Anna Railton
|
00b74d8b1c
|
Merge pull request #8895 from github/annarailton-patch-1
ATM: Update `TaintedPathInjection` -> `TaintedPath`
|
2022-04-27 16:15:46 +01:00 |
|
Stephan Brandauer
|
ee280cda32
|
Improve docs after PR comment
Co-authored-by: Asger F <asgerf@github.com>
|
2022-04-27 16:24:20 +02:00 |
|
Stephan Brandauer
|
4964f2df9a
|
add flow step to rest parameters
|
2022-04-27 16:03:19 +02:00 |
|
Erik Krogh Kristensen
|
e1c7d369be
|
Merge pull request #8796 from erik-krogh/redundantImport
Remove redundant imports
|
2022-04-27 12:39:51 +02:00 |
|
Anna Railton
|
1f1ef22f90
|
Update TaintedPathInjection -> TaintedPath
Lines up with usual naming in https://github.com/github/ml-ql-adaptive-threat-modeling-backend
|
2022-04-27 11:27:43 +01:00 |
|
Anna Railton
|
eacfceb6ce
|
Merge pull request #8605 from github/annarailton/new-query-label-mappings
Experimental (ATM): update query label mappings
|
2022-04-26 16:39:06 +01:00 |
|
Erik Krogh Kristensen
|
d389012b75
|
Merge branch 'main' into redundantImport
|
2022-04-26 14:24:51 +02:00 |
|
Erik Krogh Kristensen
|
6738270b65
|
Merge pull request #8229 from erik-krogh/parenSan
JS: step through parentheses in barrier functions
|
2022-04-26 10:30:21 +02:00 |
|
Mathias Vorreiter Pedersen
|
aca4c8727f
|
Merge pull request #8802 from github/post-release-prep/codeql-cli-2.9.0
Post-release preparation for codeql-cli-2.9.0
|
2022-04-25 22:52:55 +01:00 |
|
Jean Helie
|
47fdb79cf8
|
Merge pull request #8751 from github/jhelie/add-gitkeep-to-model-resources
ML: add .gitkeep to resources dir in which ML models are to be found
|
2022-04-25 18:08:24 +02:00 |
|
Erik Krogh Kristensen
|
0a26e891a2
|
include startsWith/endsWith checks in js/missing-origin-check
|
2022-04-25 15:28:50 +02:00 |
|
Erik Krogh Kristensen
|
fe3d71ebc2
|
fix qhelp: the window, not the origin, is sending the message
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2022-04-25 14:07:01 +02:00 |
|
Anders Schack-Mulligen
|
40a16325a9
|
Minor clean-up in AccessPathSyntax.
|
2022-04-25 12:27:48 +02:00 |
|
Erik Krogh Kristensen
|
b5193d99d7
|
have getSourceType() depend on which kind of event it is
|
2022-04-25 11:32:52 +02:00 |
|
Jeroen Ketema
|
79164056d1
|
Replace help.semmle.com links by codeql.github.com links
|
2022-04-22 20:42:11 +02:00 |
|
annarailton
|
9c25da20a4
|
Update queryNames
|
2022-04-22 13:42:29 +01:00 |
|
CodeQL CI
|
06e5962da7
|
Merge pull request #8791 from asgerf/js/static-accessors
Approved by erik-krogh
|
2022-04-22 13:39:32 +01:00 |
|
Erik Krogh Kristensen
|
3b0066e93d
|
address review comments
|
2022-04-22 14:01:24 +02:00 |
|
Erik Krogh Kristensen
|
8fcbaea273
|
Merge branch 'main' into labelNaming
|
2022-04-22 13:19:44 +02:00 |
|
Erik Krogh Kristensen
|
ff73dbc35c
|
delete redundant imports
|
2022-04-22 12:55:28 +02:00 |
|
Khang. Võ Vĩ
|
f4581ae866
|
fix PrototypePollutingAssignment examples
|
2022-04-22 11:55:45 +07:00 |
|
github-actions[bot]
|
1aecfc67c2
|
Post-release preparation for codeql-cli-2.9.0
|
2022-04-21 19:22:19 +00:00 |
|
github-actions[bot]
|
eeaf233c29
|
Release preparation for version 2.9.0
|
2022-04-21 14:49:00 +00:00 |
|
Tom Hvitved
|
bd09c61504
|
Merge pull request #8786 from hvitved/ruby/dataflow/argument-tokens
Ruby: Implement `Argument[any]` and `Argument[n..]`
|
2022-04-21 16:31:24 +02:00 |
|
Erik Krogh Kristensen
|
c1798c4ebd
|
remove redundant extends clause
|
2022-04-21 09:13:18 +02:00 |
|
Erik Krogh Kristensen
|
6007dfa101
|
fix qldoc in StoredXssCustomizations
Co-authored-by: Asger F <asgerf@github.com>
|
2022-04-21 09:11:08 +02:00 |
|
Erik Krogh Kristensen
|
b9a7c563d1
|
fix typo in change note
Co-authored-by: Asger F <asgerf@github.com>
|
2022-04-21 09:09:56 +02:00 |
|
Asger Feldthaus
|
c6e66edb97
|
JS: Change note
|
2022-04-21 08:32:01 +02:00 |
|
Erik Krogh Kristensen
|
9927a82520
|
Merge pull request #8789 from erik-krogh/apiIpaBranches
JS/PY: mention newtype constructors in API graph label classes
|
2022-04-20 23:39:46 +02:00 |
|
Erik Krogh Kristensen
|
7e73ecceab
|
add change-note
|
2022-04-20 23:31:42 +02:00 |
|
Erik Krogh Kristensen
|
ff5b873557
|
Merge pull request #8773 from erik-krogh/exhaustion
JS: promote `js/resource-exhaustion` out of experimental
|
2022-04-20 19:33:42 +02:00 |
|
Erik Krogh Kristensen
|
9c5f3e9406
|
remove leftover debug comments
|
2022-04-20 18:42:46 +02:00 |
|
Erik Krogh Kristensen
|
ef51b46795
|
JS: mention newtype constructors in API graph label classes
|
2022-04-20 18:37:19 +02:00 |
|
Erik Krogh Kristensen
|
06394c8dc6
|
move storedXss sources to the Customizations file
|
2022-04-20 18:17:49 +02:00 |
|
Erik Krogh Kristensen
|
81ce8ac715
|
ATM: fix compiler warnings about unused variables
|
2022-04-20 18:10:59 +02:00 |
|
Erik Krogh Kristensen
|
4bc36d82f6
|
update expected output for ATM
|
2022-04-20 18:10:56 +02:00 |
|
Erik Krogh Kristensen
|
c1c66a0200
|
refactor CountAlertAndEndpoints to not refer to deprecated files
|
2022-04-20 18:10:56 +02:00 |
|
Erik Krogh Kristensen
|
c5f7df17ee
|
add .actual files to .gitignore for ATM tests
|
2022-04-20 18:10:56 +02:00 |
|
Erik Krogh Kristensen
|
1c5d59f885
|
fix an instance of ql/acronyms-should-be-pascal-case
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
ea6b68fc59
|
add missing qldoc
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
12e60c7a06
|
move TypeTestGuard to the Query.qll file
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
b1bad271d5
|
only activate the PrefixString label in Query.qll files
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
8a5b1668f9
|
move initialization of sanitizer-guards to Query.qll files
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
73dbe44824
|
remove dead import
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
8d3bd9d7cd
|
move the ExceptionXss sources into the Customizations file
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
25708c5091
|
move the XssThroughDom sources into the Customizations file
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
ad14bbae90
|
create a customizations file for StoredXss
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
162a4992a5
|
move the ReflectedXss sources/sinks into the Customizations file
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
173e1d0262
|
move the DomBasedXss sources/sinks into the Customizations file
|
2022-04-20 18:10:53 +02:00 |
|
Erik Krogh Kristensen
|
9631b68de9
|
move LocalUrlSanitizingGuard out of the customizations file
|
2022-04-20 18:10:52 +02:00 |
|