Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
OpenIdentityPlatform
/
OpenAM
Public
Uh oh!
There was an error while loading.
Please reload this page
.
Notifications
You must be signed in to change notification settings
Fork
178
Star
894
Code
Issues
3
Pull requests
14
Discussions
Actions
Projects
Wiki
Security and quality
46
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Wiki
Security and quality
Insights
Actions: OpenIdentityPlatform/OpenAM
Actions
All workflows
Workflows
Build
Build
CodeQL
CodeQL
CodeQL
CodeQL
Copilot cloud agent
Copilot cloud agent
Copilot code review
Copilot code review
Dependabot Updates
Dependabot Updates
Package/Deploy
Package/Deploy
Release
Release
Show more workflows...
Management
Caches
CodeQL
CodeQL
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
codeql.yml
will be ignored since log searching is not yet available
155 workflow runs
155 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
Enable HttpOnly session cookies by default
CodeQL
#155:
Pull request
#1059
synchronize by
vharseko
4h 49m 58s
vharseko:features/httponly
vharseko:features/httponly
4h 49m 58s
View #1059
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
CodeQL
#154:
Pull request
#1134
synchronize by
vharseko
1h 54m 24s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
1h 54m 24s
View #1134
View workflow file
Add Trivy vulnerability scanning for the Docker image
CodeQL
#153:
Pull request
#1141
opened by
vharseko
1h 56m 10s
vharseko:docker-trivy-scan
vharseko:docker-trivy-scan
1h 56m 10s
View #1141
View workflow file
Run the CodeQL security-and-quality suite
CodeQL
#152:
Pull request
#1140
opened by
vharseko
2h 56m 19s
vharseko:codeql-security-and-quality
vharseko:codeql-security-and-quality
2h 56m 19s
View #1140
View workflow file
Read SAML parameters from their binding in the .NET Fedlet; run e2e scripts without a shell
CodeQL
#151:
Pull request
#1139
opened by
vharseko
1h 28m 39s
vharseko:fedlet-sample-hardening
vharseko:fedlet-sample-hardening
1h 28m 39s
View #1139
View workflow file
Keep stack traces and exception messages out of HTTP responses
CodeQL
#150:
Pull request
#1138
opened by
vharseko
1h 11m 11s
vharseko:no-stack-traces-in-responses
vharseko:no-stack-traces-in-responses
1h 11m 11s
View #1138
View workflow file
Keep a logged value from forging a debug record
CodeQL
#149:
Pull request
#1137
opened by
vharseko
1h 17m 3s
vharseko:debug-log-continuation
vharseko:debug-log-continuation
1h 17m 3s
View #1137
View workflow file
Set the Secure and HttpOnly cookie flags from creation
CodeQL
#148:
Pull request
#1136
opened by
vharseko
1h 27m 0s
vharseko:cookie-flags-from-creation
vharseko:cookie-flags-from-creation
1h 27m 0s
View #1136
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
CodeQL
#147:
Pull request
#1134
synchronize by
vharseko
52m 28s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
52m 28s
View #1134
View workflow file
Check the SAML 1.x TARGET and the WS-Federation wreply against the realm's valid goto URLs
CodeQL
#146:
Pull request
#1135
opened by
vharseko
50m 9s
vharseko:saml1-wsfed-redirect-target
vharseko:saml1-wsfed-redirect-target
50m 9s
View #1135
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
CodeQL
#145:
Pull request
#1134
opened by
vharseko
37m 44s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
37m 44s
View #1134
View workflow file
Run the security filters on every dispatch type
CodeQL
#144:
Pull request
#1133
opened by
vharseko
33m 34s
vharseko:security-filters-all-dispatchers
vharseko:security-filters-all-dispatchers
33m 34s
View #1133
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 PO…
CodeQL
#143:
Commit
50fa700
pushed by
vharseko
18m 53s
master
master
18m 53s
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_s…
CodeQL
#142:
Commit
406d5ba
pushed by
vharseko
20s
master
master
20s
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does no…
CodeQL
#141:
Commit
4b52a13
pushed by
vharseko
1h 21m 40s
master
master
1h 21m 40s
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources in openam-ui-api (4.3.1 -> 4.3.2)
CodeQL
#140:
Pull request
#1132
opened by
vharseko
1h 54m 30s
vharseko:fix/cve-2026-84375-js-yaml-api
vharseko:fix/cve-2026-84375-js-yaml-api
1h 54m 30s
View #1132
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#139:
Pull request
#1128
synchronize by
vharseko
1h 17m 31s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
1h 17m 31s
View #1128
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#138:
Pull request
#1131
synchronize by
vharseko
15m 9s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
15m 9s
View #1131
View workflow file
Do not log session ids, access tokens and password attributes (#1127)
CodeQL
#137:
Commit
b6c1d8b
pushed by
vharseko
17m 45s
master
master
17m 45s
View workflow file
GHSA-x8cj-3hqv-cgwh Session query REST endpoint lets a realm administ…
CodeQL
#136:
Commit
e0ba59d
pushed by
vharseko
1m 10s
master
master
1m 10s
View workflow file
Do not log session ids, access tokens and password attributes
CodeQL
#135:
Pull request
#1127
synchronize by
vharseko
36m 25s
vharseko:fix/sensitive-token-logging
vharseko:fix/sensitive-token-logging
36m 25s
View #1127
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#134:
Pull request
#1131
synchronize by
vharseko
29m 47s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
29m 47s
View #1131
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#133:
Pull request
#1128
synchronize by
vharseko
14m 57s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
14m 57s
View #1128
View workflow file
Do not log session ids, access tokens and password attributes
CodeQL
#132:
Pull request
#1127
synchronize by
vharseko
18m 25s
vharseko:fix/sensitive-token-logging
vharseko:fix/sensitive-token-logging
18m 25s
View #1127
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#131:
Pull request
#1131
synchronize by
vharseko
28m 25s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
28m 25s
View #1131
View workflow file
Previous
1
2
3
4
5
6
7
Next
You can’t perform that action at this time.