Owen Mansel-Chan
|
1cb5f35c56
|
Add change note
|
2024-07-30 16:29:38 +01:00 |
|
Owen Mansel-Chan
|
cd0af0fc57
|
Ignore types with methods which have annotations
The motivation is test classes in JUnit 4 and 5 are currently FPs for this. They have methods with `@Test`, so this should fix the FPs.
|
2024-07-30 16:29:35 +01:00 |
|
Owen Mansel-Chan
|
050dcb1370
|
Add some tests for java/unused-reference-type
|
2024-07-30 16:29:11 +01:00 |
|
Jami
|
2c8f3a58b3
|
Merge branch 'main' into jcogs33/java/provenance-postprocess-qltest
|
2024-07-30 10:53:52 -04:00 |
|
Owen Mansel-Chan
|
44b6309e07
|
Add change note
|
2024-07-30 15:44:00 +01:00 |
|
Owen Mansel-Chan
|
e259b25428
|
Add "tokenizer" to sensitive variable name FPs
|
2024-07-30 15:38:32 +01:00 |
|
Owen Mansel-Chan
|
0704946324
|
Factor out matching sensitive variable name FPs
|
2024-07-30 15:37:54 +01:00 |
|
Owen Mansel-Chan
|
bdff0fdcc5
|
Add test for "tokenizer"
|
2024-07-30 15:37:46 +01:00 |
|
Owen Mansel-Chan
|
0d71072f94
|
Make test more compact
|
2024-07-30 15:36:59 +01:00 |
|
Arthur Baars
|
0d469536ae
|
Merge pull request #17065 from github/aibaars/proxy-tests
Java: integration tests with proxy server
|
2024-07-30 15:53:45 +02:00 |
|
Anders Schack-Mulligen
|
5073f4f7dd
|
Merge pull request #17096 from aschackmull/java/pp-experimental-models
Java: Pretty-print experimental models for qltest.
|
2024-07-30 13:31:15 +02:00 |
|
am0o0
|
9662950405
|
add comments for FPs
|
2024-07-30 13:24:46 +02:00 |
|
Chris Smowton
|
8f52b2cd95
|
Fix link
|
2024-07-30 12:23:38 +01:00 |
|
Chris Smowton
|
a781522ca0
|
Copyedit documentation
|
2024-07-30 12:19:16 +01:00 |
|
Anders Schack-Mulligen
|
da5250d3a7
|
Java: Pretty-print experimental models for qltest.
|
2024-07-30 11:43:44 +02:00 |
|
github-actions[bot]
|
d39609254c
|
Add changed framework coverage reports
|
2024-07-30 00:18:23 +00:00 |
|
am0o0
|
4dc1a10f71
|
update tests for zip4j, add aditional flow steps for zip4j, remove BombTypeInputStream class since we don't need it anymore, add a predicate which was for testing porpose and was junk
|
2024-07-29 18:10:04 +02:00 |
|
Jami Cogswell
|
e226da4f04
|
Java: use post-process provenance pretty-printing in .ql library-tests
|
2024-07-29 11:46:28 -04:00 |
|
RobbingDaHood
|
1cb58922a2
|
Minor changes to formulations for java/error-message-exposure
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2024-07-29 16:48:15 +02:00 |
|
Ian Lynagh
|
1530037eae
|
Merge pull request #17071 from igfoo/igfoo/dep_env
Java/Kotlin: Remove support for deprecated SOURCE_ARCHIVE and TRAP_FOLDER
|
2024-07-29 14:55:50 +01:00 |
|
Jami Cogswell
|
bab89c46b6
|
Java: use post-process provenance pretty-printing in library-tests
|
2024-07-28 18:13:58 -04:00 |
|
Jami Cogswell
|
0a382bf0cf
|
Java: use post-process provenance pretty-printing in experimental/query-tests
|
2024-07-28 18:13:20 -04:00 |
|
Jami Cogswell
|
c70d39539e
|
Java: use post-process provenance pretty-printing in query-tests
|
2024-07-28 18:12:17 -04:00 |
|
am0o0
|
c8749ff82e
|
Merge branch 'amammad-java-bombs' of https://github.com/am0o0/codeql into amammad-java-bombs
|
2024-07-28 12:15:23 +02:00 |
|
am0o0
|
209fa1a10a
|
update tests
|
2024-07-28 12:15:07 +02:00 |
|
am0o0
|
0593eaad52
|
we don't need ConstructorCall for ZipFile anymore since we have a more accurate sink for this
|
2024-07-28 12:12:07 +02:00 |
|
am0o0
|
cc752113af
|
we don't need TypeInputStreamConstructorArgumentSink anymore
|
2024-07-28 12:09:52 +02:00 |
|
am0o0
|
7689db7d42
|
change apache commons sink
|
2024-07-28 12:09:33 +02:00 |
|
am0o0
|
1b97804f45
|
update tests
|
2024-07-28 11:45:48 +02:00 |
|
Am
|
96c142bf0a
|
Merge branch 'main' into amammad-java-JWT
|
2024-07-28 13:03:23 +03:30 |
|
am0o0
|
6538a06f29
|
update tests
|
2024-07-28 11:30:59 +02:00 |
|
am0o0
|
b5e7716579
|
remove flow states, remove string as sources
|
2024-07-28 11:26:18 +02:00 |
|
am0o0
|
46ddddc8cf
|
Merge tag 'codeql-cli/v2.18.1' into amammad-java-JWT
Compatible with CodeQL CLI 2.18.1
|
2024-07-28 11:23:20 +02:00 |
|
am0o0
|
85b02b1399
|
use MethodCall instead of MethodAccess, change query id
|
2024-07-28 10:42:44 +02:00 |
|
am0o0
|
494f0b709e
|
Merge branch 'main' into amammad-java-JWT
|
2024-07-28 10:37:26 +02:00 |
|
am0o0
|
14cf47b906
|
comply with PascalCase/camelCase, remove redundant import
|
2024-07-28 10:28:28 +02:00 |
|
Chris Smowton
|
e3559d8f93
|
Adjust test expectations
|
2024-07-28 10:27:11 +02:00 |
|
Chris Smowton
|
142d7ae005
|
Make test compatible with Servlet 2.5; use old Servlet stubs
|
2024-07-28 10:26:58 +02:00 |
|
Jami
|
0ba5a74f6a
|
Merge pull request #17074 from jcogs33/jcogs33/java/fix-regex-use-comments
Java: fix comments about use of sink kind `regex-use`
|
2024-07-26 08:57:39 -04:00 |
|
Jami
|
ff9093f2de
|
Merge branch 'main' into jcogs33/java/add-apache-ant-path-inj-sinks
|
2024-07-26 08:54:27 -04:00 |
|
Arthur Baars
|
b34b589005
|
Merge branch 'main' into aibaars/proxy-tests
|
2024-07-26 09:24:54 +02:00 |
|
Owen Mansel-Chan
|
c051d33cc7
|
Merge branch 'main' into dataflow/provenance-postprocess-qltest
|
2024-07-26 08:04:05 +01:00 |
|
RobbingDaHood
|
feb31d2006
|
Merge branch 'main' into 17052-second-try-do-not-expose-error-message
|
2024-07-25 18:13:49 +02:00 |
|
Daniel Winther Petersen
|
1c1ba7734f
|
Now alerts about exposing exception.getMessage() in servlet responses are split out of java/stack-trace-exposure into its own alert java/error-message-exposure because this is a better fit.
|
2024-07-25 18:12:45 +02:00 |
|
Jami
|
91f5f086fb
|
Merge pull request #17025 from jcogs33/jcogs33/java/adjust-url-syntheticfield
Java: add TaintInheritingContent for URL synthetic fields
|
2024-07-25 12:11:39 -04:00 |
|
Arthur Baars
|
9d6260b334
|
Copy os.environment
Prevents cryptic "OSError: [WinError 10106] The requested service provider could not be loaded or initialized" error from Python subprocess call
|
2024-07-25 17:59:11 +02:00 |
|
Jami Cogswell
|
eea3e82cca
|
Java: fix 'regex-use' comments
|
2024-07-25 10:39:03 -04:00 |
|
Anders Schack-Mulligen
|
c693f03462
|
Merge pull request #17070 from aschackmull/dataflow/pptype-refactor
Dataflow: Replace `ppReprType` with `DataFlowType.toString`.
|
2024-07-25 14:30:08 +02:00 |
|
Ian Lynagh
|
225d2915e5
|
Java/Kotlin: Add changenote for dropping SOURCE_ARCHIVE/TRAP_FOLDER
|
2024-07-25 12:48:55 +01:00 |
|
Ian Lynagh
|
e4b9335ce0
|
Kotlin: Remove support for deprecated SOURCE_ARCHIVE and TRAP_FOLDER
|
2024-07-25 12:46:13 +01:00 |
|