am0o0
|
b5e7716579
|
remove flow states, remove string as sources
|
2024-07-28 11:26:18 +02:00 |
|
am0o0
|
46ddddc8cf
|
Merge tag 'codeql-cli/v2.18.1' into amammad-java-JWT
Compatible with CodeQL CLI 2.18.1
|
2024-07-28 11:23:20 +02:00 |
|
am0o0
|
85b02b1399
|
use MethodCall instead of MethodAccess, change query id
|
2024-07-28 10:42:44 +02:00 |
|
am0o0
|
494f0b709e
|
Merge branch 'main' into amammad-java-JWT
|
2024-07-28 10:37:26 +02:00 |
|
am0o0
|
14cf47b906
|
comply with PascalCase/camelCase, remove redundant import
|
2024-07-28 10:28:28 +02:00 |
|
Daniel Winther Petersen
|
1c1ba7734f
|
Now alerts about exposing exception.getMessage() in servlet responses are split out of java/stack-trace-exposure into its own alert java/error-message-exposure because this is a better fit.
|
2024-07-25 18:12:45 +02:00 |
|
Owen Mansel-Chan
|
4c8da54b64
|
Merge pull request #17036 from chmodxxx/sbaddou/fix
Java: Move SensitiveLoggerConfig source to extensible format
|
2024-07-23 14:55:26 +01:00 |
|
Salah Baddou
|
092de640fe
|
add change-notes
|
2024-07-23 11:04:56 +01:00 |
|
github-actions[bot]
|
49cc8f8ff8
|
Post-release preparation for codeql-cli-2.18.1
|
2024-07-22 22:00:48 +00:00 |
|
github-actions[bot]
|
368bcb684a
|
Release preparation for version 2.18.1
|
2024-07-22 21:30:50 +00:00 |
|
Chuan-kai Lin
|
23320b6e5e
|
Revert "Release preparation for version 2.18.1"
|
2024-07-22 13:22:49 -07:00 |
|
github-actions[bot]
|
55935fc123
|
Release preparation for version 2.18.1
|
2024-07-22 14:56:15 +00:00 |
|
Owen Mansel-Chan
|
9a66e66d66
|
Merge branch 'main' into amammad-java-bombs
|
2024-07-18 21:28:23 +01:00 |
|
am0o0
|
7bb7d83b26
|
remove duplicate sinks
replace some RefType with DecompressionBomb::BombTypeInputStream
|
2024-07-18 20:55:59 +02:00 |
|
Owen Mansel-Chan
|
e6c1ff573a
|
Merge branch 'main' into max-schaefer-patch-1
|
2024-07-18 10:39:42 +01:00 |
|
Owen Mansel-Chan
|
e2356d9820
|
Merge pull request #16914 from owen-mc/java/android-app-detection
Java: Improve Android app detection
|
2024-07-16 21:52:43 +01:00 |
|
am0o0
|
025aa77e79
|
add the snappy missed sink
|
2024-07-13 11:15:45 +02:00 |
|
am0o0
|
8c106964ec
|
remove duplicate parts thanks to @owen-mc
|
2024-07-13 11:11:07 +02:00 |
|
am0o0
|
8ba48e801a
|
fix examples
|
2024-07-13 10:28:19 +02:00 |
|
am0o0
|
dd3cc33298
|
move DecompressionBombsFlow::PathGraph to DecompressionBomb.ql
|
2024-07-13 10:24:07 +02:00 |
|
Am
|
a3b5d2a28d
|
Update java/ql/src/experimental/Security/CWE/CWE-522-DecompressionBombs/DecompressionBomb.qhelp
Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
|
2024-07-13 10:20:43 +02:00 |
|
Am
|
4fbf76008e
|
Update java/ql/src/experimental/Security/CWE/CWE-522-DecompressionBombs/DecompressionBomb.qhelp
Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
|
2024-07-13 10:20:25 +02:00 |
|
Max Schaefer
|
d5d0cf5d90
|
Java: Tag java/non-https-url with CWE-345
|
2024-07-11 13:37:09 +01:00 |
|
am0o0
|
7a5838f1a2
|
MethodAccess => MethodCall
|
2024-07-09 19:43:22 +02:00 |
|
am0o0
|
e87d2fe922
|
remove redundent imports
|
2024-07-09 19:41:06 +02:00 |
|
github-actions[bot]
|
ae3aba061b
|
Post-release preparation for codeql-cli-2.18.0
|
2024-07-08 13:30:13 +00:00 |
|
Angela P Wen
|
dc20b0d19e
|
Merge pull request #16921 from github/release-prep/2.18.0
Release preparation for version 2.18.0
|
2024-07-08 13:12:57 +02:00 |
|
Chris Smowton
|
d9573596c7
|
Merge pull request #16810 from smowton/smowton/feature/java-low-db-quality-query
Java: add diagnostic query indicating low database quality
|
2024-07-08 12:06:42 +01:00 |
|
github-actions[bot]
|
b0d6778652
|
Release preparation for version 2.18.0
|
2024-07-08 09:10:51 +00:00 |
|
Owen Mansel-Chan
|
de5fc4e609
|
Add change notes
|
2024-07-07 00:24:27 +01:00 |
|
am0o0
|
fe1103d997
|
add stubs, upgrade test to inline test, update test files
|
2024-07-04 15:25:36 +02:00 |
|
Michael Nebel
|
25b20186af
|
Merge pull request #16861 from michaelnebel/modelgen/sourcesinklift
C#/Java: Do not lift source and sink models.
|
2024-07-02 08:50:31 +02:00 |
|
am0o0
|
a6833945c1
|
remove additional taint steps and flow states
|
2024-07-01 16:07:44 +02:00 |
|
am0o0
|
d31711bd89
|
merge all ne flow sources into one by extending current abstract class
|
2024-07-01 15:16:44 +02:00 |
|
am0o0
|
f1324a413a
|
update qlhelp
|
2024-07-01 15:09:56 +02:00 |
|
Arthur Baars
|
b12b33c8f9
|
Merge remote-tracking branch 'upstream/main' into 'rc/3.14'
|
2024-06-28 19:50:35 +02:00 |
|
Michael Nebel
|
e23ff3e499
|
Java: Sync files and make language specific implementation.
|
2024-06-27 11:27:08 +02:00 |
|
Chris Smowton
|
80cb908289
|
Amend message
|
2024-06-27 09:57:35 +01:00 |
|
Chris Smowton
|
df860d4128
|
autoformat
|
2024-06-27 09:57:25 +01:00 |
|
Chris Smowton
|
16a90aa180
|
autoformat
|
2024-06-27 09:57:19 +01:00 |
|
Chris Smowton
|
6292cacd74
|
Add link to build modes docs
|
2024-06-27 09:57:13 +01:00 |
|
Chris Smowton
|
d43762cae3
|
Apply suggestions from code review
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com>
Co-authored-by: Chad Bentz <1760475+felickz@users.noreply.github.com>
|
2024-06-27 09:57:07 +01:00 |
|
Chris Smowton
|
f397ab2d72
|
Java: add diagnostic query indicating low database quality
|
2024-06-27 09:57:02 +01:00 |
|
Ian Lynagh
|
f9ae44ca5c
|
Merge pull request #16736 from igfoo/igfoo/debugLoC
Java/Kotlin: Tag the LoC queries 'debug'
|
2024-06-25 22:57:36 +01:00 |
|
Ian Lynagh
|
c12adbeeaa
|
Java/Kotlin: Tag the LoC queries 'debug'
This brings them into line with LinesOfCode.ql
|
2024-06-25 15:46:10 +01:00 |
|
github-actions[bot]
|
fd385736e6
|
Post-release preparation for codeql-cli-2.17.6
|
2024-06-25 06:39:45 +00:00 |
|
github-actions[bot]
|
e32a587078
|
Release preparation for version 2.17.6
|
2024-06-24 14:33:10 +00:00 |
|
Michael Nebel
|
c687dcb094
|
Java: Sync files and make language specific implementation.
|
2024-06-24 13:07:39 +02:00 |
|
Michael Nebel
|
9cd16fd9d6
|
Java: Base the model printing on the shared implementation.
|
2024-06-24 11:52:50 +02:00 |
|
Michael Nebel
|
94d12edfdb
|
Merge pull request #16759 from michaelnebel/modelgen/sourcesinkmodelgen
C#/Java: Introduce source and sink model generation sanitisers.
|
2024-06-24 11:47:11 +02:00 |
|