Merge pull request #16725 from MathiasVP/rc-3.14-mergeback

Mergeback from `rc/3.14`
This commit is contained in:
Mathias Vorreiter Pedersen
2024-06-11 17:37:40 +01:00
committed by GitHub
149 changed files with 839 additions and 567 deletions

View File

@@ -1,3 +1,7 @@
## 1.0.1
No user-facing changes.
## 1.0.0
### Breaking Changes

View File

@@ -0,0 +1,3 @@
## 1.0.1
No user-facing changes.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.0.0
lastReleaseVersion: 1.0.1

View File

@@ -1,5 +1,5 @@
name: codeql/java-automodel-queries
version: 1.0.1-dev
version: 1.0.2-dev
groups:
- java
- automodel

View File

@@ -1,3 +1,13 @@
## 1.1.0
### Major Analysis Improvements
* The precision of virtual dispatch has been improved. This increases precision in general for all data flow queries.
### Minor Analysis Improvements
* Support for Eclipse Compiler for Java (ecj) has been fixed to work with (a) runs that don't pass `-noExit` and (b) runs that use post-Java-9 command-line arguments.
## 1.0.0
### Breaking Changes

View File

@@ -1,4 +0,0 @@
---
category: majorAnalysis
---
* The precision of virtual dispatch has been improved. This increases precision in general for all data flow queries.

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Support for Eclipse Compiler for Java (ecj) has been fixed to work with (a) runs that don't pass `-noExit` and (b) runs that use post-Java-9 command-line arguments.

View File

@@ -0,0 +1,9 @@
## 1.1.0
### Major Analysis Improvements
* The precision of virtual dispatch has been improved. This increases precision in general for all data flow queries.
### Minor Analysis Improvements
* Support for Eclipse Compiler for Java (ecj) has been fixed to work with (a) runs that don't pass `-noExit` and (b) runs that use post-Java-9 command-line arguments.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.0.0
lastReleaseVersion: 1.1.0

View File

@@ -1,5 +1,5 @@
name: codeql/java-all
version: 1.0.1-dev
version: 1.1.1-dev
groups: java
dbscheme: config/semmlecode.dbscheme
extractor: java

View File

@@ -1,3 +1,10 @@
## 1.0.1
### Minor Analysis Improvements
* The query `java/spring-disabled-csrf-protection` detects disabling CSRF via `ServerHttpSecurity$CsrfSpec::disable`.
* Added more `java.io.File`-related sinks to the path injection query.
## 1.0.0
### Breaking Changes

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* Added more `java.io.File`-related sinks to the path injection query.

View File

@@ -1,4 +0,0 @@
---
category: minorAnalysis
---
* The query `java/spring-disabled-csrf-protection` detects disabling CSRF via `ServerHttpSecurity$CsrfSpec::disable`.

View File

@@ -0,0 +1,6 @@
## 1.0.1
### Minor Analysis Improvements
* The query `java/spring-disabled-csrf-protection` detects disabling CSRF via `ServerHttpSecurity$CsrfSpec::disable`.
* Added more `java.io.File`-related sinks to the path injection query.

View File

@@ -1,2 +1,2 @@
---
lastReleaseVersion: 1.0.0
lastReleaseVersion: 1.0.1

View File

@@ -1,5 +1,5 @@
name: codeql/java-queries
version: 1.0.1-dev
version: 1.0.2-dev
groups:
- java
- queries