Tag all security queries in supported languages' experimental directories with an experimental tag

This commit is contained in:
turbo
2022-12-14 17:15:50 +01:00
parent a92acf5218
commit 4ec401a3f6
148 changed files with 155 additions and 3 deletions

View File

@@ -7,6 +7,7 @@
* @precision medium
* @id rb/user-controlled-bypass
* @tags security
* experimental
* external/cwe/cwe-807
* external/cwe/cwe-290
*/

View File

@@ -6,7 +6,9 @@
* @security-severity 7.8
* @precision medium
* @id rb/user-controlled-file-decompression
* @tags security external/cwe/cwe-409
* @tags security
* experimental
* external/cwe/cwe-409
*/
import codeql.ruby.AST

View File

@@ -5,6 +5,7 @@
* @problem.severity warning
* @precision high
* @tags security
* experimental
* @id rb/improper-memoization
*/

View File

@@ -7,6 +7,7 @@
* @precision low
* @id rb/manually-checking-http-verb
* @tags security
* experimental
*/
import codeql.ruby.AST

View File

@@ -7,6 +7,7 @@
* @precision medium
* @id rb/weak-params
* @tags security
* experimental
*/
import codeql.ruby.AST