Mathias Vorreiter Pedersen
|
295e022df3
|
Merge branch 'main' into improve-tainted-arithmetic
|
2021-06-23 15:45:18 +02:00 |
|
Ian Lynagh
|
089e4e2e1e
|
Merge pull request #6147 from AlexDenisov/adjust_test_expectation
C++: Adjust test expectations after frontend upgrade
|
2021-06-23 14:43:47 +01:00 |
|
Alex Denisov
|
653afc8448
|
C++: Adjust test expectations after frontend upgrade
|
2021-06-23 14:39:16 +02:00 |
|
Mathias Vorreiter Pedersen
|
c44475458e
|
Update cpp/ql/src/Security/CWE/CWE-190/Bounded.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-06-23 14:38:36 +02:00 |
|
Mathias Vorreiter Pedersen
|
6379463bcf
|
Merge branch 'main' into improve-tainted-arithmetic
|
2021-06-23 11:42:45 +02:00 |
|
Geoffrey White
|
298f70f082
|
Merge pull request #6120 from MathiasVP/not-overflow-is-barrier-in-cwe-190
C++: Recognize any non-overflowing arithmetic expression as a barrier for `cpp/uncontrolled-arithmetic`
|
2021-06-23 10:35:33 +01:00 |
|
Mathias Vorreiter Pedersen
|
9b94f3a650
|
Merge branch 'main' into improve-tainted-arithmetic
|
2021-06-23 11:04:08 +02:00 |
|
Mathias Vorreiter Pedersen
|
a611e76ed2
|
C++: Respond to review comments.
|
2021-06-23 10:28:00 +02:00 |
|
Mathias Vorreiter Pedersen
|
3bc6b11ae5
|
C++: Share the 'bounded' predicate from 'cpp/uncontrolled-arithmetic' and use it in 'cpp/tainted-arithmetic'.
|
2021-06-21 16:38:17 +02:00 |
|
Mathias Vorreiter Pedersen
|
05389bb9d4
|
Merge pull request #6099 from geoffw0/weak-crypto3
Further improvements to cpp/weak-cryptographic-algorithm
|
2021-06-21 15:46:50 +02:00 |
|
Geoffrey White
|
05ed4ed739
|
Update cpp/change-notes/2021-06-21-weak-cryptographic-algorithm.md
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-06-21 14:22:56 +01:00 |
|
Mathias Vorreiter Pedersen
|
238c483e5b
|
C++: Make any non-overflowing arithmetic operation a barrier.
|
2021-06-21 14:05:34 +02:00 |
|
Mathias Vorreiter Pedersen
|
18e5d3cce8
|
C++: Add false positive with multiplication.
|
2021-06-21 14:04:27 +02:00 |
|
Geoffrey White
|
6f808c9e4c
|
C++: Update change note.
|
2021-06-21 12:32:48 +01:00 |
|
Geoffrey White
|
79198974dc
|
Merge branch 'main' into weak-crypto3
|
2021-06-21 11:55:29 +01:00 |
|
Anders Schack-Mulligen
|
9110dfaeb3
|
Merge pull request #6095 from hvitved/dataflow/local-cc-join
Data flow: Fix `getLocalCallContext` join-order
|
2021-06-21 12:53:38 +02:00 |
|
Geoffrey White
|
90e2a2d222
|
C++: Change note.
|
2021-06-21 11:30:12 +01:00 |
|
Mathias Vorreiter Pedersen
|
17df8e44d0
|
C++: Convert 'cpp/tainted-arithmetic' to a 'path-problem' query.
|
2021-06-18 14:56:17 +02:00 |
|
Calum Grant
|
32f6a465b0
|
Merge pull request #6080 from github/calumgrant/security-severities
Update security-severity scores
|
2021-06-18 09:40:40 +01:00 |
|
Tom Hvitved
|
eb86bceb4d
|
Address review comments
|
2021-06-18 10:18:47 +02:00 |
|
Geoffrey White
|
b4cbe6dce8
|
C++: Increase query precision to high.
|
2021-06-17 14:33:17 +01:00 |
|
Geoffrey White
|
b5c71fd1d7
|
C++: Repair funcion call in a function call.
|
2021-06-17 14:33:16 +01:00 |
|
Geoffrey White
|
e5147c2a1f
|
C++: Exclude functions that don't involve buffers.
|
2021-06-17 14:33:16 +01:00 |
|
Geoffrey White
|
a481e5c292
|
C++: Exclude template code.
|
2021-06-17 12:36:14 +01:00 |
|
Geoffrey White
|
8efdf359dc
|
C++: Fix some incorrect uses of 'const' in the tests.
|
2021-06-17 12:36:13 +01:00 |
|
Geoffrey White
|
3641cdcc1f
|
C++: Add a test case involving an array.
|
2021-06-17 12:36:09 +01:00 |
|
Geoffrey White
|
23db21cd90
|
C++: Test spacing.
|
2021-06-17 12:33:31 +01:00 |
|
Geoffrey White
|
d590952aaa
|
C++: Add a test case involving nested function calls.
|
2021-06-17 12:23:18 +01:00 |
|
Geoffrey White
|
7632c9edb5
|
C++: Add test cases involving strings and comparisons.
|
2021-06-17 12:23:17 +01:00 |
|
Geoffrey White
|
2e236dd2a9
|
C++: Add a test case involving a harmless assert.
|
2021-06-17 12:23:17 +01:00 |
|
Geoffrey White
|
dca397dfb1
|
C++: Add a test case with a template class.
|
2021-06-17 12:23:16 +01:00 |
|
Anders Schack-Mulligen
|
b173b4141d
|
Merge pull request #6096 from smowton/smowton/fix/inline-expectations-missing-prefix
Inline expectation tests: accept // $MISSING: and // $SPURIOUS:
|
2021-06-17 11:41:15 +02:00 |
|
Chris Smowton
|
558813acf7
|
Inline expectation tests: accept // $MISSING: and // $SPURIOUS:
Previously there had to be a space after the $ token, unlike ordinary expectations (i.e., // $xss was already accepted)
|
2021-06-17 09:44:39 +01:00 |
|
Tom Hvitved
|
ffb2350a54
|
Data flow: Fix getLocalCallContext join-order
|
2021-06-17 10:02:31 +02:00 |
|
Tom Hvitved
|
cc383e0f6a
|
Data flow: Workaround for too clever compiler in consistency queries
|
2021-06-17 09:43:36 +02:00 |
|
Calum Grant
|
771e686946
|
Update security-severity scores
|
2021-06-15 13:25:17 +01:00 |
|
Cornelius Riemenschneider
|
0ebf53b9df
|
Merge pull request #6073 from geoffw0/loc
C++: Add lines of user code query
|
2021-06-15 09:18:46 +02:00 |
|
Geoffrey White
|
d7db18213d
|
C++: Add a generated file to the test.
|
2021-06-14 16:21:30 +01:00 |
|
Geoffrey White
|
1e1ae27974
|
C++: Test the new query.
|
2021-06-14 16:06:20 +01:00 |
|
Geoffrey White
|
e71264d1d2
|
C++: Lines of user code query.
|
2021-06-14 16:03:16 +01:00 |
|
Jonas Jensen
|
e23b88b7f1
|
Merge pull request #6052 from jsinglet/jsinglet/stdtypes
Implementation of standard C/C++ fixed width, minimum width, and maximum width types
|
2021-06-11 17:03:01 +02:00 |
|
John L. Singleton
|
8c6c011be2
|
Formatting fixes, comment moving.
|
2021-06-11 10:17:05 -04:00 |
|
John L. Singleton
|
9c946a79c7
|
Update cpp/change-notes/2021-06-10-std-types.md
Co-authored-by: Jonas Jensen <jbj@github.com>
|
2021-06-11 09:49:44 -04:00 |
|
John L. Singleton
|
cd61fb4753
|
this should be abstract
|
2021-06-10 19:54:58 -04:00 |
|
John L. Singleton
|
219dc71ae6
|
changlog entry
|
2021-06-10 17:15:06 -04:00 |
|
John L. Singleton
|
2a01324172
|
more maintainable pattern for class abstractions
|
2021-06-10 17:09:32 -04:00 |
|
Calum Grant
|
a594afb828
|
Add security-severity metadata
|
2021-06-10 20:11:08 +01:00 |
|
John L. Singleton
|
bd7c416356
|
comment change
|
2021-06-10 11:21:11 -04:00 |
|
John L. Singleton
|
0d3f53b013
|
Changes to structure per feedback of @jbj
|
2021-06-10 11:16:58 -04:00 |
|
John L. Singleton
|
f174d7a0e0
|
Comment changes
|
2021-06-10 09:52:22 -04:00 |
|