Geoffrey White
|
3bf0d66d6c
|
Merge pull request #13906 from geoffw0/commandinject2
Swift: Add tests and develop command injection query
|
2023-09-13 08:59:06 +01:00 |
|
Robert Marsh
|
4b970ff774
|
Swift: update models for array/collection content
|
2023-09-12 19:20:22 +00:00 |
|
Robert Marsh
|
3b7295b0fd
|
Swift: unify ArrayContent and CollectionContent
|
2023-09-12 19:12:44 +00:00 |
|
Robert Marsh
|
53ad559da5
|
Swift: fix for-try-await CFG
|
2023-09-12 19:04:30 +00:00 |
|
Robert Marsh
|
ecf1d98ce5
|
Merge pull request #14165 from rdmarsh2/rdmarsh2/swift/keypath-write-flow
Swift: flow through writeable keypaths
|
2023-09-12 14:24:40 -04:00 |
|
Robert Marsh
|
c2868fe05a
|
Swift: change note for keypath write dataflow
|
2023-09-12 15:53:50 +00:00 |
|
Robert Marsh
|
47ac54bb81
|
Swift: autoformat DataFlowPrivate
|
2023-09-12 15:52:53 +00:00 |
|
Alex Denisov
|
743fd902a1
|
Swift: fix CFG for identity expressions (await, dot_self, parent)
|
2023-09-12 16:04:45 +02:00 |
|
Geoffrey White
|
ae0fcf791b
|
Swift: Expand the additional taint step from the cleartext storage database query to the other sensitive data queries.
|
2023-09-11 22:25:17 +01:00 |
|
Geoffrey White
|
e038f60640
|
Swift: Convert some sinks to CSV.
|
2023-09-11 14:54:32 +01:00 |
|
Geoffrey White
|
7d05446483
|
Swift: Formatting.
|
2023-09-11 14:11:11 +01:00 |
|
Geoffrey White
|
1cde183005
|
Merge branch 'main' into logfix
|
2023-09-11 13:14:58 +01:00 |
|
Geoffrey White
|
3fd5de83cb
|
Merge branch 'main' into sqlpathinject
|
2023-09-11 12:42:49 +01:00 |
|
github-actions[bot]
|
d699880c86
|
Post-release preparation for codeql-cli-2.14.4
|
2023-09-08 21:17:52 +00:00 |
|
Robert Marsh
|
988a871999
|
Swift: add flow through for-in loops
|
2023-09-08 20:00:27 +00:00 |
|
Robert Marsh
|
a3e250aef5
|
Swift: extract iterator variable for for-in loops
|
2023-09-08 19:08:57 +00:00 |
|
Robert Marsh
|
50d23f145b
|
merge main into for-in getnextcall branch
|
2023-09-08 15:51:27 +00:00 |
|
Robert Marsh
|
161e5a4ca2
|
Merge branch 'main' into rdmarsh2/swift/keypath-write-flow
|
2023-09-08 15:39:06 +00:00 |
|
Robert Marsh
|
1082b1d4d1
|
Swift: use PostUpdateNodeImpl for more postupdate nodes
|
2023-09-08 15:19:46 +00:00 |
|
Robert Marsh
|
0d79158bb1
|
Swift: remove TODOs after deciding not to do them
|
2023-09-07 20:15:12 +00:00 |
|
Robert Marsh
|
4f4491a876
|
Swift: autoformat
|
2023-09-07 16:14:05 +00:00 |
|
Robert Marsh
|
5fe942e642
|
Swift: flow through writeable keypaths
|
2023-09-07 15:56:44 +00:00 |
|
Robert Marsh
|
5bdd9597d2
|
Merge branch 'main' into rdmarsh2/swift/dictionary-flow-tuples
|
2023-09-06 14:50:16 +00:00 |
|
github-actions[bot]
|
abf2b12b1c
|
Release preparation for version 2.14.4
|
2023-09-05 16:56:14 +00:00 |
|
Geoffrey White
|
0cb00c9091
|
Swift: Change note.
|
2023-08-31 15:50:54 +01:00 |
|
Geoffrey White
|
93c39c5fdd
|
Swift: Add data flow through OpenExistentialExpr.
|
2023-08-31 15:50:32 +01:00 |
|
Tom Hvitved
|
9af706c2a5
|
Swift: Use data flow consistency checks from shared pack
|
2023-08-30 15:29:41 +02:00 |
|
Mathias Vorreiter Pedersen
|
6a21fa04cd
|
Merge pull request #14034 from geoffw0/hostname
Swift: New query: Incomplete regular expression for hostnames
|
2023-08-30 11:33:36 +01:00 |
|
Dave Bartolomeo
|
3343b78015
|
Merge pull request #14074 from github/post-release-prep/codeql-cli-2.14.3
Post-release preparation for codeql-cli-2.14.3
|
2023-08-28 13:34:10 -04:00 |
|
github-actions[bot]
|
3eba77421a
|
Post-release preparation for codeql-cli-2.14.3
|
2023-08-28 15:53:49 +00:00 |
|
Mathias Vorreiter Pedersen
|
2fd627b460
|
Merge pull request #13827 from geoffw0/closuremodels
Swift: Model withUnsafeBytes and similar closure methods
|
2023-08-25 10:01:52 +01:00 |
|
Geoffrey White
|
46fc1fdaa1
|
Swift: Suggestions from review.
|
2023-08-23 14:04:56 +01:00 |
|
Geoffrey White
|
15c49eeee9
|
Update swift/ql/lib/codeql/swift/regex/Regex.qll
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2023-08-23 13:58:05 +01:00 |
|
Geoffrey White
|
efcadbda69
|
Swift: Get the IncompleteHostnameRegex query working for Swift.
|
2023-08-23 10:32:10 +01:00 |
|
Geoffrey White
|
6deaf4e5f8
|
Swift: Rework ParsedStringRegex and introduce the needed RegexPatternSource class.
|
2023-08-23 09:01:15 +01:00 |
|
Geoffrey White
|
6fb1058e73
|
Swift: Copy IncompleteHostnameRegex query from JS.
|
2023-08-23 08:46:13 +01:00 |
|
Alex Denisov
|
e9fdbfabea
|
Swift: extract nextCall from ForEachStmt
|
2023-08-22 17:36:40 +02:00 |
|
Robert Marsh
|
5734e475d4
|
Merge pull request #14014 from rdmarsh2/rdmarsh2/swift/keypath-force-steps
Swift: flow through keypath optional components
|
2023-08-22 10:35:36 -04:00 |
|
Robert Marsh
|
e94781fa8f
|
Swift: fix comment
|
2023-08-22 13:27:17 +00:00 |
|
Michael Nebel
|
ce6fd8ac5f
|
Merge pull request #13432 from michaelnebel/updateissupported
Java/C#: Update telemetry queries to report callables with sink/source neutrals as being supported.
|
2023-08-22 08:39:38 +02:00 |
|
Robert Marsh
|
a335ece5e5
|
Swift: change note for keypath optional flows
|
2023-08-21 20:11:37 +00:00 |
|
Robert Marsh
|
1634fa2e25
|
Swift: support for optional chaining in keypaths
|
2023-08-21 20:09:28 +00:00 |
|
Robert Marsh
|
246d5c530e
|
Swift: flow through keypath force components
|
2023-08-21 19:07:40 +00:00 |
|
Geoffrey White
|
f7776f812c
|
Swift: 'good enough' fix for UnsafeJsEval flow.
|
2023-08-21 18:30:30 +01:00 |
|
Geoffrey White
|
317757b7ae
|
Swift: Create proper models for JavaScriptCore.
|
2023-08-21 18:24:26 +01:00 |
|
Geoffrey White
|
a54747f850
|
Swift: Fix mysterious taint flow issue.
|
2023-08-21 11:06:04 +01:00 |
|
Geoffrey White
|
b4db68af80
|
Swift: Add content to the string models.
|
2023-08-21 10:16:40 +01:00 |
|
Michael Nebel
|
106ba11e10
|
Address review comments.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
d66fe08661
|
Add QLDoc for the getKind predicate.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
a9f7994b7d
|
Swift: Sync files and make manual changes.
|
2023-08-21 09:59:01 +02:00 |
|