Ahmed Farid
|
76bd3317eb
|
Create Zip.qll
|
2022-03-01 00:05:30 +01:00 |
|
Ahmed Farid
|
abe25da3df
|
Create ZipSlip.qll
|
2022-03-01 00:04:02 +01:00 |
|
Ahmed Farid
|
3eae13161f
|
Delete ZipSlipCheckLib.ql
|
2022-03-01 00:01:34 +01:00 |
|
Ahmed Farid
|
21f6ad5190
|
Update and rename ZipSlipCheck.ql to ZipSlip.ql
|
2022-03-01 00:01:06 +01:00 |
|
Ahmed Farid
|
c207294dfc
|
Update zipslip_good.py
|
2022-02-26 18:31:22 +01:00 |
|
Ahmed Farid
|
d0d14be693
|
Update ZipSlip.qhelp
|
2022-02-26 18:25:13 +01:00 |
|
jorgectf
|
67b672a467
|
Merge remote-tracking branch 'origin/main' into jty/python/emailInjection
|
2022-02-26 01:22:55 +01:00 |
|
jorgectf
|
2f2cf2c1f6
|
Use StrConst.getText() instead of Str_.getS()
|
2022-02-26 01:19:50 +01:00 |
|
github-actions[bot]
|
20fe22c8c8
|
Release preparation for version 2.8.2
|
2022-02-24 14:57:08 +00:00 |
|
Rasmus Wriedt Larsen
|
aeba497832
|
Merge pull request #7735 from yoff/python/promote-log-injection
Python: promote log injection
|
2022-02-23 16:21:12 +01:00 |
|
Taus
|
3ce7d47b5b
|
Merge pull request #7452 from jorgectf/python_jwt
Python: Add Python_JWT to JWT security query
|
2022-02-23 15:23:20 +01:00 |
|
Jorge
|
0216798cb9
|
Apply suggestions from code review
Co-authored-by: Taus <tausbn@github.com>
|
2022-02-22 20:55:51 +01:00 |
|
Rasmus Wriedt Larsen
|
b59ab7f5f3
|
Merge branch 'main' into python/promote-log-injection
|
2022-02-21 09:59:31 +01:00 |
|
jorgectf
|
c5f30d99d5
|
Create an extendable AdditionalTaintStep class in customizations
|
2022-02-20 17:34:12 +01:00 |
|
Arthur Baars
|
ebb87c4b36
|
Merge pull request #7975 from github/post-release-prep/codeql-cli-2.8.1
Post-release preparation for codeql-cli-2.8.1
|
2022-02-15 20:17:35 +01:00 |
|
Rasmus Wriedt Larsen
|
5a90214ece
|
Merge pull request #7783 from yoff/python/promote-ldap-injection
Python: promote LDAP injection query
|
2022-02-15 10:24:18 +01:00 |
|
yoff
|
de5b3a272d
|
Merge pull request #7660 from RasmusWL/deprecate-old-modeling
Python: Deprecate old points-to based modeling
|
2022-02-14 19:48:03 +01:00 |
|
Rasmus Lerchedahl Petersen
|
d1200d0cd5
|
python: fix change-note formatting
|
2022-02-14 12:22:29 +01:00 |
|
Rasmus Lerchedahl Petersen
|
84447e4710
|
python: more detailed alert message
|
2022-02-14 11:55:07 +01:00 |
|
root
|
5ed5e0b105
|
Add query to detect ZipSlip
|
2022-02-13 16:44:27 -05:00 |
|
github-actions[bot]
|
21bf29353f
|
Post-release preparation for codeql-cli-2.8.1
|
2022-02-11 11:07:31 +00:00 |
|
github-actions[bot]
|
f25fc70b7c
|
Release preparation for version 2.8.1
|
2022-02-10 22:08:24 +00:00 |
|
Rasmus Wriedt Larsen
|
94f9656e8e
|
Python: Solve deprecation warnings for old experimental queries
|
2022-02-10 00:09:43 +01:00 |
|
Rasmus Lerchedahl Petersen
|
aa010e420b
|
python: update qhelp
|
2022-02-09 15:27:39 +01:00 |
|
Rasmus Lerchedahl Petersen
|
75a2f92ce4
|
pthon: add change note
|
2022-02-09 15:23:36 +01:00 |
|
jorgectf
|
85b5ef36ae
|
XmlInjection -> XmlEntityInjection
|
2022-02-09 13:28:56 +01:00 |
|
Tom Hvitved
|
9440a45015
|
Merge branch 'main' into post-release-prep/codeql-cli-2.8.0
|
2022-02-09 09:40:33 +01:00 |
|
jorgectf
|
c6d8b97871
|
Make verifyCall() a private predicate
|
2022-02-08 23:37:17 +01:00 |
|
jorgectf
|
ed60d16367
|
Refactor the way to check the verifying call
|
2022-02-08 23:33:30 +01:00 |
|
Jorge
|
f1fab98ea2
|
Merge branch 'github:main' into python_jwt
|
2022-02-08 23:12:58 +01:00 |
|
jorgectf
|
01ad25f3f0
|
Apply .getALocalSource() and fix xmltodict's vulnerable predicate
|
2022-02-08 17:51:09 +01:00 |
|
jorgectf
|
8f9cd16806
|
Update
|
2022-02-08 17:23:18 +01:00 |
|
Rasmus Lerchedahl Petersen
|
103b5761f3
|
python: remove superfluous configuration
this also removes duplicated nodes and edges
in the path results
|
2022-02-08 11:34:11 +01:00 |
|
Rasmus Lerchedahl Petersen
|
a9cfc60ea1
|
python: move supporting libraries
and update reference in query
|
2022-02-08 11:27:45 +01:00 |
|
Rasmus Lerchedahl Petersen
|
88efcff818
|
python: move query
and update reference in query test
|
2022-02-08 11:24:09 +01:00 |
|
Rasmus Wriedt Larsen
|
eb109828c0
|
Merge pull request #7252 from museljh/feature/cwe-338
Python: CWE-338 insecureRandomness
|
2022-02-07 19:30:06 +01:00 |
|
github-actions[bot]
|
b4ab86c020
|
Post-release preparation for codeql-cli-2.8.0
|
2022-02-06 23:34:07 +00:00 |
|
Jorge
|
d96eb01b9c
|
Merge branch 'github:main' into jorgectf/python/deserialization
|
2022-02-04 16:32:01 +01:00 |
|
Erik Krogh Kristensen
|
5e23da813f
|
rename named-parameters to keyword-parameters
|
2022-02-03 23:10:39 +01:00 |
|
Erik Krogh Kristensen
|
e434f075fa
|
introduce, and use, API::APICallNode
|
2022-02-03 23:10:39 +01:00 |
|
Rasmus Wriedt Larsen
|
8386b36217
|
Python: Apply suggestions from code review
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-02-03 15:00:04 +01:00 |
|
Rasmus Wriedt Larsen
|
cf68148316
|
Python: Add change-note
|
2022-02-03 14:29:02 +01:00 |
|
liangjinhuang
|
1dd15fa235
|
style:auto format
|
2022-02-02 01:30:54 +08:00 |
|
liangjinhuang
|
976e484c57
|
style:move all source files under src/experimental & feat:modify source regular matching rules
|
2022-02-02 01:14:51 +08:00 |
|
liangjinhuang
|
1885b683f7
|
style:formatDocument
|
2022-02-02 00:21:26 +08:00 |
|
Rasmus Lerchedahl Petersen
|
c2cd58edc4
|
python: rewrite to separate configurations
source nodes get duplicated, so perhaps flow states
are actually better for performance?
|
2022-02-01 14:36:11 +01:00 |
|
Rasmus Lerchedahl Petersen
|
bec8c0daea
|
python: update change note
|
2022-02-01 13:39:03 +01:00 |
|
museljh
|
012434b152
|
Update python/ql/src/experimental/Security/CWE-338/InsecureRandomness.ql
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-02-01 19:00:06 +08:00 |
|
museljh
|
a6002186bd
|
Update python/ql/src/experimental/Security/CWE-338/InsecureRandomness.ql
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-02-01 18:59:12 +08:00 |
|
Rasmus Wriedt Larsen
|
f7a0b17ed6
|
Merge pull request #7687 from yoff/python/PathInjection-FlowState
python: Rewrite path injection query to use flow state
|
2022-02-01 11:33:37 +01:00 |
|