonymous X509TrustManager accepting any certificate (CWE-295)
#121
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect LDAP StartTLS fail-open fallback to plaintext (CWE-319)
#120
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect Jelly anchors with tainted href expressions (CWE-79)
#119
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect unhardened DocumentBuilderFactory/TransformerFactory XML parsing (CWE-611)
#118
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect secret-typed Jenkins jelly fields rendered with f:textbox (CWE-522)
#117
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect trust-all Apache HttpClient TLS configuration (CWE-295)
#116
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect HttpGet/HttpPut created with non-literal URL (CWE-918)
#115
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect Executor.interrupt without any permission check in the enclosing method (CWE-862)
#114
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect fail-open permission check that redirects without return/throw (CWE-862)
#113
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect state-changing Stapler do* handlers without @RequirePOST (CWE-352)
#112
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect Matcher.replaceAll/appendReplacement with tainted replacement strings (CWE-74)
#111
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect doCheck* file-capability probes without a permission check (CWE-200)
#110
opened Aug 14, 2026 by
ai-anant
Loading…
feat(java): detect credential values passed into child-process environment maps (CWE-214)
#109
opened Aug 14, 2026 by
ai-anant
Loading…
Previous Next
ProTip!
What’s not been updated in a month: updated:<2026-07-18.