
Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022
Prerequisites • Resources • Workshop
You can choose between two options to run the workshop exercises:
Use a local CodeQL installation to work on the workshop exercises.
git installed on your local machine.git clone https://github.com/sylwia-budzynska/codeql-workshop
cd codeql-workshop
git submodule init
git submodule update --recursive --depth 1
# Download CodeQL databases
curl -L -O "https://github.com/sylwia-budzynska/codeql-workshop/releases/download/v1/test-app-db.zip"
curl -L -O "https://github.com/sylwia-budzynska/codeql-workshop/releases/download/v1/kohya_ss-db.zip"
vscode-codeql-starter.code-workspaceUse a remote GitHub Codespace to work on the workshop exercises.
Note: The first 120 hours per core of Codespace usage are free per month, we use a codespace with 4 cores for this workshop since 4 cores is the current maximum for free accounts. (If you have a Pro account, we recommend switching to an 8-core machine.)
VS Code will start in your browser and a remote Codespace will be built. This may take a few minutes.
If you are asked to open the workspace vscode-codeql-starter.code-workspace click on "Open Workspace".
You can see your codespaces on at github.com/codespaces. The codespace will turn off on its own after a few hours of not using it, but to ensure you are not using additional hours of the 120h free ones, remember to go to github.com/codespaces > three dots > "Stop codespace" after the workshop.
In case you see errors such as:
Failed to run query: Could not resolve library path for [..]Could not resolve module [..]Could not resolve type [..]It is very likely that you missed cloning the git submodules (namely the ql repo). To fix this run git submodule init && git submodule update --recursive.
vscode-codeql-starter.code-workspace open in VS Code.test-app-db.zip file in the root of the repository.
Note: At this point you may encounter an error in VSCode with a pop-up message asking to install the CodeQL CLI. Accepting this install should fix the issue. After the CLI install finishes, you should be able to then complete the above database selection.

Make sure that the previously chosen CodeQL database is selected in the CodeQL view. (Click on "Select" if it's not)
When the database is selected it should look like this (note the checkmark):
codeql-custom-queries-pythontest.qlselect "Hello World!"Welcome to the workshop "Finding vunlnerabilities with CodeQL"!