Tony Torralba
|
8ad787f3b8
|
Java: Generelize MaybeBrokenCryptoAlgorithmQuery.qll
|
2023-12-22 10:15:40 +01:00 |
|
Ed Minnix
|
8051cfcef5
|
Fix tests and fix getStringValue method
|
2023-12-21 22:48:08 -05:00 |
|
Ed Minnix
|
6455e1893d
|
Add more test cases
|
2023-12-21 22:48:08 -05:00 |
|
Ed Minnix
|
7f9dff2dc7
|
Fix minor error in Weak Hashing
|
2023-12-21 22:48:07 -05:00 |
|
Aditya Sharad
|
b1803d0ac2
|
Merge rc/3.12 into main
|
2023-12-21 16:40:51 -08:00 |
|
masterofnow
|
0fd09759df
|
Added sample java file for qhelp to render correctly.
|
2023-12-22 08:31:23 +08:00 |
|
masterofnow
|
cb5733d647
|
Apply suggestions from code review
Update to documentation.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-22 08:25:05 +08:00 |
|
Stephan Brandauer
|
a9d21cef01
|
Update MaD Declarations after Triage
|
2023-12-21 15:39:03 +01:00 |
|
masterofnow
|
7162540faf
|
Added options, .qhelp and .expected file for unit test.
|
2023-12-21 19:57:37 +08:00 |
|
masterofnow
|
8dc522fb5f
|
Merge remote-tracking branch 'origin/LoadClassNoSignatureCheck' into LoadClassNoSignatureCheck
|
2023-12-21 12:15:06 +08:00 |
|
masterofnow
|
25c818f425
|
Added unit test files.
|
2023-12-21 12:13:00 +08:00 |
|
github-actions[bot]
|
d77e8df800
|
Add changed framework coverage reports
|
2023-12-21 00:16:28 +00:00 |
|
Tony Torralba
|
1b9f59efa7
|
Merge pull request #14646 from github/java/update-mad-decls-after-triage-2023-10-31T15-52-01
Java: Update MaD Declarations after Triage
|
2023-12-20 15:37:19 +01:00 |
|
Tony Torralba
|
39708524e7
|
Minor fixes
- Query ID
- MethodAccess -> MethodCall
- Redundant import
- Formatting
|
2023-12-20 15:31:09 +01:00 |
|
Tony Torralba
|
e744d974e8
|
Merge pull request #14580 from github/java/update-mad-decls-after-triage-2023-10-24T15-42-01
Java: Update MaD Declarations after Triage
|
2023-12-20 15:01:24 +01:00 |
|
Tony Torralba
|
2df8bcb9dc
|
Update java/ql/lib/change-notes/2023-10-31-new-models.md
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-12-20 14:59:07 +01:00 |
|
masterofnow
|
e85c4b5bf6
|
Update query from code review feedback to express it as a dataflow problem.
|
2023-12-20 18:28:16 +08:00 |
|
Ed Minnix
|
a93d6dd956
|
Change note
|
2023-12-19 10:28:23 -05:00 |
|
Ed Minnix
|
ce130c6ed5
|
Add replace to MapMutator
|
2023-12-19 10:23:06 -05:00 |
|
Tony Torralba
|
c8a369d9ef
|
Update java/ql/lib/ext/jakarta.persistence.model.yml
|
2023-12-19 14:58:07 +01:00 |
|
github-actions[bot]
|
8f72b0e4f7
|
Post-release preparation for codeql-cli-2.15.5
|
2023-12-19 10:32:57 +00:00 |
|
github-actions[bot]
|
19af35b29a
|
Release preparation for version 2.15.5
|
2023-12-18 21:22:44 +00:00 |
|
Edward Minnix III
|
56921a6e21
|
Merge pull request #14040 from egregius313/egregius313/weak-hashing-properties
Java: Add support for algorithm names specified in `.properties` files to `java/potentially-weak-cryptographic-algorithm`
|
2023-12-18 09:38:58 -05:00 |
|
Tony Torralba
|
9446249e94
|
Merge pull request #15012 from atorralba/atorralba/java/fix-missing-pinning-fp
Java: Fix FPs in Missing certificate pinning
|
2023-12-18 09:37:18 +01:00 |
|
Tony Torralba
|
0524289a73
|
Update java/ql/src/Security/CWE/CWE-327/MaybeBrokenCryptoAlgorithm.ql
|
2023-12-18 08:50:10 +01:00 |
|
masterofnow
|
4a77f45aa6
|
Minor adjustment to resolve error for codeql version 2.15.4
|
2023-12-16 12:41:39 +08:00 |
|
masterofnow
|
99b273d308
|
Apply suggestions from code review
Added suggestion from atorralba.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-16 12:00:45 +08:00 |
|
Chris Smowton
|
84c86f256a
|
Add buildless tests
|
2023-12-15 22:37:55 +00:00 |
|
Eric Bickle
|
95ce7c9ba4
|
Merge branch 'main' into fix/update-gson-model
|
2023-12-15 10:15:53 -08:00 |
|
Ed Minnix
|
09a0730491
|
QLdoc fix
|
2023-12-15 11:13:09 -05:00 |
|
Ed Minnix
|
02581a3850
|
Move class for getProperty method call to Properties.qll
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
73cb01fc89
|
Remove integration test (ported to query test)
The `.properties` file extractor has been enabled by default, so the
test about sources from `getProperty` calls can be ported to a query test.
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
fc53727b9d
|
Bump change note date
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
8826eaf1a3
|
Move test case to query tests
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
afefccf8f7
|
Update change note
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
0d12981d6a
|
Bump change note
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
078a33eecc
|
Updated change note
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
1c3993e632
|
QLDocs
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
8e55ced288
|
Update test to use MaybeBrokenCryptoAlgorithm
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
83c6ece405
|
Move weak hashing into MaybeBrokenCryptoAlgorithm
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
fbc2a33597
|
Replace MethodAccess with MethodCall
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
c20ea1f629
|
Bump change note date
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
cb0ea350b5
|
Improve docs
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
0efca8200d
|
Weak Hashing query wording
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
86b57a11ac
|
Bump change note date
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
25fa8d5ae7
|
Move some logic to class
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
4ff6c1e2ea
|
Test case
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
93cf5b8eb9
|
Weak Hashing Property initial query
|
2023-12-15 11:09:07 -05:00 |
|
Anders Schack-Mulligen
|
337e5e458c
|
Update java/ql/lib/semmle/code/java/security/InsufficientKeySize.qll
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-15 08:48:50 +01:00 |
|
Anders Schack-Mulligen
|
7623432c76
|
Java: Remove/deprecate FlowStateString-based extension points.
|
2023-12-14 15:15:58 +01:00 |
|