From 4514fd4e9bf02f2d83901777223ad17f83bf05e1 Mon Sep 17 00:00:00 2001 From: Max Schaefer Date: Thu, 2 May 2024 09:04:40 +0100 Subject: [PATCH] Temporarily remove all jackson-databind sources and sinks. --- java/ql/lib/ext/com.fasterxml.jackson.databind.model.yml | 6 ------ 1 file changed, 6 deletions(-) diff --git a/java/ql/lib/ext/com.fasterxml.jackson.databind.model.yml b/java/ql/lib/ext/com.fasterxml.jackson.databind.model.yml index 4262a30b31c..8a1e4587bb1 100644 --- a/java/ql/lib/ext/com.fasterxml.jackson.databind.model.yml +++ b/java/ql/lib/ext/com.fasterxml.jackson.databind.model.yml @@ -11,9 +11,3 @@ extensions: - ["com.fasterxml.jackson.databind", "ObjectMapper", True, "valueToTree", "", "", "Argument[0].MapValue", "ReturnValue", "taint", "manual"] - ["com.fasterxml.jackson.databind", "ObjectMapper", True, "valueToTree", "", "", "Argument[0].MapValue.Element", "ReturnValue", "taint", "manual"] - ["com.fasterxml.jackson.databind", "ObjectReader", False, "createParser", "", "", "Argument[0]", "ReturnValue", "taint", "manual"] - - addsTo: - pack: codeql/java-all - extensible: sinkModel - data: - - ["com.fasterxml.jackson.databind", "ObjectMapper", True, "readValue", "(File,Class)", "", "Argument[0]", "path-injection", "ai-manual"] - - ["com.fasterxml.jackson.databind", "ObjectMapper", True, "writeValue", "(File,Object)", "", "Argument[0]", "path-injection", "ai-manual"]