Ed Minnix
|
dbb5aa9aad
|
Change note
|
2023-10-25 14:31:54 -04:00 |
|
Ed Minnix
|
083a5068c3
|
Remove unnecessary models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
886c85ddc1
|
Fix net.schmizz.sshj models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
ee6cb96d07
|
Add a superclass for credential nodes
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
3219edc603
|
Change credential-other to more appropriate sink kinds
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
6b94b77a0a
|
Remove spaces in sig field of models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
f8c3b2977a
|
Fix credential-other
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
f783ca7940
|
Fix credential-username
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
96d6ecb108
|
Fix crypto parameters
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
35e19eac96
|
Fix password models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
4f8908106b
|
Refactor HardcodedCredentials to use new SensitiveApi api
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
f7c07d55ed
|
Credential-other sinks
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
49218cdbfb
|
Credential-username models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
18661eee77
|
Crypto-parameter models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
66486b08dc
|
Password models
|
2023-10-25 14:31:53 -04:00 |
|
Ed Minnix
|
4aec302fb7
|
Create new sink kinds
|
2023-10-25 14:31:53 -04:00 |
|
Anders Schack-Mulligen
|
283d6efdf8
|
Rangeanalysis/Java/C++: Address some ql4ql findings.
|
2023-10-25 14:06:35 +02:00 |
|
Jami
|
53d92d58fc
|
Merge pull request #14581 from jcogs33/jcogs33/add-internal-to-model-exclusions
Java: exclude internal packages globally from MaD models
|
2023-10-25 08:04:03 -04:00 |
|
Michael Nebel
|
b3e5b86f0a
|
Java: Cleanup threat models tests.
|
2023-10-25 14:02:31 +02:00 |
|
Anders Schack-Mulligen
|
2592c94c54
|
Java: Replace range analysis with shared version.
|
2023-10-25 11:29:55 +02:00 |
|
Anders Schack-Mulligen
|
36082808d3
|
Java: Implement shared range analysis signatures.
|
2023-10-25 11:29:55 +02:00 |
|
Stephan Brandauer
|
cffcc7334d
|
Java: automodel extraction docs: add two intro sentences
|
2023-10-25 09:45:00 +02:00 |
|
Stephan Brandauer
|
0f2db1bcdb
|
Java: automodel extraction docs: use markdown footnote
|
2023-10-25 09:32:59 +02:00 |
|
Stephan Brandauer
|
3eeb6ffec4
|
Java: automodel extraction docs: spell out positive and negative
|
2023-10-25 09:05:22 +02:00 |
|
Stephan Brandauer
|
44c87561b3
|
Java: review suggestion from adityasharad
Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com>
|
2023-10-25 09:00:28 +02:00 |
|
Stephan Brandauer
|
c240c1b3f5
|
Java: review suggestions from aeisenberg
Co-authored-by: Andrew Eisenberg <aeisenberg@github.com>
|
2023-10-25 08:59:21 +02:00 |
|
github-actions[bot]
|
6cbadece0e
|
Add changed framework coverage reports
|
2023-10-25 00:15:35 +00:00 |
|
Marcono1234
|
bf20b8e5a5
|
Kotlin: Mention Literal::getLiteral() difference from source code
It appears the Kotlin extractor does not have access to the actual
string representation in the source code, and for most literal types
uses simply the represented value also as `getLiteral` result, see
https://github.com/github/codeql/blob/codeql-cli/v2.15.1/java/kotlin-extractor/src/main/kotlin/KotlinFileExtractor.kt#L4443
|
2023-10-25 02:04:54 +02:00 |
|
Dave Bartolomeo
|
5fd56ce866
|
Alternate threat model implementation
|
2023-10-24 13:12:37 -04:00 |
|
Jami Cogswell
|
121fd0896b
|
Java: exclude internal packages in general from models
|
2023-10-24 12:49:49 -04:00 |
|
Tony Torralba
|
9f7a8aa18c
|
Update MaD Declarations after Triage
|
2023-10-24 17:42:03 +02:00 |
|
Chris Smowton
|
30610c9a3f
|
Temporarily de-deprecate SuperMethodAccess to accommodate private tests
|
2023-10-24 16:05:52 +01:00 |
|
Stephan Brandauer
|
e97456f5fc
|
Java: automodel extraction docs: note on packaging and backwards compatibility
|
2023-10-24 16:30:59 +02:00 |
|
Chris Smowton
|
92d3d9d83f
|
Update integration test expectations
|
2023-10-24 14:47:19 +01:00 |
|
Chris Smowton
|
4205f1bd03
|
Temporarily un-deprecate MethodAccess to decouple from private tests
|
2023-10-24 14:03:26 +01:00 |
|
Chris Smowton
|
b849a66c97
|
Update test expectations
|
2023-10-24 14:02:30 +01:00 |
|
Chris Smowton
|
06238dd5f6
|
Improve reflective class names
|
2023-10-24 13:29:32 +01:00 |
|
Chris Smowton
|
011666b48c
|
Fix description and improve predicate name of VarWrite.
|
2023-10-24 12:59:57 +01:00 |
|
Chris Smowton
|
ede17585a6
|
Amend NewClassExpr description
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2023-10-24 12:51:42 +01:00 |
|
Chris Smowton
|
e3edea2a5f
|
Apply simple suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2023-10-24 12:51:03 +01:00 |
|
Stephan Brandauer
|
eb97ce3294
|
Java: automodel extraction query docs, candidate examples
|
2023-10-24 13:49:38 +02:00 |
|
Chris Smowton
|
efb63aada3
|
Add change note
|
2023-10-24 11:45:41 +01:00 |
|
Chris Smowton
|
3627eb2bcf
|
Add missing qldoc
|
2023-10-24 11:15:08 +01:00 |
|
Chris Smowton
|
e8c9708282
|
Autoformat
|
2023-10-24 11:06:19 +01:00 |
|
Chris Smowton
|
09e83d1173
|
Fix isEnclosingMethodAccess wrapper
|
2023-10-24 11:03:57 +01:00 |
|
Chris Smowton
|
ac38d4c9c6
|
Mass rename L/RValue -> VarWrite/Read
|
2023-10-24 10:58:29 +01:00 |
|
Chris Smowton
|
59a49eef0b
|
Add aliases for public, importable renamed classes and predicates.
Also rename and aliases a couple of uses of Access noted along the way.
|
2023-10-24 10:54:35 +01:00 |
|
Chris Smowton
|
f552a15aae
|
Mass-rename MethodAccess -> MethodCall
|
2023-10-24 10:30:26 +01:00 |
|
Chris Smowton
|
a10731c591
|
Java: introduce more-intuitive names for ClassInstanceExpr, L/RValue and MethodAccess.
|
2023-10-24 09:38:49 +01:00 |
|
Tony Torralba
|
cd10dc8a27
|
Java: Added up to date models for Spring's ResponseEntity
|
2023-10-23 16:06:11 +02:00 |
|