Michael Nebel
|
5623ccf4a0
|
Java: Re-factor NeutralCallable to include all neutrals and introduce NeutralSummaryCallable.
|
2023-08-21 09:59:00 +02:00 |
|
github-actions[bot]
|
098dfb4242
|
Release preparation for version 2.14.3
|
2023-08-18 14:48:15 +00:00 |
|
Edward Minnix III
|
d109637e2d
|
Merge pull request #13413 from egregius313/egregius313/trust-boundary
Java: Trust Boundary Violation Query
|
2023-08-18 10:33:32 -04:00 |
|
Erik Krogh Kristensen
|
08ef31d452
|
Merge pull request #13916 from erik-krogh/limit-java-field-reg
Java: limit field flow when tracking regex strings
|
2023-08-18 12:14:31 +02:00 |
|
Stephan Brandauer
|
480e3bf506
|
Java: update model exclusions logic to cope with new automodel test location
|
2023-08-18 10:28:51 +02:00 |
|
Ed Minnix
|
655a98452a
|
Remove escapeHTML models
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
d468ea9e90
|
Add default sanitizers
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
a36c12ff1f
|
Add trust-boundary-violation sink kind
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
60642c52aa
|
Use non-extending subtype
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
e22a67e7fe
|
Remove unnecessary methods
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
a3a4c31911
|
Replace servlet source node with RemoteFlowSource
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
172b8a6967
|
Documentation fixes
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
b567ec875a
|
Documentation
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
55fae2daaa
|
Added ESAPI sanitizer
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
f58590c6a9
|
Trust Boundary Work
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
ab9f0240d3
|
Add taint steps for HTML encoding methods
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
b9f2da7875
|
Comments and import fixes
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
a8b7e70d01
|
Convert trust boundary models to MaD
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
76438f13b6
|
Trust Boundary Query
|
2023-08-17 13:05:36 -04:00 |
|
Edward Minnix III
|
41a527cf72
|
Merge pull request #13934 from egregius313/egregius313/add-dashes-to-sha-algorithms
Java: Add dashes to SHA algorithm names in `Encryption.qll`
|
2023-08-17 13:03:15 -04:00 |
|
Anders Schack-Mulligen
|
e27aad9d6c
|
Merge pull request #13987 from aschackmull/java/rangeanalysis-joinorder-fix
Java: Join-order fix in RangeAnalysis.
|
2023-08-17 14:47:26 +02:00 |
|
Anders Schack-Mulligen
|
f8a0b6cd22
|
Java: Add nomagic
|
2023-08-17 11:20:02 +02:00 |
|
Anders Schack-Mulligen
|
0afda68ba1
|
Java: Join-order fix in RangeAnalysis.
|
2023-08-17 11:07:24 +02:00 |
|
Jeroen Ketema
|
33e8310625
|
Merge branch 'main' into shared-taint-tracking
|
2023-08-17 00:14:25 +02:00 |
|
Ed Minnix
|
cafd08521e
|
Add change note
|
2023-08-15 23:46:12 -04:00 |
|
Ed Minnix
|
7cfe78a52d
|
Add dashes to SHA algorithm names in Encryption.qll
|
2023-08-15 23:42:17 -04:00 |
|
Michael Nebel
|
a95aad51bd
|
Merge pull request #13546 from michaelnebel/java/withoutelement
Java: Support for With[out]Element for MaD.
|
2023-08-15 10:03:03 +02:00 |
|
Henry Mercer
|
1213eba630
|
Merge branch 'main' into post-release-prep/codeql-cli-2.14.2
|
2023-08-11 13:54:55 +01:00 |
|
github-actions[bot]
|
432c21d4fb
|
Post-release preparation for codeql-cli-2.14.2
|
2023-08-09 18:45:18 +00:00 |
|
Anders Schack-Mulligen
|
0ca3f3308b
|
Merge pull request #13478 from aschackmull/java/varcapture
Java: Add proper support for variable capture flow.
|
2023-08-08 16:22:56 +02:00 |
|
Anders Schack-Mulligen
|
9d59f50340
|
Java: Review fixes.
|
2023-08-08 13:37:40 +02:00 |
|
Michael Nebel
|
0ed724eb13
|
Java: Make a flow summary for Set.clear using WithoutElement and introduce appropriate tests.
|
2023-08-08 11:10:08 +02:00 |
|
Anders Schack-Mulligen
|
ab334f6c1b
|
Java: Always apply heuristic query regardless of existing models.
|
2023-08-08 10:01:43 +02:00 |
|
erik-krogh
|
45c39e6072
|
limit field flow when tracking regex strings in Java
|
2023-08-08 09:01:23 +02:00 |
|
github-actions[bot]
|
79c90fa36a
|
Release preparation for version 2.14.2
|
2023-08-07 18:08:52 +00:00 |
|
Jeroen Ketema
|
8b6a7985db
|
Refactor the traint-tracking library to follow the dataflow library refactoring
|
2023-08-07 15:23:15 +02:00 |
|
Jeroen Ketema
|
5d2984b7a5
|
Merge branch 'main' into shared-taint-tracking
|
2023-08-07 15:22:29 +02:00 |
|
Jami
|
5862cd2378
|
Merge pull request #13889 from jcogs33/jcogs33/fix-some-models
Java: remove duplicate models
|
2023-08-07 08:46:18 -04:00 |
|
Edward Minnix III
|
58d8a2d77f
|
Merge pull request #13899 from egregius313/egregius313/random-nextbytes-typo-fix
Java: Fix typo in `StdlibRandomSource::getOutput`
|
2023-08-07 07:36:44 -04:00 |
|
Tom Hvitved
|
2126ab0dde
|
Merge pull request #13901 from hvitved/dataflow/refactor
Data flow: Refactor shared library
|
2023-08-07 13:22:53 +02:00 |
|
Michael Nebel
|
e62ec888c0
|
Merge pull request #13506 from michaelnebel/java/threatmodels
Java: Threat Models
|
2023-08-07 12:50:01 +02:00 |
|
Tony Torralba
|
fb0102b763
|
Java: New models for JAX-RS
|
2023-08-07 11:52:23 +02:00 |
|
Tom Hvitved
|
693970f243
|
Java: Adjust to data flow refactor
|
2023-08-07 11:35:23 +02:00 |
|
Tony Torralba
|
43b9199734
|
Java: Improved JaxWsEndpoint::getARemoteMethod
|
2023-08-07 10:21:58 +02:00 |
|
Ed Minnix
|
23e2eb11dd
|
Change note
|
2023-08-07 00:23:58 -04:00 |
|
Ed Minnix
|
fe4eef0bcb
|
Fix typo, replace getBytes with nextBytes
|
2023-08-07 00:16:47 -04:00 |
|
Jeroen Ketema
|
747cd1745a
|
Update all languages to use the shared taint-tracking library
|
2023-08-04 22:53:25 +02:00 |
|
Jami Cogswell
|
19622aec49
|
Java: remove duplicate 'Files.newOutputStream' ai model
|
2023-08-04 14:06:57 -04:00 |
|
Jami Cogswell
|
e64d581f7a
|
Java: remove duplicate 'Files.newInputStream' ai model
|
2023-08-04 14:05:05 -04:00 |
|
Jami Cogswell
|
d2a24dee7f
|
Java: remove duplicate 'Files.delete' ai model
|
2023-08-04 14:02:59 -04:00 |
|