Tamas Vajk
|
25977778a2
|
Kotlin: Fix duplicate field entry in declaration stack
|
2022-09-07 15:21:11 +02:00 |
|
Tamas Vajk
|
0c257a1b78
|
Kotlin: add test for incorrect declaration stack
|
2022-09-07 15:21:10 +02:00 |
|
Tony Torralba
|
cd61bd0606
|
Move files from experimental
|
2022-09-07 13:13:40 +02:00 |
|
Tamás Vajk
|
3410dd589d
|
Merge pull request #9783 from tamasvajk/feature/kotlin-stdlib-mad
Kotlin: Add MaD for stdlib
|
2022-09-07 12:57:23 +02:00 |
|
Tony Torralba
|
8e0b4892ee
|
Add Implicit PendingIntents sinks for Compat classes
|
2022-09-07 11:04:22 +02:00 |
|
Tamas Vajk
|
07038d0b3a
|
Fix QL formatting
|
2022-09-07 10:48:22 +02:00 |
|
Tamás Vajk
|
b1e0d73de8
|
Merge pull request #10297 from tamasvajk/kotlin-fix-kotlin-to-java-fn-names
Kotlin: Lookup getter methods based on special JVM method mapping
|
2022-09-07 08:56:19 +02:00 |
|
Ed Minnix
|
0a83cedeb7
|
Unit tests for android:allowBackup query
|
2022-09-06 13:52:43 -04:00 |
|
Tony Torralba
|
ff731f1d83
|
Merge pull request #10138 from atorralba/atorralba/contentresolver-summaries
Java: Add summaries for ContentResolver and adjacent classes
|
2022-09-06 16:28:28 +02:00 |
|
Tony Torralba
|
b745b5ab71
|
Add models for androidx.core.app.NotificationCompat
|
2022-09-06 14:43:13 +02:00 |
|
Tamas Vajk
|
826bbdf834
|
Kotlin: Fix vararg extraction outside of method call
|
2022-09-06 11:32:32 +02:00 |
|
Tamas Vajk
|
cb3c53dee7
|
Kotlin: Add test case for unexpected vararg extraction error
|
2022-09-06 11:32:24 +02:00 |
|
Tony Torralba
|
b94e0d3e69
|
Merge pull request #10251 from atorralba/atorralba/implicit-pendingintent-sinks
Java: Add new AlarmManager sinks to Use of implicit PendingIntents
|
2022-09-06 11:31:27 +02:00 |
|
Tamás Vajk
|
5f841f71db
|
Merge pull request #10291 from tamasvajk/kotlin-fix-array-set
Kotlin: Fix array `set` operator extraction
|
2022-09-06 09:01:05 +02:00 |
|
Tamas Vajk
|
1c21ce0ec4
|
Kotlin: Lookup getter methods based on special JVM method mapping
|
2022-09-05 16:02:25 +02:00 |
|
Tamas Vajk
|
6a90db9b30
|
Kotlin: List diagnostics for special getter method extraction
|
2022-09-05 16:00:40 +02:00 |
|
Ian Lynagh
|
b38ad13f82
|
Merge pull request #10268 from tamasvajk/kotlin-local-function-comments
Kotlin: fix doc comment extraction for local functions
|
2022-09-05 13:35:01 +01:00 |
|
Tamas Vajk
|
6f7f760682
|
Kotlin: Fix array set operator extraction
|
2022-09-05 10:20:07 +02:00 |
|
Tamas Vajk
|
608f99bd0d
|
Kotlin: Add test case for various array set operator overloads
|
2022-09-05 10:19:57 +02:00 |
|
Tamas Vajk
|
37500d274a
|
Accept failing consistency test
|
2022-09-05 08:58:38 +02:00 |
|
Tamas Vajk
|
7daf53fd99
|
Add regenerated models after rebase
|
2022-09-02 16:32:42 +02:00 |
|
Tamas Vajk
|
5004a5fb60
|
Fix failing external model tests
|
2022-09-02 16:12:22 +02:00 |
|
Tamas Vajk
|
9fad42b25d
|
Kotlin: Add manual model for Array.withIndex
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
a144fa06dc
|
Kotlin: Add generated MaD for stdlib
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
57d861337b
|
Kotlin: Add dataflow tests for stdlib calls
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
71cce9cf28
|
Kotlin: Extract error expression for enumValues<T> calls
|
2022-09-02 15:42:05 +02:00 |
|
Tamas Vajk
|
fd0d2ad767
|
Kotlin: Add test for enumValues call with type parameter
|
2022-09-02 15:40:03 +02:00 |
|
Ian Lynagh
|
07b3b15528
|
Merge pull request #10221 from tamasvajk/kotlin-internal
Kotlin: Change `Modifiable::isPublic` to not cover Kotlin `internal` members
|
2022-09-02 11:51:56 +01:00 |
|
Tamas Vajk
|
c77f573a8e
|
Kotlin: fix doc comment extraction for local functions
|
2022-09-02 10:47:08 +02:00 |
|
Tamas Vajk
|
46c52aeaae
|
Kotlin: Add test for doc comment on local functions
|
2022-09-02 10:45:08 +02:00 |
|
Tamas Vajk
|
e66d2dddb6
|
Fix review findings
|
2022-09-01 14:07:27 +02:00 |
|
Tamas Vajk
|
a5415c9c8a
|
Kotlin: Fix array indexer extraction
|
2022-09-01 11:12:14 +02:00 |
|
Tamas Vajk
|
afeea64078
|
Kotlin: Add test case for overloaded array get
|
2022-09-01 11:09:44 +02:00 |
|
Tony Torralba
|
bee4e4b40a
|
Add new AlarmManager sinks
|
2022-09-01 09:47:58 +02:00 |
|
Tamás Vajk
|
bf7437fd2e
|
Merge pull request #10224 from tamasvajk/kotlin-comment-fixes
Kotlin: Fix issues in comment extraction
|
2022-08-31 14:22:09 +02:00 |
|
Michael Nebel
|
1cb6d78d35
|
Merge pull request #10170 from michaelnebel/java/models-io
Java: Update models for commons-io and add negative models.
|
2022-08-31 11:05:09 +02:00 |
|
Tony Torralba
|
2ec53bf78c
|
Merge pull request #9873 from luchua-bc/java/permissive-dot-regex
Java: CWE-625 Query to detect regex dot bypass
|
2022-08-31 10:24:18 +02:00 |
|
luchua-bc
|
e2e87980cc
|
Move pattern check to MatchRegexConfiguration::isSink
|
2022-08-30 22:48:12 +00:00 |
|
Tamas Vajk
|
9ced14672d
|
Kotlin: Assign container class as the owner of init block comments
|
2022-08-30 15:37:55 +02:00 |
|
Tamas Vajk
|
d9b3726ee8
|
Kotlin: Add test case for doc comment on init block
|
2022-08-30 15:37:00 +02:00 |
|
Tamas Vajk
|
3513bb8eed
|
Kotlin: Change Modifiable::isPublic to not cover Kotlin internal members
|
2022-08-30 14:37:27 +02:00 |
|
Tamas Vajk
|
d9086e6328
|
Kotlin: Add test case for internal member accessed from java
|
2022-08-30 14:26:12 +02:00 |
|
Tony Torralba
|
1f83c5833b
|
Merge pull request #10092 from zbazztian/zbazztian/string.replace-taint
Java: Add additional taint steps for java.lang.String methods
|
2022-08-30 12:24:37 +02:00 |
|
Anders Schack-Mulligen
|
e26a7fc4f3
|
Merge pull request #10173 from zbazztian/spring-crudrepository
Java: Add data flow model for Spring's CrudRepository.save() method
|
2022-08-29 15:00:07 +02:00 |
|
Michael Nebel
|
dbfd16647b
|
Java: Add negative model CSV validation test.
|
2022-08-29 14:29:32 +02:00 |
|
Tamás Vajk
|
4f5c06fed7
|
Merge pull request #10169 from tamasvajk/kotlin-array-iterator
Kotlin: fix array iterator extraction
|
2022-08-26 08:33:52 +02:00 |
|
Erik Krogh Kristensen
|
06afe9c0f4
|
Merge pull request #9816 from erik-krogh/msgConsis
Make alert messages consistent across languages
|
2022-08-25 15:20:01 +02:00 |
|
Sebastian Bauersfeld
|
a486a89cee
|
Java: Taint flow through org.springframework.data.repository.CrudRepository.save().
|
2022-08-25 17:58:24 +07:00 |
|
erik-krogh
|
c7aa58252a
|
change "does not seem to check" to "does not check" in unchecked-cast-in-equals queries
|
2022-08-25 12:31:58 +02:00 |
|
Ian Lynagh
|
bf6d9f8c23
|
Merge pull request #10161 from igfoo/igfoo/exec
Make a load of files non-executable
|
2022-08-25 10:05:39 +01:00 |
|