Jami
|
cfbaf5e53b
|
Merge pull request #10785 from jcogs33/insuff-key-size-globalflow-keysize
Java: Promote insufficient key size query from experimental
|
2022-11-08 18:05:01 -05:00 |
|
Jami Cogswell
|
bada986433
|
apply review comments
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
b99a1d2cd9
|
update sink and tests
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
0e93e71127
|
update tests
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
5402001362
|
remove original sanitizer
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
5dcd3b2c0f
|
clean up files
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
5b089bbb9c
|
split sanitizer into three
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
91491d9a7b
|
refactor into more classes; add more test cases; add LITERAL sanitizer
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
6545cff0ef
|
add Pattern.quote sanitizer
|
2022-11-08 15:29:33 -05:00 |
|
Jami Cogswell
|
833c5edf06
|
move to .qll file and switch to InlineExpectations tests
|
2022-11-08 15:29:32 -05:00 |
|
Jami Cogswell
|
25436fe555
|
update options and qlref files
|
2022-11-08 15:29:32 -05:00 |
|
Jami Cogswell
|
32b140045e
|
move files out of experimental
|
2022-11-08 15:29:32 -05:00 |
|
Jami Cogswell
|
f40eefce57
|
use CompileTimeConstantExpr instead of StringLiteral
|
2022-10-27 17:11:07 -04:00 |
|
Ian Lynagh
|
63b64e4daa
|
Kotlin: Test tweaks for the diags consistency query
|
2022-10-25 16:26:11 +01:00 |
|
Jami Cogswell
|
e5982f19fa
|
minor updates
|
2022-10-19 11:05:40 -04:00 |
|
Jami Cogswell
|
961e5c72a3
|
minor updates
|
2022-10-19 08:44:35 -04:00 |
|
Tony Torralba
|
fd8f8cb930
|
Merge pull request #10223 from atorralba/atorralba/unsafe-content-resolver
Java: New Android query to detect unsafe content URI resolution
|
2022-10-19 11:22:04 +02:00 |
|
Jami Cogswell
|
4df0fbcce1
|
update tests
|
2022-10-19 01:17:57 -04:00 |
|
Jami Cogswell
|
2714c7fdcf
|
update tests
|
2022-10-14 16:45:13 -04:00 |
|
Jami Cogswell
|
2daa3457d7
|
combine three configs into one
|
2022-10-13 17:57:56 -04:00 |
|
Jami Cogswell
|
bfbb6db436
|
clean up code
|
2022-10-12 16:58:34 -04:00 |
|
Jami Cogswell
|
37d85587e0
|
refactor code into InsufficientKeySize.qll
|
2022-10-12 15:39:57 -04:00 |
|
Edward Minnix III
|
ce740b47ae
|
Merge pull request #10637 from egregius313/egregius313/android-misconfigured-contentprovider
Android ContentProvider Incomplete Permissions
|
2022-10-12 09:41:03 -04:00 |
|
Jami Cogswell
|
01c2a8cbba
|
add symm to the single config; still seems to work
|
2022-10-12 08:51:22 -04:00 |
|
Jami Cogswell
|
29de0c6748
|
make one config for asymm with flow states; seems to work...
|
2022-10-11 22:29:48 -04:00 |
|
Jami Cogswell
|
26f4abf12b
|
remove globalflow for key(pair)gen
|
2022-10-11 16:56:11 -04:00 |
|
Jami Cogswell
|
e64825ff7a
|
fix code-scanning bot problems
|
2022-10-11 16:56:11 -04:00 |
|
Jami Cogswell
|
bd76b1fcc0
|
clean-up and update configurations to have specs as sink
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
3cc7f143b2
|
clean up code somewhat
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
f5a2fef7a3
|
update tests for non-path version
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
b7123c17f8
|
draft of adding kpg tracking into dataflow config
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
cdac0e2b52
|
add local algo name tracking, still need to add ability to track algo name when KeyGen obj is param to other method
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
c414ee0e25
|
add ECC dataflow config; passes all test cases; still don't have algo name tracking
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
5e2ef66014
|
refactoring to use both dataflow configs; commit before deleting unused code
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
ac707198d5
|
commit before adding taint flow back (since no taint flow doesn't capture all cases)
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
8ffd2522e7
|
add draft code to find algo type to replace tainttracking configs
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
d3b1a04c13
|
handle FN case with simple VarAccess; add draft of dataflow config to handle complex VarAccess
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
7de9c05c9d
|
use CompileTimeConstantExpr for FN with VarAccess, and remove KeyGeneratorInitConfiguration
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
75794ec7a7
|
false negative testing - before rewrite for variable dataflow
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
9eb45c3787
|
refactor tests and code, update help file
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
657e1e62ca
|
start refactoring query logic into lib file
|
2022-10-11 16:56:10 -04:00 |
|
Jami Cogswell
|
9b7df354e6
|
move files
|
2022-10-11 16:56:10 -04:00 |
|
Josh Soref
|
21caa4b03f
|
spelling: across
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-11 00:23:35 -04:00 |
|
Tony Torralba
|
ceae5eef28
|
Revert "Decouple from #10177"
This reverts commit 7b34b10cee.
|
2022-10-06 16:30:23 +02:00 |
|
Tony Torralba
|
7b34b10cee
|
Decouple from #10177
|
2022-10-06 16:28:17 +02:00 |
|
Tony Torralba
|
1bf1349167
|
Test all sinks
|
2022-10-06 16:28:17 +02:00 |
|
Tony Torralba
|
4a18892da9
|
Second query version
Remove sinks flowing to write operations requirement
|
2022-10-06 16:28:17 +02:00 |
|
Ed Minnix
|
f888c4b279
|
Move files from CWE-276 to CWE-926
|
2022-10-04 10:40:34 -04:00 |
|
Tony Torralba
|
f19eb783be
|
Generalize file/path taint steps
This is needed by PathSanitizer but also helps simplify ZipSlip.ql
|
2022-10-04 12:27:01 +02:00 |
|
Tony Torralba
|
df29e05b9f
|
Revert "Java: Adjust ImpossibleJavadocThrows.ql"
This reverts commit c40b6285a2.
|
2022-10-04 10:59:39 +02:00 |
|