aegilops :github::microsoft: · @aegilops
126 followers · 470 posts · Server fosstodon.org

I open sourced a tool to create lists of repos to run GitHub CodeQL’s Multi-Repository Variant Analysis on, using a keyword search on GitHub.

It's a Bash script you can trigger with a VSCode build task. It uses the GitHub API (via the GitHub CLI) to fill a list in the VSCode settings.

It’s a stopgap before this sort of feature makes it into the product.

github.com/advanced-security/m

#mrva #variantanalysis #CodeQL #github #vscode #buildtask #sast #vulnerabilityresearch

Last updated 1 year ago

aegilops :github::microsoft: · @aegilops
118 followers · 432 posts · Server fosstodon.org

You can now run a single static analysis query across thousands of repos on GitHub using CodeQL's MRVA (Multi-repo Variant Analysis).

That's great both for security research and rapidly auditing exposure to a single vuln or weakness for security teams.

It works from the CodeQL extension for VSCode, with open source public repos & private repos where CodeQL Code Scanning is enabled.

github.blog/2023-03-09-multi-r

#github #securityresearch #vulnerabilityresearch #CodeQL #variantanalysis #mrva #sast

Last updated 1 year ago