Variant analysis platform designed to help developers ship secure code. Community-driven security analysis by @GitHub (previously @Semmle) - FREE for #OSS.
We've just launched our @github App for LGTM, part of our migration away from the OAuth API. It's now simpler than ever to enable automated code review for your projects, with much tighter control over permissions, and many of other benefits!
https://t.co/EvADGf5Tqy
ICYMI: We're running a CTF until December 31st. Write a CodeQL query to find a specific class of DOM-based XSS vulns. The 2 best submissions will win Nintendo Switches, and 10 additional entries will receive coupons that can be used for GitHub Swag.
https://t.co/fqliovIXP2
Learn how our security researcher @nicowaisman found wireless vulnerabilities in the Linux Kernel, and variants, thanks to CodeQL: https://t.co/eKE0VPPna5
Now in beta! LGTM is supporting Golang and we have some projects that you can explore. Check them out and suggest others you'd like us to analyze. https://t.co/wTgvI4iPuU
Attending @owasp#GlobalAppSec Amsterdam? @samlanning will be talking about how to find and prevent entire classes of security vulnerabilities tomorrow. https://t.co/p8mml34llJ
Ever wish you had an extra team member to review each pull request with laser focus on security?
Join a live discussion and demo with Semmle's @oegerikus (CEO and founder) and @fjserna (CSO) on community-powered secure development.
https://t.co/cFkrbfi8sC
Today we welcome @Semmle to the GitHub family!
We’re excited to bring the world’s most powerful semantic code engine to the world’s largest developer community🔥
https://t.co/EwkmDrGWPu
Big news! Semmle is joining the @Github team to bring community-powered security analysis to millions of developers. Learn more from Semmle CEO @oegerikus here: https://t.co/iDN5RrY8J1
ICYMI: QL snapshots for analysis of large open source projects are now available. If you want to perform #VariantAnalysis on large OSS projects, get more info here: https://t.co/uPMuwIDA7E
Does a developer's emotional state of mind affect the code they write? Our data science team investigates the impact of angry devs https://t.co/YAmmcMUYI8
The #SemmleCTF Challenge ends today! Last chance to submit your QL query for a chance to win wireless headphones. Winners will be announced next week... stay tuned! https://t.co/0ApXuknats
Are unit tests really effective in preventing bugs? We analyzed over 50k LGTM projects in Java, Python, and Javascript to find out. https://t.co/CTjGkPduss
.@fjserna shares what "open security" means to him and highlights OSS-Fuzz, @github and other projects which are leading the way. https://t.co/Lm4wyAPCpk
We just extended the #SemmleCTF Challenge from #BlackHat until Sept 6!
Simply follow these instructions to find real vulnerabilities in Das U-Boot using QL and submit your query for a chance to win a pair of these! https://t.co/JMY9xphXbc
In case you missed us at #BlackHat2019, check out the recap of @fjserna's preso on finding vulns in Das U-Boot, @baron_von_ryan's #SemmleCTF challenge, and the penthouse party with our friends from @IOActive https://t.co/L3GmmACJoj