Tony Torralba
|
c3b1ef2cdf
|
Merge branch 'main' into atorralba/java/command-injection-mad-sinks
|
2023-06-02 08:57:24 +02:00 |
|
Jami
|
1a82e21fdb
|
Merge pull request #13136 from jcogs33/jcogs33/revamp-java-source-kinds
Java: change `android-widget` MaD source kind to `remote`
|
2023-06-01 14:18:02 -04:00 |
|
Jami
|
617107de35
|
Merge pull request #12916 from jcogs33/jcogs33/revamp-java-sink-kinds
Java: revamp MaD sink kinds
|
2023-06-01 12:48:30 -04:00 |
|
Jami Cogswell
|
119b446dbc
|
Java: add change note
|
2023-06-01 12:25:26 -04:00 |
|
Jami Cogswell
|
9853a66b32
|
Java: update change note
|
2023-05-31 15:51:07 -04:00 |
|
Jami Cogswell
|
6bb6802fb8
|
Java: add change note draft
|
2023-05-31 15:51:07 -04:00 |
|
Ian Lynagh
|
0090429d53
|
Kotlin: Support 1.9.0
|
2023-05-31 19:43:45 +01:00 |
|
Arthur Baars
|
c211b704f3
|
Merge pull request #13272 from github/post-release-prep/codeql-cli-2.13.3
Post-release preparation for codeql-cli-2.13.3
|
2023-05-31 15:33:12 +02:00 |
|
Taus
|
b39a5a64af
|
Merge pull request #13317 from github/java/update-mad-decls-after-triage-2023-05-30T14-11-29
Java: Update MaD Declarations after Triage
|
2023-05-31 11:40:49 +02:00 |
|
Tony Torralba
|
482bb94ad9
|
Merge pull request #13179 from pwntester/java_gson
[Java] Add basic support for Google's Gson library
|
2023-05-31 11:16:19 +02:00 |
|
Arthur Baars
|
490d22d123
|
Merge remote-tracking branch 'upstream/main' into post-release-prep/codeql-cli-2.13.3
|
2023-05-30 21:31:28 +02:00 |
|
Tony Torralba
|
0151a728f8
|
Add change note
|
2023-05-30 17:53:03 +02:00 |
|
Taus
|
00e4c455b5
|
Update MaD Declarations after Triage
|
2023-05-30 16:11:30 +02:00 |
|
Tony Torralba
|
903fdb0cb8
|
Java: Add models for the Play Framework
|
2023-05-26 10:23:43 +02:00 |
|
Tony Torralba
|
a276cc3094
|
Convert all command injection sinks to MaD format
|
2023-05-25 11:41:32 +02:00 |
|
Tony Torralba
|
7d0b02e267
|
Merge pull request #13248 from atorralba/atorralba/java/nio-files-copy-models-fix
Java: Tweak java.nio.file.Files.copy models
|
2023-05-24 10:55:15 +02:00 |
|
Edward Minnix III
|
52340802bb
|
Merge pull request #13097 from egregius313/egregius313/java/webgoat/ssrf-regex-fix
Java: Add constraint to `HostnameSanitizingPrefix` to prevent false negatives in SSRF queries
|
2023-05-23 10:50:43 -04:00 |
|
Tony Torralba
|
6f012d51c0
|
Merge pull request #13091 from atorralba/atorralba/java/inputstreamwrapper-transitive
Java: Make inputStreamWrapper consider supertypes transitively
|
2023-05-23 13:28:17 +02:00 |
|
Tony Torralba
|
5c5f910130
|
Add change note
|
2023-05-23 10:31:28 +02:00 |
|
github-actions[bot]
|
7aa23cf11d
|
Release preparation for version 2.13.3
|
2023-05-22 20:47:00 +00:00 |
|
Ed Minnix
|
2d69f81d85
|
Add change note
|
2023-05-22 15:57:15 -04:00 |
|
Tony Torralba
|
183915410d
|
Add change note
|
2023-05-22 15:01:25 +02:00 |
|
Tony Torralba
|
a48fa652ce
|
Java: Add SQLi sinks for Spring JDBC
|
2023-05-12 10:57:49 +02:00 |
|
Stephan Brandauer
|
61b0514b53
|
Merge pull request #13122 from github/java/update-mad-decls-after-triage-2023-05-11T08-52-07
Java: Update MaD Declarations after Triage
|
2023-05-11 16:04:36 +02:00 |
|
Stephan Brandauer
|
b0ec089a3a
|
Update MaD Declarations after Triage
|
2023-05-11 10:52:09 +02:00 |
|
Tony Torralba
|
e1f868b976
|
Merge pull request #12965 from atorralba/atorralba/java/apache-commons-net-models
Java: Add manual models for `org.apache.commons.net`
|
2023-05-10 16:28:19 +02:00 |
|
Tony Torralba
|
9839eb1fd2
|
Update java/ql/lib/change-notes/2023-05-02-apache-commons-net-models.md
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-05-10 10:15:55 +02:00 |
|
Michael Nebel
|
f2f9944a1c
|
Merge pull request #12931 from michaelnebel/neutralkinds
Java/C#: Introduce kind for neutrals.
|
2023-05-09 08:42:38 +02:00 |
|
Edward Minnix III
|
05b1bd881e
|
Merge pull request #12852 from egregius313/egregius313/java/webgoat/model-jwsheader
Java: Model `io.jsonwebtoken.SigningKeyResolverAdapter` and `io.jsonwebtoken.JwsHeader`
|
2023-05-08 10:57:34 -04:00 |
|
Michael Nebel
|
7858da66e3
|
C#/Java: Add change note.
|
2023-05-08 16:18:59 +02:00 |
|
Edward Minnix III
|
2d5b35067e
|
Merge pull request #12721 from egregius313/egregius313/java/move-configurations-to-libraries
Java: Move more dataflow configurations to `*Query.qll` files
|
2023-05-04 20:14:22 -04:00 |
|
Ed Minnix
|
62cbcdb30c
|
Add change note
|
2023-05-04 16:52:40 -04:00 |
|
Ed Minnix
|
3100e98513
|
Add missing change notes and update date
|
2023-05-04 10:25:17 -04:00 |
|
Ed Minnix
|
c319ee4c0d
|
Add TempDirLocalInformationDisclosureQuery
|
2023-05-04 10:25:16 -04:00 |
|
Ed Minnix
|
b087cf9a0a
|
Add Arithmetic query libraries
|
2023-05-04 10:25:16 -04:00 |
|
Ed Minnix
|
77ee80fd81
|
Add missing change notes
|
2023-05-04 10:25:16 -04:00 |
|
Ed Minnix
|
24b00bac11
|
Add UnsafeHostnameVerificationQuery
|
2023-05-04 10:25:16 -04:00 |
|
Ed Minnix
|
e4f47ece43
|
Add ResponseSplittingLocalQuery
|
2023-05-04 10:15:00 -04:00 |
|
Ed Minnix
|
91b3533035
|
Add SqlTaintedLocalQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
a0f7575b34
|
Add StackTraceExposureQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
aff299eafd
|
Add ExecTaintedLocal
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
b39d5088de
|
Add InsecureCookieQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
0249187282
|
Add ExternallyControlledFormatStringLocalQuery.qll
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
cc22a7d4b4
|
Add XssLocalQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
c2b6a3f4e0
|
Add XPathInjectionQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
c15ce27957
|
Add SqlConcatenatedQuery
|
2023-05-04 10:14:59 -04:00 |
|
Ed Minnix
|
1af6d5f7b3
|
Add TaintedPermissionsCheckQuery
|
2023-05-04 10:14:59 -04:00 |
|
Jami Cogswell
|
2e683b3dd2
|
Java: add change note
|
2023-05-03 10:43:50 -04:00 |
|
Tony Torralba
|
ec44aa2597
|
Add change note
|
2023-05-02 15:31:20 +02:00 |
|
github-actions[bot]
|
3bd29171fb
|
Release preparation for version 2.13.1
|
2023-04-28 12:14:35 +00:00 |
|