Meta tags:
description= CodeQL adds beta support for Ruby!;
Headings (most frequently used words):
2022, nov, maintainer, turbo, lmrodriguezr, editor, edit, oct, how, replies, footer, 14, mtodd, author, codeql, adds, beta, support, for, ruby, 6922, insert, link, 20, 2021, what, in, the, box, do, enable, it, can, give, feedback, comments, navigation, alexrford, aibaars,
Text of the page (most frequently used words):
the (37), this (28), github (19), #codeql (19), you (16), add (16), for (16), beta (16), code (15), ctrl (13), and (13), ruby (13), with (12), 2022 (12), quote (11), #comment (11), give (11), feedback (11), was (11), translation (10), helpful (10), reply (10), options (10), path (10), nov (9), reacted (8), emoji (8), list (7), shift (7), text (7), support (7), your (6), that (6), security (6), replies (6), case (6), from (6), about (5), new (5), sign (5), scanning (5), maintainer (5), turbo (5), not (5), use (5), discussions (5), 2021 (5), jump (5), all (5), can (4), issue (4), link (4), must (4), logged (4), vote (4), now (4), please (4), also (4), some (4), algorithm (4), warning (4), redirection (4), params (4), oct (4), open (4), repository (4), issues (4), 6922 (4), tab (3), blog (3), pull (3), have (3), join (3), available (3), analysis (3), because (3), more (3), broken (3), weak (3), cryptographic (3), don (3), lmrodriguezr (3), file (3), locations (3), safe (3), when (3), which (3), any (3), discussion (3), workflow (3), source (3), adds (3), actions (3), signed (2), another (2), window (2), refresh (2), session (2), reload (2), pricing (2), footer (2), navigation (2), thumbs (2), task (2), numbered (2), bulleted (2), italic (2), bold (2), heading (2), request (2), user (2), url (2), show (2), tell (2), already (2), account (2), conversation (2), https (2), author (2), alert (2), sensitive (2), results (2), find (2), past (2), false (2), prevent (2), retriggering (2), dismissed (2), want (2), identicon (2), modifying (2), just (2), been (2), running (2), mtodd (2), statements (2), only (2), thanks (2), though (2), but (2), think (2), work (2), fix (2), end (2), root_path (2), redirect_to (2), something (2), top (2), comments (2), public (2), how (2), write (2), will (2), help (2), started (2), enterprise (2), com (2), community (2), most (2), injection (2), editor (2), edit (2), content (2), insights (2), projects (2), requests (2), manage (2), packages (2), web (2), out, perform, action, time, training, api, contact, docs, status, privacy, terms, inc, eyes, rocket, heart, confused, hooray, laugh, down, reference, directly, mention, team, insert, participants, feature, enhancement, labels, category, free, generally, changelog, launches, see, 11107, reason, why, pops, version, deployed, yesterday, apparently, query, has, gotten, causing, flag, did, unfortunately, result, positive, dismissing, should, aibaars, perhaps, enough, next, cryptographically, longstanding, being, modified, expect, alter, everyone, suddenly, without, scanner, looking, appears, flagging, hundreds, commits, half, day, based, timeline, above, seeing, report, md5, used, auto, generate, avatars, same, seems, true, triple, constructs, answers, marked, them, positives, repo, hopefully, resolved, since, particular, extremely, useful, properly, control, flow, through, check, isn, recognized, sanitizer, there, ongoing, eta, alexrford, tested, yes, does, would, trigger, miguel, detects, comes, provided, however, triggered, one, known, getting, rule, faulty, sanitize, input, dictionary, checking, allowed, paths, structure, like, newest, oldest, encourage, questions, related, writing, forum, run, into, problems, question, setup, alerts, etc, respond, supply, much, detail, encountered, well, information, reproduce, feel, comfortable, posting, ticket, thread, contribute, own, queries, get, guide, start, using, simply, set, update, existing, default, starting, today, included, server, joins, includes, java, javascript, typescript, python, supported, languages, extension, cli, enable, within, secure, services, tools, created, release, spots, many, common, including, sql, regular, expression, denial, service, redos, multiple, cross, site, scripting, attack, vectors, command, line, 10th, popular, language, what, box, following, announcement, heard, official, launched, universe, went, wrong, actor, deleted, edited, return, locked, 261, 567, star, fork, notifications, message, organization, suggested, collections, trending, topics, repositories, articles, readme, project, fund, developers, sponsors, resources, customer, stories, studies, devsecops, devops, automation, solution, education, startups, teams, solutions, skills, documentation, features, explore, collaborate, outside, plan, track, changes, review, better, copilot, instant, dev, environments, codespaces, vulnerabilities, host, automate, product, toggle, skip, wayback, machine, http, archive, org, 20221215180558, timestamps, capture, fail, success, 2023, jan, dec, jul, 2025, captures,
Text of the page (random words):
codeql adds beta support for ruby discussion 6922 github codeql github 4 captures 28 oct 2021 26 jul 2025 nov dec jan 15 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221215180558 https github com github codeql discussions 6922 skip to content toggle navigation sign up product actions automate any workflow packages host and manage packages security find and fix vulnerabilities codespaces instant dev environments copilot write better code with ai code review manage code changes issues plan and track work discussions collaborate outside of code explore all features documentation github skills blog solutions for enterprise teams startups education by solution ci cd automation devops devsecops case studies customer stories resources open source github sponsors fund open source developers the readme project github community articles repositories topics trending collections pricing in this repository all github jump to no suggested jump to results in this repository all github jump to in this organization all github jump to in this repository all github jump to sign in sign up message github codeql public notifications fork 1 2k star 5 5k code issues 567 pull requests 261 discussions actions projects 0 security insights more code issues pull requests discussions actions projects security insights codeql adds beta support for ruby 6922 locked turbo started this conversation in show and tell codeql adds beta support for ruby 6922 turbo oct 20 2021 3 comments 6 replies return to top discussion options quote reply edited editor s edit actor deleted this content editor s edit something went wrong turbo oct 20 2021 maintainer if you have been following the universe 2021 announcement you ve already heard about it but now it s official we ve launched beta ruby support for codeql and github code scanning what s in the box ruby is the 10th most popular language within the open source community to help secure services and tools created with ruby this beta release spots many of the most common security issues including sql injection regular expression denial of service redos multiple cross site scripting attack vectors command line injection and more how do i enable it codeql for ruby is available by default in github com code scanning the codeql cli and the codeql extension for vs code starting today it will also be included in github enterprise server 3 4 ruby joins the list of supported codeql languages which also includes c c c java javascript typescript python and go to start using the new ruby analysis in code scanning simply update your existing workflow file or if you re new to code scanning set up an analysis workflow from the security tab in your repository want to contribute or write your own codeql queries for ruby this guide will help you get started how can i give feedback if you run into any problems or have a question about the ruby codeql beta setup alerts etc please respond to this thread please supply as much detail as you can about the issue you encountered as well as information to reproduce if available if you don t feel comfortable posting in this public discussion please open a support ticket we also encourage you to use the codeql discussions forum for any questions related to running or writing codeql beta was this translation helpful give feedback 1 you must be logged in to vote 3 replies 3 comments 6 replies oldest newest top comment options quote reply lmrodriguezr oct 14 2022 hi i m getting a warning from rule id rb url redirection which i think is faulty as i sanitize the input by dictionary checking of allowed paths the structure is something like case params path when w some safe redirection locations path params path redirect_to file join root_path path end codeql detects this as an issue because path comes from params path which is user provided however this redirection is only triggered when the path is one of the known safe locations thanks miguel beta was this translation helpful give feedback 1 you must be logged in to vote 4 replies comment options quote reply mtodd nov 2 2022 would it trigger with case path params path when w some safe redirection locations redirect_to file join root_path path end beta was this translation helpful give feedback comment options quote reply lmrodriguezr nov 2 2022 i just tested yes it does beta was this translation helpful give feedback comment options quote reply alexrford nov 3 2022 maintainer i think that the issue is that we don t properly account for control flow through case statements so the check isn t recognized as a sanitizer there s some ongoing work to fix this though no eta beta was this translation helpful give feedback comment options quote reply lmrodriguezr nov 3 2022 the same seems to be true for if statements and triple constructs not only case thanks for the answers though i ve marked them as false positives in my repo for now but hopefully this can be resolved since that particular warning is extremely useful beta was this translation helpful give feedback 1 comment options quote reply mtodd nov 2 2022 we re seeing a report for use of broken weak cryptographic algorithm md5 used to auto generate identicon avatars use of a broken or weak cryptographic algorithm the scanner is not just looking at the code we re modifying in the pr and appears to be flagging hundreds of commits in the past half day it s been running based on the timeline from the link above i dismissed it because it s not a cryptographically sensitive use and is longstanding code that is not being modified i don t expect we d want to alter everyone s identicon suddenly without warning by modifying the algorithm i ve dismissed the warning perhaps that is enough to prevent it from retriggering on the next pr beta was this translation helpful give feedback 1 you must be logged in to vote 2 replies comment options quote reply aibaars nov 3 2022 maintainer the reason why this alert pops up now is because a new version of codeql was deployed yesterday apparently the use of a broken or weak cryptographic algorithm query has gotten more sensitive causing it to flag up some results it did not find in the past unfortunately the new result is a false positive in your case dismissing the alert should prevent it from retriggering beta was this translation helpful give feedback 1 comment options quote reply turbo nov 3 2022 maintainer author please also see 11107 comment beta was this translation helpful give feedback comment options quote reply turbo nov 14 2022 maintainer author codeql support for ruby is now generally available https github blog changelog 2022 11 09 codeql code scanning launches ruby analysis support in ga beta was this translation helpful give feedback 1 you must be logged in to vote 0 replies sign up for free to join this conversation on github already have an account sign in to comment category show and tell labels enhancement new feature or request 5 participants add heading text add bold text ctrl b add italic text ctrl i add a quote ctrl shift add code ctrl e insert link link text url add add a link ctrl k add a bulleted list ctrl shift 8 add a numbered list ctrl shift 7 add a task list ctrl shift l directly mention a user or team reference an issue or pull request add heading text add bold text ctrl b add italic text ctrl i add a bulleted list ctrl shift 8 add a numbered list ctrl shift 7 add a task list ctrl shift l 1 reacted with thumbs up emoji 1 reacted with thumbs down emoji 1 reacted with laugh emoji 1 reacted with hooray emoji 1 reacted with confused emoji ️ 1 reacted with heart emoji 1 reacted with rocket emoji 1 reacted with eyes emoji footer 2022 github inc footer navigation terms privacy security status docs contact github pricing api training blog about you can t perform that action at this time you signed in with another tab or window reload to refresh your session you signed out in another tab or window reload to refresh your session
|