Skip to content

[Question] is Cross repo taint analysis in java possible ?  #12300

@chmodxxx

Description

@chmodxxx

Hello, we perform codeql java analysis on some repos, and in case the referenced package is from another repo we lose information,

I was wondering if it's possible to perform cross repo analysis, and how would that look like ? I wonder if a db build of multiple repos is possible and is that the best solution ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions