Taus
|
af888f7604
|
Python: Add call graph meta-query
|
2022-03-23 16:36:28 +00:00 |
|
Rasmus Lerchedahl Petersen
|
441e206cfa
|
python: CSRF -> Csrf
|
2022-03-23 11:29:27 +01:00 |
|
Rasmus Lerchedahl Petersen
|
53de8287f5
|
python: rule out test code for CSRF
|
2022-03-22 14:57:05 +01:00 |
|
Rasmus Lerchedahl Petersen
|
0f2c21c8bd
|
python: require local protection to be absent
for CSRF to be likely
|
2022-03-22 13:42:52 +01:00 |
|
github-actions[bot]
|
a3e74efc21
|
Post-release preparation for codeql-cli-2.8.4
|
2022-03-21 19:36:47 +00:00 |
|
Rasmus Wriedt Larsen
|
b8dee25cce
|
Python: ReflectedXSS -> ReflectedXss for new Query file
So we stick to the naming conventions.
This rename is OK, since the new file was only just introduced in this
PR.
|
2022-03-21 16:12:38 +01:00 |
|
Arthur Baars
|
79cd7bf8ed
|
Python: create semmle/python/dataflow/new/Regex.qll
|
2022-03-21 15:57:19 +01:00 |
|
Rasmus Wriedt Larsen
|
695553ba9f
|
Python: Deprecate old non-Query.qll dataflow defs
|
2022-03-21 15:03:22 +01:00 |
|
github-actions[bot]
|
dedc8c2254
|
Release preparation for version 2.8.4
|
2022-03-21 13:25:49 +00:00 |
|
Arthur Baars
|
9412b331db
|
Revert "Revert "Python: switch to shared implementation of IncompleteHostnameRegExp.ql""
This reverts commit 6d24591416.
|
2022-03-18 16:31:22 +01:00 |
|
Arthur Baars
|
6d24591416
|
Revert "Python: switch to shared implementation of IncompleteHostnameRegExp.ql"
This reverts commit ce50f35dda.
|
2022-03-18 13:02:55 +01:00 |
|
Erik Krogh Kristensen
|
879680057e
|
fix all ql/unused-field warnings
|
2022-03-17 09:41:42 +01:00 |
|
Arthur Baars
|
ab93b3784b
|
Merge remote-tracking branch 'upstream/main' into incomplete-hostname
|
2022-03-16 12:31:12 +01:00 |
|
Erik Krogh Kristensen
|
c7509c4dd3
|
Merge branch 'main' into deadCode
|
2022-03-15 09:19:14 +01:00 |
|
Jonas Jensen
|
d89c52f4b0
|
Merge pull request #8403 from erik-krogh/noUpper
Rename all upper-case variables, and all lower-case modules
|
2022-03-15 09:00:37 +01:00 |
|
haby0
|
e11c74c580
|
Delete redundant comments
|
2022-03-15 15:25:08 +08:00 |
|
haby0
|
4195eef9ba
|
Add CSV injection model
|
2022-03-15 15:15:38 +08:00 |
|
Arthur Baars
|
6a74e761c8
|
Merge pull request #8398 from github/post-release-prep/codeql-cli-2.8.3
Post-release preparation for codeql-cli-2.8.3
|
2022-03-14 21:05:09 +01:00 |
|
Erik Krogh Kristensen
|
3bf5e06d53
|
delete all dead code
|
2022-03-14 13:03:31 +01:00 |
|
Erik Krogh Kristensen
|
ad2ab5602e
|
PY: rename remaining private python modules
|
2022-03-14 12:22:33 +01:00 |
|
Jeroen Ketema
|
4c2081b7fc
|
Merge pull request #8401 from jketema/taint-flow
Extend taint tracking interface with flow states
|
2022-03-14 12:06:10 +01:00 |
|
Rasmus Wriedt Larsen
|
2f4a22c86c
|
Merge pull request #6112 from jorgectf/jorgectf/python/deserialization
Python: Port and extend XXE modeling
|
2022-03-14 11:59:28 +01:00 |
|
Erik Krogh Kristensen
|
bbb2847ec1
|
Merge pull request #8323 from erik-krogh/acronyms
Enforcing consistent casing of acronyms
|
2022-03-14 11:38:25 +01:00 |
|
Ahmed Farid
|
3c9de6f488
|
Update Zip.qll
|
2022-03-11 18:50:37 +01:00 |
|
Arthur Baars
|
cf4b834536
|
Address comments
|
2022-03-11 14:25:34 +01:00 |
|
Ahmed Farid
|
f092cd8d80
|
Update Zip.qll
|
2022-03-11 14:15:05 +01:00 |
|
Ahmed Farid
|
eb71cdf7a2
|
Update ZipSlip.ql
|
2022-03-11 14:13:28 +01:00 |
|
Ahmed Farid
|
0de1cef26e
|
Update ZipSlip.qll
|
2022-03-11 14:03:17 +01:00 |
|
Jeroen Ketema
|
93a0da75b6
|
Fix taint tracking configurations that broke due to interface change
|
2022-03-11 12:18:04 +01:00 |
|
Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
Erik Krogh Kristensen
|
ddf93b555e
|
PY: fix some ql/non-doc-block warnings
|
2022-03-11 11:02:58 +01:00 |
|
github-actions[bot]
|
3a5ebbb861
|
Post-release preparation for codeql-cli-2.8.3
|
2022-03-11 09:23:34 +00:00 |
|
github-actions[bot]
|
6b194bc55f
|
Release preparation for version 2.8.3
|
2022-03-10 19:43:58 +00:00 |
|
Taus
|
4ee4bba4d1
|
Merge branch 'main' into ZipSlip
|
2022-03-10 13:30:51 +01:00 |
|
jorgectf
|
c155ac6e7a
|
Add HtmlEscaping sanitizer
|
2022-03-10 00:47:04 +01:00 |
|
Erik Krogh Kristensen
|
a1769f8036
|
Python: add default implementation of getName() and deprecate it
|
2022-03-09 18:28:12 +01:00 |
|
Taus
|
7b877fb317
|
Merge pull request #8336 from tausbn/python-fix-a-bunch-of-ql-warnings
Python: Fix a bunch of QL warnings
|
2022-03-09 16:31:28 +01:00 |
|
Rasmus Wriedt Larsen
|
0e9da4aadb
|
Python: Resolve name conflict over XML module
Not the prettiest solution... but it works ¯\_(ツ)_/¯
|
2022-03-09 11:02:28 +01:00 |
|
Ahmed Farid
|
475cca0d7e
|
Update ZipSlip.qll
|
2022-03-09 00:00:52 +01:00 |
|
Ahmed Farid
|
27b9d6c752
|
Update ZipSlip.qll
|
2022-03-08 23:59:03 +01:00 |
|
jorgectf
|
3f43e6ef54
|
Fix FlaskMail's getTo
|
2022-03-08 18:45:53 +01:00 |
|
jorgectf
|
bbba1a21c4
|
Explicitly call this in SendGridMail
|
2022-03-08 18:40:20 +01:00 |
|
jorgectf
|
930fbf777c
|
Move getFlaskMailArgument inside FlaskMail and refactor
|
2022-03-08 18:38:32 +01:00 |
|
jorgectf
|
6b04344655
|
Refactor sendgridContent and sendgridWrite
Move the predicates inside `SendGridMail`.
See https://github.com/github/codeql/pull/7127#discussion_r821574462
|
2022-03-08 18:26:20 +01:00 |
|
jorgectf
|
6722671541
|
Refactor sendgridApiClient and sendgridApiSendCall
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-03-08 18:24:38 +01:00 |
|
Taus
|
063a8bbc43
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-03-08 15:20:35 +01:00 |
|
Rasmus Wriedt Larsen
|
6b14c1d6b9
|
Merge branch 'main' into jorgectf/python/deserialization
|
2022-03-08 11:15:03 +01:00 |
|
Taus
|
d2603884ca
|
Python: Fix a bunch of class QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Taus
|
af7f532212
|
Python: Fix up a bunch of function QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Arthur Baars
|
ce50f35dda
|
Python: switch to shared implementation of IncompleteHostnameRegExp.ql
|
2022-03-07 16:10:08 +01:00 |
|