Merge pull request #20975 from github/oscarsj/merge-back-rc-3.20

Merge back rc/3.20
This commit is contained in:
Óscar San José
2025-12-05 21:16:18 +01:00
committed by GitHub
215 changed files with 719 additions and 147 deletions

View File

@@ -1,3 +1,11 @@
## 0.4.23
No user-facing changes.
## 0.4.22
No user-facing changes.
## 0.4.21
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.4.22
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.4.23
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 0.4.21
lastReleaseVersion: 0.4.23

View File

@@ -1,5 +1,5 @@
name: codeql/actions-all
version: 0.4.22-dev
version: 0.4.24-dev
library: true
warnOnImplicitThis: true
dependencies:

View File

@@ -1,3 +1,11 @@
## 0.6.15
No user-facing changes.
## 0.6.14
No user-facing changes.
## 0.6.13
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.6.14
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 0.6.15
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 0.6.13
lastReleaseVersion: 0.6.15

View File

@@ -1,5 +1,5 @@
name: codeql/actions-queries
version: 0.6.14-dev
version: 0.6.16-dev
library: false
warnOnImplicitThis: true
groups: [actions, queries]

View File

@@ -1,3 +1,13 @@
## 6.1.2
No user-facing changes.
## 6.1.1
### Minor Analysis Improvements
* The class `DataFlow::FieldContent` now covers both `union` and `struct`/`class` types. A new predicate `FieldContent.getAField` has been added to access the union members associated with the `FieldContent`. The old `FieldContent` has been renamed to `NonUnionFieldContent`.
## 6.1.0
### New Features

View File

@@ -1,4 +1,5 @@
---
category: minorAnalysis
---
* The class `DataFlow::FieldContent` now covers both `union` and `struct`/`class` types. A new predicate `FieldContent.getAField` has been added to access the union members associated with the `FieldContent`. The old `FieldContent` has been renamed to `NonUnionFieldContent`.
## 6.1.1
### Minor Analysis Improvements
* The class `DataFlow::FieldContent` now covers both `union` and `struct`/`class` types. A new predicate `FieldContent.getAField` has been added to access the union members associated with the `FieldContent`. The old `FieldContent` has been renamed to `NonUnionFieldContent`.

View File

@@ -0,0 +1,3 @@
## 6.1.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 6.1.0
lastReleaseVersion: 6.1.2

View File

@@ -1,5 +1,5 @@
name: codeql/cpp-all
version: 6.1.1-dev
version: 6.1.3-dev
groups: cpp
dbscheme: semmlecode.cpp.dbscheme
extractor: cpp

View File

@@ -1,3 +1,11 @@
## 1.5.6
No user-facing changes.
## 1.5.5
No user-facing changes.
## 1.5.4
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.5.5
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.5.6
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.5.4
lastReleaseVersion: 1.5.6

View File

@@ -1,5 +1,5 @@
name: codeql/cpp-queries
version: 1.5.5-dev
version: 1.5.7-dev
groups:
- cpp
- queries

View File

@@ -1,3 +1,11 @@
## 1.7.54
No user-facing changes.
## 1.7.53
No user-facing changes.
## 1.7.52
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.53
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.54
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.7.52
lastReleaseVersion: 1.7.54

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-solorigate-all
version: 1.7.53-dev
version: 1.7.55-dev
groups:
- csharp
- solorigate

View File

@@ -1,3 +1,11 @@
## 1.7.54
No user-facing changes.
## 1.7.53
No user-facing changes.
## 1.7.52
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.53
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.54
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.7.52
lastReleaseVersion: 1.7.54

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-solorigate-queries
version: 1.7.53-dev
version: 1.7.55-dev
groups:
- csharp
- solorigate

View File

@@ -1,3 +1,15 @@
## 5.4.2
No user-facing changes.
## 5.4.1
### Minor Analysis Improvements
* Improved stability when downloading .NET versions by setting appropriate environment variables for `dotnet` commands. The correct architecture-specific version of .NET is now downloaded on ARM runners.
* Compilation errors are now included in the debug log when using build-mode none.
* Added a new extractor option to specify a custom directory for dependency downloads in buildless mode. Use `-O buildless_dependency_dir=<path>` to configure the target directory.
## 5.4.0
### Deprecated APIs

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Compilation errors are now included in the debug log when using build-mode none.

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Added a new extractor option to specify a custom directory for dependency downloads in buildless mode. Use `-O buildless_dependency_dir=<path>` to configure the target directory.

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Improved stability when downloading .NET versions by setting appropriate environment variables for `dotnet` commands. The correct architecture-specific version of .NET is now downloaded on ARM runners.

View File

@@ -0,0 +1,7 @@
## 5.4.1
### Minor Analysis Improvements
* Improved stability when downloading .NET versions by setting appropriate environment variables for `dotnet` commands. The correct architecture-specific version of .NET is now downloaded on ARM runners.
* Compilation errors are now included in the debug log when using build-mode none.
* Added a new extractor option to specify a custom directory for dependency downloads in buildless mode. Use `-O buildless_dependency_dir=<path>` to configure the target directory.

View File

@@ -0,0 +1,3 @@
## 5.4.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 5.4.0
lastReleaseVersion: 5.4.2

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-all
version: 5.4.1-dev
version: 5.4.3-dev
groups: csharp
dbscheme: semmlecode.csharp.dbscheme
extractor: csharp

View File

@@ -1,3 +1,11 @@
## 1.5.2
No user-facing changes.
## 1.5.1
No user-facing changes.
## 1.5.0
### New Queries
@@ -180,7 +188,7 @@ No user-facing changes.
### Minor Analysis Improvements
* C#: The method `string.ReplaceLineEndings(string)` is now considered a sanitizer for the `cs/log-forging` query.
* C#: The method `string.ReplaceLineEndings(string)` is now considered a sanitizer for the `cs/log-forging` query.
## 1.0.10

View File

@@ -0,0 +1,3 @@
## 1.5.1
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.5.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.5.0
lastReleaseVersion: 1.5.2

View File

@@ -1,5 +1,5 @@
name: codeql/csharp-queries
version: 1.5.1-dev
version: 1.5.3-dev
groups:
- csharp
- queries

View File

@@ -1,3 +1,11 @@
## 1.0.37
No user-facing changes.
## 1.0.36
No user-facing changes.
## 1.0.35
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.36
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.37
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.0.35
lastReleaseVersion: 1.0.37

View File

@@ -1,5 +1,5 @@
name: codeql-go-consistency-queries
version: 1.0.36-dev
version: 1.0.38-dev
groups:
- go
- queries

View File

@@ -1,3 +1,11 @@
## 5.0.4
No user-facing changes.
## 5.0.3
No user-facing changes.
## 5.0.2
### Bug Fixes

View File

@@ -0,0 +1,3 @@
## 5.0.3
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 5.0.4
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 5.0.2
lastReleaseVersion: 5.0.4

View File

@@ -1,5 +1,5 @@
name: codeql/go-all
version: 5.0.3-dev
version: 5.0.5-dev
groups: go
dbscheme: go.dbscheme
extractor: go

View File

@@ -1,3 +1,16 @@
## 1.5.1
No user-facing changes.
## 1.5.0
### New Queries
* The `go/cookie-http-only-not-set` query has been promoted from the experimental query pack. This query was originally contributed to the experimental query pack by @edvraa.
* A new query `go/cookie-secure-not-set` has been added to detect cookies without the `Secure` flag set.
* Added a new query, `go/weak-crypto-algorithm`, to detect the use of a broken or weak cryptographic algorithm. A very simple version of this query was originally contributed as an [experimental query by @dilanbhalla](https://github.com/github/codeql-go/pull/284).
* Added a new query, `go/weak-sensitive-data-hashing`, to detect the use of a broken or weak cryptographic hash algorithm on sensitive data.
## 1.4.9
No user-facing changes.

View File

@@ -1,5 +0,0 @@
---
category: newQuery
---
* The `go/cookie-http-only-not-set` query has been promoted from the experimental query pack. This query was originally contributed to the experimental query pack by @edvraa.
* A new query `go/cookie-secure-not-set` has been added to detect cookies without the `Secure` flag set.

View File

@@ -1,5 +1,8 @@
---
category: newQuery
---
## 1.5.0
### New Queries
* The `go/cookie-http-only-not-set` query has been promoted from the experimental query pack. This query was originally contributed to the experimental query pack by @edvraa.
* A new query `go/cookie-secure-not-set` has been added to detect cookies without the `Secure` flag set.
* Added a new query, `go/weak-crypto-algorithm`, to detect the use of a broken or weak cryptographic algorithm. A very simple version of this query was originally contributed as an [experimental query by @dilanbhalla](https://github.com/github/codeql-go/pull/284).
* Added a new query, `go/weak-sensitive-data-hashing`, to detect the use of a broken or weak cryptographic hash algorithm on sensitive data.

View File

@@ -0,0 +1,3 @@
## 1.5.1
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.4.9
lastReleaseVersion: 1.5.1

View File

@@ -1,5 +1,5 @@
name: codeql/go-queries
version: 1.4.10-dev
version: 1.5.2-dev
groups:
- go
- queries

View File

@@ -1,3 +1,13 @@
## 7.8.1
No user-facing changes.
## 7.8.0
### Deprecated APIs
* The SSA interface has been updated and all classes and several predicates have been renamed. See the qldoc for more specific migration information.
## 7.7.4
No user-facing changes.

View File

@@ -1,4 +1,5 @@
---
category: deprecated
---
## 7.8.0
### Deprecated APIs
* The SSA interface has been updated and all classes and several predicates have been renamed. See the qldoc for more specific migration information.

View File

@@ -0,0 +1,3 @@
## 7.8.1
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 7.7.4
lastReleaseVersion: 7.8.1

View File

@@ -1,5 +1,5 @@
name: codeql/java-all
version: 7.7.5-dev
version: 7.8.2-dev
groups: java
dbscheme: config/semmlecode.dbscheme
extractor: java

View File

@@ -1,3 +1,13 @@
## 1.10.2
No user-facing changes.
## 1.10.1
### Minor Analysis Improvements
* Operations that extract only a fixed-length prefix or suffix of a string (for example, `substring` in Java or `take` in Kotlin), when limited to a length of at most 7 characters, are now treated as sanitizers for the `java/sensitive-log` query.
## 1.10.0
### Query Metadata Changes

View File

@@ -1,4 +1,5 @@
---
category: minorAnalysis
---
* Operations that extract only a fixed-length prefix or suffix of a string (for example, `substring` in Java or `take` in Kotlin), when limited to a length of at most 7 characters, are now treated as sanitizers for the `java/sensitive-log` query.
## 1.10.1
### Minor Analysis Improvements
* Operations that extract only a fixed-length prefix or suffix of a string (for example, `substring` in Java or `take` in Kotlin), when limited to a length of at most 7 characters, are now treated as sanitizers for the `java/sensitive-log` query.

View File

@@ -0,0 +1,3 @@
## 1.10.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.10.0
lastReleaseVersion: 1.10.2

View File

@@ -1,5 +1,5 @@
name: codeql/java-queries
version: 1.10.1-dev
version: 1.10.3-dev
groups:
- java
- queries

View File

@@ -1,3 +1,13 @@
## 2.6.17
No user-facing changes.
## 2.6.16
### Minor Analysis Improvements
- JavaScript `DataFlow::globalVarRef` now recognizes `document.defaultView` as an alias of `window`, allowing flows such as `document.defaultView.history.pushState(...)` to be modeled and found by queries relying on `globalVarRef("history")`.
## 2.6.15
No user-facing changes.

View File

@@ -1,5 +1,5 @@
---
category: minorAnalysis
---
## 2.6.16
### Minor Analysis Improvements
- JavaScript `DataFlow::globalVarRef` now recognizes `document.defaultView` as an alias of `window`, allowing flows such as `document.defaultView.history.pushState(...)` to be modeled and found by queries relying on `globalVarRef("history")`.

View File

@@ -0,0 +1,3 @@
## 2.6.17
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 2.6.15
lastReleaseVersion: 2.6.17

View File

@@ -1,5 +1,5 @@
name: codeql/javascript-all
version: 2.6.16-dev
version: 2.6.18-dev
groups: javascript
dbscheme: semmlecode.javascript.dbscheme
extractor: javascript

View File

@@ -1,3 +1,13 @@
## 2.2.2
No user-facing changes.
## 2.2.1
### Minor Analysis Improvements
* Fixed a bug in the Next.js model that would cause the analysis to miss server-side taint sources in the `app/pages` folder.
## 2.2.0
### Query Metadata Changes

View File

@@ -1,4 +1,5 @@
---
category: minorAnalysis
---
## 2.2.1
### Minor Analysis Improvements
* Fixed a bug in the Next.js model that would cause the analysis to miss server-side taint sources in the `app/pages` folder.

View File

@@ -0,0 +1,3 @@
## 2.2.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 2.2.0
lastReleaseVersion: 2.2.2

View File

@@ -1,5 +1,5 @@
name: codeql/javascript-queries
version: 2.2.1-dev
version: 2.2.3-dev
groups:
- javascript
- queries

View File

@@ -1,3 +1,11 @@
## 1.0.37
No user-facing changes.
## 1.0.36
No user-facing changes.
## 1.0.35
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.36
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.0.37
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.0.35
lastReleaseVersion: 1.0.37

View File

@@ -1,4 +1,4 @@
name: codeql/suite-helpers
version: 1.0.36-dev
version: 1.0.38-dev
groups: shared
warnOnImplicitThis: true

View File

@@ -1,3 +1,13 @@
## 5.0.2
No user-facing changes.
## 5.0.1
### Bug Fixes
- Fixed a bug in the Python extractor's import handling where failing to find an import in `find_module` would cause a `KeyError` to be raised. (Contributed by @akoeplinger.)
## 5.0.0
### Breaking Changes

View File

@@ -1,5 +1,5 @@
---
category: fix
---
## 5.0.1
### Bug Fixes
- Fixed a bug in the Python extractor's import handling where failing to find an import in `find_module` would cause a `KeyError` to be raised. (Contributed by @akoeplinger.)

View File

@@ -0,0 +1,3 @@
## 5.0.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 5.0.0
lastReleaseVersion: 5.0.2

View File

@@ -1,5 +1,5 @@
name: codeql/python-all
version: 5.0.1-dev
version: 5.0.3-dev
groups: python
dbscheme: semmlecode.python.dbscheme
extractor: python

View File

@@ -1,3 +1,11 @@
## 1.7.2
No user-facing changes.
## 1.7.1
No user-facing changes.
## 1.7.0
### Query Metadata Changes

View File

@@ -0,0 +1,3 @@
## 1.7.1
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 1.7.2
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.7.0
lastReleaseVersion: 1.7.2

View File

@@ -1,5 +1,5 @@
name: codeql/python-queries
version: 1.7.1-dev
version: 1.7.3-dev
groups:
- python
- queries

View File

@@ -1,3 +1,11 @@
## 5.1.5
No user-facing changes.
## 5.1.4
No user-facing changes.
## 5.1.3
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 5.1.4
No user-facing changes.

View File

@@ -0,0 +1,3 @@
## 5.1.5
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 5.1.3
lastReleaseVersion: 5.1.5

View File

@@ -1,5 +1,5 @@
name: codeql/ruby-all
version: 5.1.4-dev
version: 5.1.6-dev
groups: ruby
extractor: ruby
dbscheme: ruby.dbscheme

View File

@@ -1,3 +1,11 @@
## 1.5.2
No user-facing changes.
## 1.5.1
No user-facing changes.
## 1.5.0
### Query Metadata Changes

Some files were not shown because too many files have changed in this diff Show More