Rasmus Lerchedahl Petersen
|
f53314019a
|
Python: test aiopg.sa
|
2021-11-09 12:42:03 +01:00 |
|
Rasmus Lerchedahl Petersen
|
cd332a75fc
|
Python: model aiopg
|
2021-11-09 12:32:21 +01:00 |
|
Rasmus Lerchedahl Petersen
|
cb8f1b4593
|
Python: Add tests for aiopg
|
2021-11-09 11:49:31 +01:00 |
|
Erik Krogh Kristensen
|
8727060ca7
|
add comment about modes of operation
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-11-09 11:15:12 +01:00 |
|
Rasmus Lerchedahl Petersen
|
3f4c2ba24e
|
Python: Support debugging inline taint tests
The module `Conf` is created so that it can be imported
without importing the query predicates from the same file.
|
2021-11-08 14:08:11 +01:00 |
|
jorgectf
|
c0a0c5d811
|
Cover footer and subscription_tracking html injection
|
2021-11-08 10:51:11 +01:00 |
|
jorgectf
|
5774ce2479
|
Improve django test
|
2021-11-08 10:34:16 +01:00 |
|
jorgectf
|
f4a73fcc59
|
Add RFS to sendgrid test
|
2021-11-08 10:33:57 +01:00 |
|
jorgectf
|
d316974157
|
Add HtmlContent additional taint step
|
2021-11-08 10:23:50 +01:00 |
|
jorgectf
|
83e3de1fed
|
Polish documentation.
|
2021-11-05 21:05:33 +01:00 |
|
jorgectf
|
ed74bd6800
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/insecure-cookie
|
2021-11-05 20:14:06 +01:00 |
|
jorgectf
|
86aac7c215
|
Add/Update .expected files.
|
2021-11-05 20:13:12 +01:00 |
|
jorgectf
|
a420e6e18d
|
Add CookieInjection.qlref
|
2021-11-05 20:12:56 +01:00 |
|
jorgectf
|
cf47e8eb9c
|
Fix endpoints' naming
|
2021-11-05 20:12:35 +01:00 |
|
jorgectf
|
b3258ce20f
|
Add CookieInjection sample and .qhelp
|
2021-11-05 20:12:05 +01:00 |
|
jorgectf
|
d7a79469e6
|
Improve tests
|
2021-11-05 20:08:52 +01:00 |
|
jorgectf
|
4cb78ac654
|
Fix typo
|
2021-11-05 20:08:37 +01:00 |
|
Rasmus Lerchedahl Petersen
|
624b794980
|
Python: separate taint sources in with
|
2021-11-04 17:06:36 +01:00 |
|
Rasmus Wriedt Larsen
|
9e2bc41648
|
Python: Improve hashlib.new modeling
By using a backwards type-tracker to find possible hashing algorithm
names.
|
2021-11-04 15:36:32 +01:00 |
|
Rasmus Wriedt Larsen
|
9e91f3a341
|
Python: Highlight shortcomings of hashlib.new modeling
|
2021-11-04 15:29:40 +01:00 |
|
Erik Krogh Kristensen
|
a19627c72f
|
optionally ignore everything after a dash
|
2021-11-04 13:19:44 +01:00 |
|
Erik Krogh Kristensen
|
02f500b9c2
|
Merge branch 'main' into htmlReg
|
2021-11-04 12:58:42 +01:00 |
|
Erik Krogh Kristensen
|
523c15cd72
|
don't include mode-of-operation into the algorithm names
|
2021-11-03 14:54:50 +01:00 |
|
Rasmus Wriedt Larsen
|
84b38b6c32
|
Python: Add test with custom django json response (FP)
|
2021-11-03 14:17:08 +01:00 |
|
Rasmus Lerchedahl Petersen
|
05aa314ac9
|
Python: Add tests for non-async constructs
|
2021-11-03 10:54:36 +01:00 |
|
Mathias Vorreiter Pedersen
|
4a2894a707
|
Merge pull request #7025 from MathiasVP/nomagic-parameterCand
Dataflow: Replace a 'noinline' pragma with a 'nomagic' pragma
|
2021-11-02 20:40:44 +00:00 |
|
Rasmus Wriedt Larsen
|
8cd9fdebf9
|
Python: Model flask_admin
|
2021-11-02 15:43:13 +01:00 |
|
Rasmus Wriedt Larsen
|
ab88d945e2
|
Python: Add flask_admin tests
|
2021-11-02 15:41:57 +01:00 |
|
Rasmus Wriedt Larsen
|
c2632cff3d
|
Python: Add RequestHandler meta query
|
2021-11-02 15:41:57 +01:00 |
|
Rasmus Lerchedahl Petersen
|
768932d7b3
|
Python: Add tainttracking step that was removed
when the correpsonding datadlow step was removed.
|
2021-11-02 15:01:47 +01:00 |
|
Rasmus Lerchedahl Petersen
|
07d5086b07
|
Python: support user defined taint source
|
2021-11-02 15:00:23 +01:00 |
|
Erik Krogh Kristensen
|
5975e19f53
|
sync identical files
|
2021-11-02 14:45:33 +01:00 |
|
yoff
|
97625d7c2c
|
Merge pull request #7023 from RasmusWL/toml
Python: Add modeling of `toml`
|
2021-11-02 14:42:06 +01:00 |
|
Rasmus Wriedt Larsen
|
cb6bcada4c
|
Merge branch 'main' into django-rest-framework
|
2021-11-02 14:33:16 +01:00 |
|
yoff
|
0240631510
|
Merge pull request #6782 from RasmusWL/fastapi
Python: Model FastAPI
|
2021-11-02 14:16:12 +01:00 |
|
Rasmus Wriedt Larsen
|
c52e453342
|
Python: Minor rewrite
|
2021-11-02 13:37:50 +01:00 |
|
Anders Schack-Mulligen
|
7d0152f3c0
|
Merge pull request #6932 from aschackmull/dataflow/flow-features
Dataflow: Add support for call context restrictions on sources/sinks.
|
2021-11-02 13:24:17 +01:00 |
|
Mathias Vorreiter Pedersen
|
6f4107ff23
|
Dataflow: Replace a 'noinline' pragma with a 'nomagic' pragma.
|
2021-11-02 11:37:40 +00:00 |
|
Rasmus Wriedt Larsen
|
8ee804a8c2
|
Python: Add toml modeling
|
2021-11-02 11:57:15 +01:00 |
|
Rasmus Wriedt Larsen
|
14bc297946
|
Python: Add toml encode/decode test
|
2021-11-02 11:57:06 +01:00 |
|
Tom Hvitved
|
302373d154
|
Merge pull request #6858 from hvitved/python/type-tracker-changes
Python: Type tracker changes
|
2021-11-02 11:47:01 +01:00 |
|
CodeQL CI
|
d5e2026a26
|
Merge pull request #6934 from erik-krogh/more-instanceof
Approved by MathiasVP, esbena, yoff
|
2021-11-02 03:46:23 -07:00 |
|
CodeQL CI
|
5d62aa5b29
|
Merge pull request #6994 from erik-krogh/redundant-cast
Approved by RasmusWL, aschackmull, esbena, geoffw0, hvitved, nickrolfe
|
2021-11-02 03:45:48 -07:00 |
|
Tom Hvitved
|
1e64893742
|
Update python/ql/lib/semmle/python/dataflow/new/internal/TypeTracker.qll
Co-authored-by: Taus <tausbn@github.com>
|
2021-11-02 11:16:32 +01:00 |
|
Tom Hvitved
|
660398aa78
|
Python: Introduce TypeBackTracker::getACompatibleTypeTracker()
|
2021-11-02 11:16:32 +01:00 |
|
Tom Hvitved
|
73fd66cfed
|
Python: Cache TypeBackTracker::prepend
|
2021-11-02 11:16:32 +01:00 |
|
Rasmus Wriedt Larsen
|
83389be8e2
|
Python: Add some missing QLDocs
|
2021-11-02 11:02:51 +01:00 |
|
Rasmus Wriedt Larsen
|
5c2734c643
|
Python: Fix experimental Django.qll
|
2021-11-02 10:55:44 +01:00 |
|
Rasmus Wriedt Larsen
|
fd12b144bc
|
Python: Add change-note
|
2021-11-02 10:55:44 +01:00 |
|
Rasmus Wriedt Larsen
|
a7e4e5ef83
|
Python: Add rest_framework Response modeling
|
2021-11-02 10:55:44 +01:00 |
|