Asger F
|
d9a43dbd85
|
JS: Migrate UnsafeHtmlConstruction
|
2024-12-13 10:08:17 +01:00 |
|
Asger F
|
8907252814
|
JS: Migrate TemplateObjectInjection
|
2024-12-13 10:08:16 +01:00 |
|
Asger F
|
3573f0b065
|
JS: Migrate SecondOrderCommandInjection
|
2024-12-13 10:08:15 +01:00 |
|
Asger F
|
355f7cdd54
|
JS: Migrate PrototypePollutingMergeCall
|
2024-12-13 10:08:13 +01:00 |
|
Asger F
|
c38e3a23eb
|
JS: Migrate NoSqlInjection
|
2024-12-13 10:08:12 +01:00 |
|
Asger F
|
8e8de5cf23
|
JS: Migrate LoopBoundInjection
|
2024-12-13 10:08:11 +01:00 |
|
Asger F
|
daddff0dc6
|
JS: Avoid deprecation warning in XssThroughDom
|
2024-12-13 10:08:10 +01:00 |
|
Asger F
|
15d999a9dc
|
JS: Migrate DeepObjectResourceExhaustion
|
2024-12-13 10:08:09 +01:00 |
|
Asger F
|
5f42a715f6
|
JS: Migrate TaintedObject to a CommonFlowState
|
2024-12-13 10:08:08 +01:00 |
|
Asger F
|
14ca1c134b
|
JS: Update TaintedUrlSuffix test
|
2024-12-13 10:08:07 +01:00 |
|
Asger F
|
12289d4c39
|
JS: Migrate DomBasedXssQuery to FlowState
|
2024-12-13 10:08:06 +01:00 |
|
Asger F
|
114d4a141a
|
JS: Move FlowState definition into CommonFlowState
Needed for migrating the XSS query
|
2024-12-13 10:08:05 +01:00 |
|
Asger F
|
3cf14d8506
|
JS: Migrate ClientSideUrlRedirect to flow state
|
2024-12-13 10:08:03 +01:00 |
|
Asger F
|
cca980298f
|
JS: Use flow state in barrier and step relations
|
2024-12-13 10:08:02 +01:00 |
|
Asger F
|
a8fdd759f9
|
JS: Add FlowState class to TaintedUrlSuffix
|
2024-12-13 10:08:01 +01:00 |
|
Paolo Tranquilli
|
92ec7e89ab
|
Merge branch 'main' into redsun82/swift-6
|
2024-12-13 09:38:15 +01:00 |
|
Ed Minnix
|
68e2f27180
|
Add summary Microsoft.AspNetCore.Components.CompilerServices.RuntimeHelpers::TypeCheck<T>
|
2024-12-12 22:10:15 -05:00 |
|
Ed Minnix
|
8e37a5cd55
|
Fix test case
|
2024-12-12 22:05:26 -05:00 |
|
Owen Mansel-Chan
|
b58e6ebade
|
Address review comments for localTaintStep
|
2024-12-12 22:07:15 +00:00 |
|
Ed Minnix
|
0a967325e7
|
Change note
|
2024-12-12 16:22:09 -05:00 |
|
Ed Minnix
|
40ea5f582c
|
MarkupString models
|
2024-12-12 16:18:29 -05:00 |
|
Jeroen Ketema
|
792504434a
|
Merge pull request #18277 from jketema/printast
C++: Fix small PrintAST and PrintIR issue
|
2024-12-12 19:17:43 +01:00 |
|
Jeroen Ketema
|
8e458f4651
|
C++: Simplify local variable names
|
2024-12-12 17:13:02 +01:00 |
|
Joe Farebrother
|
dcbcf7e2bd
|
Add additional tests demonstrating false negative flow
|
2024-12-12 15:55:36 +00:00 |
|
Jeroen Ketema
|
f9bfd969a9
|
C++: Address review comments
|
2024-12-12 16:49:24 +01:00 |
|
Simon Friis Vindum
|
1d8e7fd9ea
|
Rust: Accept differences
|
2024-12-12 16:47:51 +01:00 |
|
Simon Friis Vindum
|
0fa40fcdcc
|
Rust: Fix captured variable data flow inconsistency
|
2024-12-12 16:28:19 +01:00 |
|
Asger F
|
a53d294d91
|
Merge pull request #18203 from asgerf/jss/document-url
JS: Use TaintedUrlSuffix in ClientSideUrlRedirect
|
2024-12-12 15:47:51 +01:00 |
|
Tom Hvitved
|
20db548fef
|
Merge pull request #18263 from hvitved/dataflow/remove-column
Data flow: Remove unused column from `flowThroughOutOfCall`
|
2024-12-12 15:41:20 +01:00 |
|
Geoffrey White
|
03f962ed86
|
Merge pull request #18226 from geoffw0/badcrypto
Rust: Weak encryption algorithm query.
|
2024-12-12 14:21:16 +00:00 |
|
Michael Nebel
|
a52a549945
|
Merge pull request #18246 from michaelnebel/csharp/fixwarnings
C#: Fix some new compiler warnings
|
2024-12-12 15:07:23 +01:00 |
|
Michael Nebel
|
0bfc1b6ea8
|
Also move the postprocessing queries to the library pack.
|
2024-12-12 15:03:03 +01:00 |
|
Michael Nebel
|
941b0abbf6
|
Move modules to the library packs.
|
2024-12-12 15:03:01 +01:00 |
|
Michael Nebel
|
864c34fc03
|
Rust: Update all test util paths to point to the new location.
|
2024-12-12 15:02:59 +01:00 |
|
Tom Hvitved
|
5d18e23979
|
Merge pull request #18269 from hvitved/csharp/dataflow-reflection-call
C#: Remove false-positive reflection calls in dataflow
|
2024-12-12 14:43:13 +01:00 |
|
Owen Mansel-Chan
|
26b52078c0
|
Add change note
|
2024-12-12 13:41:35 +00:00 |
|
Owen Mansel-Chan
|
8703e21f62
|
Merge pull request #17996 from owen-mc/java/lightweight-IR-layer-classes
Java: Make separate classes for different control flow node kinds
|
2024-12-12 13:36:54 +00:00 |
|
Geoffrey White
|
44a0ad2942
|
Update data-flow -> data flow in all versions of ConceptsShared.qll.
|
2024-12-12 13:36:26 +00:00 |
|
Michael Nebel
|
9c0dddb4d8
|
Merge pull request #18267 from michaelnebel/csharp/updateglobaljson
C#: Update global.json for cshtml_standalone_flowsteps.
|
2024-12-12 13:55:03 +01:00 |
|
Michael Nebel
|
cbae2cf7fa
|
Rust: Move test utilities into the query pack.
|
2024-12-12 13:54:42 +01:00 |
|
Michael Nebel
|
9ecacddf79
|
Swift: Update all test util paths to point to the new location.
|
2024-12-12 13:54:40 +01:00 |
|
Michael Nebel
|
ca66153a3b
|
Swift: Move test utilities into the query pack.
|
2024-12-12 13:54:38 +01:00 |
|
Michael Nebel
|
138e294dae
|
Ruby: Update all test util paths to point to the new location.
|
2024-12-12 13:54:37 +01:00 |
|
Michael Nebel
|
157afff135
|
Ruby: Move test utilities into the query pack.
|
2024-12-12 13:54:35 +01:00 |
|
Michael Nebel
|
2ca6147932
|
QL: Update all test util paths to point to the new location.
|
2024-12-12 13:54:33 +01:00 |
|
Michael Nebel
|
dd06d50b7f
|
QL: Move test utilities into the src folder.
|
2024-12-12 13:54:32 +01:00 |
|
Michael Nebel
|
2321ca59f6
|
Python: Update all test util paths to point to the new location.
|
2024-12-12 13:54:30 +01:00 |
|
Michael Nebel
|
1490400ab0
|
Python: Move test utilities into the query pack.
|
2024-12-12 13:54:28 +01:00 |
|
Michael Nebel
|
c3fe3e468c
|
Javascript: Update all test util paths to point to the new location.
|
2024-12-12 13:54:25 +01:00 |
|
Michael Nebel
|
0f146f1486
|
Javascript: Move test utilities into the query pack.
|
2024-12-12 13:54:23 +01:00 |
|