Geoffrey White
|
18f80eb3e3
|
C++: Loosen a few constraints slightly.
|
2022-03-28 11:16:57 +01:00 |
|
Geoffrey White
|
3fed7bf6d0
|
C++: Extend cpp/cleartext-transmission using PrivateData.qll.
|
2022-03-28 11:16:56 +01:00 |
|
Geoffrey White
|
bb272003b4
|
C++: More test cases.
|
2022-03-28 10:54:54 +01:00 |
|
Geoffrey White
|
9f3fd57534
|
Merge branch 'main' into cwe497b
|
2022-03-25 11:57:30 +00:00 |
|
Jeroen Ketema
|
8b4c42dd07
|
C++: Add cpp/command-line-injection test using a wrapper macro
|
2022-03-21 11:19:54 +01:00 |
|
Jeroen Ketema
|
f8198c3123
|
C++: Use flow states in cpp/command-line-injection
|
2022-03-18 20:06:45 +01:00 |
|
Jeroen Ketema
|
d37ef1b5ca
|
C++: Add command line injection test that currently results in a false positive
|
2022-03-18 16:12:09 +01:00 |
|
Jeroen Ketema
|
459870ac1e
|
C++: Add additional command line injection tests
|
2022-03-18 13:42:27 +01:00 |
|
Geoffrey White
|
92d748e006
|
C++: Fix ODR/dbcheck issue in test.
|
2022-03-15 20:00:19 +00:00 |
|
Geoffrey White
|
28315df405
|
Merge branch 'main' into cwe497b
|
2022-03-15 11:23:00 +00:00 |
|
Geoffrey White
|
d1b04b4e07
|
C++: Use asDefiningArgument() where appropriate.
|
2022-03-14 17:53:47 +00:00 |
|
Mathias Vorreiter Pedersen
|
3c17d90e3b
|
C++: Accept test changes.
|
2022-03-11 09:30:44 +00:00 |
|
Mathias Vorreiter Pedersen
|
f2676968f0
|
C++: Actally convert 'cpp/overflow-destination' to a path-problem query.
|
2022-03-09 13:49:52 +00:00 |
|
Mathias Vorreiter Pedersen
|
8a8fb692a3
|
C++: Use a 'TaintTracking::Configuration' for 'cpp/uncontrolled-allocation-size'.
|
2022-03-09 12:09:32 +00:00 |
|
Mathias Vorreiter Pedersen
|
2328898b19
|
C++: Use a 'TaintTracking::Configuration' for 'cpp/unclear-array-index-validation'.
|
2022-03-09 12:09:27 +00:00 |
|
Mathias Vorreiter Pedersen
|
624795cbbf
|
Merge pull request #8059 from rdmarsh2/rdmarsh2/cpp/insufficient-key-strength
C++: new query for insufficient key strength
|
2022-03-04 17:11:44 +00:00 |
|
Robert Marsh
|
280fdbfc1b
|
C++: accept test output from perf improvement
The last commit removed some source nodes from the dataflow graph, which
changed the test expectations slightly. No result changes occurred.
|
2022-03-04 11:39:10 -05:00 |
|
Geoffrey White
|
88b7a085b0
|
C++: Make the bulk of test cases in tests.cpp more relevant.
|
2022-03-03 10:40:17 +00:00 |
|
Geoffrey White
|
07b4bf7023
|
C++: Use the same trick as in ExposedSystemData to catch a few more results.
|
2022-03-03 10:33:39 +00:00 |
|
Geoffrey White
|
6e5729c924
|
C++: Fix typo and adjust violation message wording.
|
2022-03-03 10:28:53 +00:00 |
|
Geoffrey White
|
70e4a409fd
|
C++: Add the new query to tests.
|
2022-03-02 17:56:53 +00:00 |
|
Geoffrey White
|
67aa1449ce
|
C++: Add some more test cases (moved from the private repo).
|
2022-03-02 17:23:07 +00:00 |
|
Geoffrey White
|
19718fa280
|
C++: Add a couple of new test cases.
|
2022-03-02 15:18:04 +00:00 |
|
Geoffrey White
|
da740cfa05
|
C++: Test layout.
|
2022-03-02 15:18:04 +00:00 |
|
Geoffrey White
|
5402b02fd7
|
Merge branch 'main' into cwe497
|
2022-03-01 11:58:24 +00:00 |
|
Mathias Vorreiter Pedersen
|
dfd30e46b0
|
Merge pull request #8227 from geoffw0/319improve
C++: Promote cpp/non-https-url
|
2022-02-25 08:48:44 +00:00 |
|
Geoffrey White
|
899ae90ba4
|
C++: Add GVN.
|
2022-02-24 17:22:37 +00:00 |
|
Geoffrey White
|
0bb9a95563
|
C++: Extend tests.
|
2022-02-24 17:15:29 +00:00 |
|
Geoffrey White
|
6c40cda68d
|
C++: Pragmatic solution to include more sinks (plus autoformat changes).
|
2022-02-24 12:10:34 +00:00 |
|
Geoffrey White
|
c16302be13
|
C++: Fix the FP.
|
2022-02-24 10:54:08 +00:00 |
|
Geoffrey White
|
326dfa5bc2
|
C++: Add test cases.
|
2022-02-23 18:37:58 +00:00 |
|
Robert Marsh
|
a37f746dff
|
C++: fix FP and add paths in InsufficientKeySize
|
2022-02-22 15:38:50 -05:00 |
|
Geoffrey White
|
4908eaf5ec
|
C++: Typos.
|
2022-02-22 14:33:11 +00:00 |
|
Robert Marsh
|
103796dfa8
|
C++: respond to PR comments on InsufficientKeySize
|
2022-02-16 14:58:29 -05:00 |
|
Geoffrey White
|
703f18b82f
|
C++: Better deduplication.
|
2022-02-15 17:52:27 +00:00 |
|
Geoffrey White
|
c4d9c1d9e7
|
C++: Reduce result duplication.
|
2022-02-11 16:03:38 +00:00 |
|
Geoffrey White
|
00ba76b7e4
|
C++: Convert to IR taint tracking.
|
2022-02-11 13:00:42 +00:00 |
|
Robert Marsh
|
dbe4770c7d
|
C++: add initial insufficient key size query
|
2022-02-10 14:53:40 -05:00 |
|
Geoffrey White
|
b0c2a144cc
|
C++: Remove no longer relevant tests.
|
2022-02-10 11:11:31 +00:00 |
|
Geoffrey White
|
20ad92a82e
|
C++: Filter noisiest sources.
|
2022-02-10 11:11:30 +00:00 |
|
Geoffrey White
|
7b5b2fdcd1
|
C++: Modernize cpp/system-data-exposure as a path-problem using IR taint, RemoteFlowSinkFunction.
|
2022-02-10 11:11:26 +00:00 |
|
Geoffrey White
|
5490809bcf
|
C++: Expand tests.
|
2022-02-10 10:43:21 +00:00 |
|
Jeroen Ketema
|
1f2865c7cc
|
Merge pull request #7798 from jketema/missing-open-arg
C++: Add query for missing mode argument in `open`/`openat` calls
|
2022-02-07 12:01:44 +01:00 |
|
Geoffrey White
|
8031c3f699
|
Merge branch 'main' into clrtxt9
|
2022-02-03 17:01:59 +00:00 |
|
Geoffrey White
|
02b1774d7f
|
C++: Switch from GVN to localFlow.
|
2022-02-03 16:00:26 +00:00 |
|
Geoffrey White
|
3cfd1b5052
|
C++: More test cases.
|
2022-02-03 15:11:59 +00:00 |
|
Geoffrey White
|
4048ba0a1c
|
C++: Fix false positives around terminal output.
|
2022-02-02 17:59:28 +00:00 |
|
Geoffrey White
|
39a2ffd438
|
C++: Fix false positives around 'stdin'.
|
2022-02-02 17:39:14 +00:00 |
|
Jeroen Ketema
|
f32500306a
|
Address review comments
|
2022-02-02 17:24:55 +01:00 |
|
Geoffrey White
|
cc20969bdd
|
C++: Add test cases based on some remaining real world FPs.
|
2022-02-02 16:15:59 +00:00 |
|