jorgectf
|
c0a0c5d811
|
Cover footer and subscription_tracking html injection
|
2021-11-08 10:51:11 +01:00 |
|
jorgectf
|
d316974157
|
Add HtmlContent additional taint step
|
2021-11-08 10:23:50 +01:00 |
|
jorgectf
|
83e3de1fed
|
Polish documentation.
|
2021-11-05 21:05:33 +01:00 |
|
jorgectf
|
cf47e8eb9c
|
Fix endpoints' naming
|
2021-11-05 20:12:35 +01:00 |
|
jorgectf
|
b3258ce20f
|
Add CookieInjection sample and .qhelp
|
2021-11-05 20:12:05 +01:00 |
|
jorgectf
|
4cb78ac654
|
Fix typo
|
2021-11-05 20:08:37 +01:00 |
|
Erik Krogh Kristensen
|
02f500b9c2
|
Merge branch 'main' into htmlReg
|
2021-11-04 12:58:42 +01:00 |
|
Rasmus Wriedt Larsen
|
cb6bcada4c
|
Merge branch 'main' into django-rest-framework
|
2021-11-02 14:33:16 +01:00 |
|
Rasmus Wriedt Larsen
|
5c2734c643
|
Python: Fix experimental Django.qll
|
2021-11-02 10:55:44 +01:00 |
|
Rasmus Wriedt Larsen
|
f1307b772a
|
Python: Add RequestHandler meta query
|
2021-11-02 10:55:44 +01:00 |
|
jorgectf
|
356b07112a
|
Cover MimeType.amp as a vulnerable mimetype
|
2021-10-30 21:19:22 +02:00 |
|
jorgectf
|
3264e7be99
|
Merge branch 'jty/python/emailInjection' of https://github.com/jty-team/codeql into jty/python/emailInjection
|
2021-10-30 21:11:30 +02:00 |
|
thank_you
|
d9e4df7f97
|
Remove unnecessary comment
|
2021-10-30 14:00:58 -04:00 |
|
Erik Krogh Kristensen
|
d36c66cfca
|
remove redundant inline casts in arguments where the type is inferred by the call target
|
2021-10-29 14:37:56 +02:00 |
|
jorgectf
|
066b40098c
|
Add lxml.etree.XMLParser missing resolve_entities dangerous case
|
2021-10-28 19:34:15 +02:00 |
|
jorgectf
|
4afcd9d207
|
[mrthankyou] smtplib partial modeling.
|
2021-10-28 19:18:59 +02:00 |
|
jorgectf
|
ba3ea700f5
|
Add Sendgrid dict data html body modeling
|
2021-10-28 18:47:54 +02:00 |
|
jorgectf
|
dbf5b24b86
|
Polish Sendgrid.qll qldoc
|
2021-10-28 18:26:35 +02:00 |
|
Erik Krogh Kristensen
|
15c90adec5
|
remove redundant cast where the type is enforced by an equality comparison
|
2021-10-28 18:08:20 +02:00 |
|
jorgectf
|
47b14f1adc
|
Polish Concepts.qll qldocs
|
2021-10-28 17:55:34 +02:00 |
|
jorgectf
|
b3ec82cd36
|
Merge branch 'jorgectf/python/jwt-queries' of https://github.com/jorgectf/codeql into jorgectf/python/jwt-queries
|
2021-10-28 17:40:33 +02:00 |
|
jorgectf
|
a6c285ad32
|
Apply getItem(_) and extend verifiesSignature readability
|
2021-10-28 17:40:27 +02:00 |
|
Jorge
|
f4d63cc5e7
|
Apply suggestions from code review
Co-authored-by: Taus <tausbn@github.com>
|
2021-10-28 17:34:11 +02:00 |
|
jorgectf
|
ef4a27ff8c
|
Apply code review suggestions
|
2021-10-28 17:31:52 +02:00 |
|
jorgectf
|
e8e0f0fea8
|
Add temporary .expected
|
2021-10-28 14:22:14 +02:00 |
|
jorgectf
|
bf68495102
|
Polish FlaskMail qldocs
|
2021-10-28 14:21:43 +02:00 |
|
jorgectf
|
c9634f3c6f
|
Fix getFlaskMailArgument()
|
2021-10-28 13:54:14 +02:00 |
|
jorgectf
|
4c2a4226ef
|
Merge remote-tracking branch 'origin/main' into jty/python/emailInjection
|
2021-10-28 13:26:57 +02:00 |
|
jorgectf
|
3dec222922
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/jwt-queries
|
2021-10-28 13:11:46 +02:00 |
|
jorgectf
|
7069f45864
|
Polish documentation
|
2021-10-28 13:09:28 +02:00 |
|
Rasmus Wriedt Larsen
|
58bc1102e5
|
Merge branch 'main' into jorgectf/python/deserialization
|
2021-10-28 12:31:34 +02:00 |
|
jorgectf
|
cf9e9f9dd4
|
Add cookie injection query missing proper tests
|
2021-10-28 10:28:45 +02:00 |
|
jorgectf
|
5dc1ad6f8a
|
Polish .ql
|
2021-10-28 09:25:47 +02:00 |
|
jorgectf
|
48c3c3d8a8
|
Broaden scope
|
2021-10-27 21:00:50 +02:00 |
|
jorgectf
|
28ec8c9dee
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/insecure-cookie
|
2021-10-27 19:00:55 +02:00 |
|
jorgectf
|
350cbb4c5d
|
Polish qhelp and libraries
|
2021-10-27 18:47:19 +02:00 |
|
Rasmus Lerchedahl Petersen
|
fed6a97eb8
|
Python: Promote ReDoS queries
|
2021-10-27 11:03:57 +02:00 |
|
Erik Krogh Kristensen
|
44afa34e37
|
Merge branch 'main' of github.com:github/codeql into htmlReg
|
2021-10-26 14:46:27 +02:00 |
|
Erik Krogh Kristensen
|
a3c55c2aec
|
use set literal instead of big disjunction of literals
|
2021-10-26 12:55:25 +02:00 |
|
Rasmus Wriedt Larsen
|
852e9875bd
|
Python: Apply suggestions from code review
Co-authored-by: Taus <tausbn@github.com>
|
2021-10-21 10:24:34 +02:00 |
|
Rasmus Wriedt Larsen
|
8f28684d10
|
Python: Rename ExtractionErrors.ql -> ExtractionWarnings.ql
|
2021-10-20 17:01:33 +02:00 |
|
Rasmus Wriedt Larsen
|
605494c3d1
|
Python: Treat SyntaxErrors as warnings in diagnostics
Rename going to happen in second commit, so git doesn't get too confused
I don't actually recall where to lookup that warning is 1, and error is
2, but I took this from
https://github.com/github/codeql/pull/6830/files#diff-460fc20823ced3b074784db804f2d4d6cfcad4f23fe5d264dc7496c782629a2eR121-R123
|
2021-10-20 16:59:00 +02:00 |
|
Rasmus Wriedt Larsen
|
b0af805460
|
Merge pull request #6899 from thepurpleowl/patch-1
Python SignatureOverriddenMethod: Rmv duplicate condition
|
2021-10-19 11:24:01 +02:00 |
|
Surya Prakash Sahu
|
2871bdb206
|
Python SignatureOverriddenMethod: Rmv duplicate condition
|
2021-10-17 18:04:20 +05:30 |
|
jorgectf
|
14c50e993b
|
Add django GET.get RFS
|
2021-10-16 13:10:48 +02:00 |
|
jorgectf
|
45146bc798
|
Merge branch 'main' into jorgectf/python/headerInjection
|
2021-10-16 12:46:57 +02:00 |
|
jorgectf
|
2db1ffef1e
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/headerInjection
|
2021-10-16 10:40:52 +02:00 |
|
jorgectf
|
f1a73e3009
|
Merge branch 'jorgectf/python/deserialization' of https://github.com/jorgectf/codeql into jorgectf/python/deserialization
|
2021-10-16 10:07:13 +02:00 |
|
jorgectf
|
c2046f1777
|
Improve readability for xmlDom()
|
2021-10-16 10:07:11 +02:00 |
|
Jorge
|
be424704a6
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-10-16 10:04:50 +02:00 |
|