Tony Torralba
|
ff731f1d83
|
Merge pull request #10138 from atorralba/atorralba/contentresolver-summaries
Java: Add summaries for ContentResolver and adjacent classes
|
2022-09-06 16:28:28 +02:00 |
|
Anders Schack-Mulligen
|
b84dca92cf
|
Merge pull request #10240 from aschackmull/java/scc-typeflow
Java: Support SCCs in TypeFlow.
|
2022-09-06 15:43:20 +02:00 |
|
Tony Torralba
|
b745b5ab71
|
Add models for androidx.core.app.NotificationCompat
|
2022-09-06 14:43:13 +02:00 |
|
Anders Schack-Mulligen
|
bc57d87303
|
Java: Address comments.
|
2022-09-06 13:59:54 +02:00 |
|
Tony Torralba
|
b94e0d3e69
|
Merge pull request #10251 from atorralba/atorralba/implicit-pendingintent-sinks
Java: Add new AlarmManager sinks to Use of implicit PendingIntents
|
2022-09-06 11:31:27 +02:00 |
|
erik-krogh
|
a86a940df7
|
add getRepr() and toString() on RelevantState
|
2022-09-05 13:27:34 +02:00 |
|
Erik Krogh Kristensen
|
0162bc3c77
|
use RelevantState inside the lastStartState predicate
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-09-05 11:22:12 +02:00 |
|
erik-krogh
|
c38062ce93
|
convert RelevantState to a class in the PrefixConstruction module
|
2022-09-02 20:26:31 +02:00 |
|
Tamas Vajk
|
7daf53fd99
|
Add regenerated models after rebase
|
2022-09-02 16:32:42 +02:00 |
|
Tamas Vajk
|
2138e491a5
|
Add change note
|
2022-09-02 16:12:22 +02:00 |
|
Tamas Vajk
|
8c5d220dc0
|
Add optional friendly name parameter to MaD generator
|
2022-09-02 16:12:22 +02:00 |
|
Tamas Vajk
|
09e62058ae
|
Generate negative summaries
|
2022-09-02 16:12:22 +02:00 |
|
Tamas Vajk
|
9fad42b25d
|
Kotlin: Add manual model for Array.withIndex
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
bb82bcabbe
|
Kotlin: move and rename KotlinStdLib.qll to kotlin/StdLib.qll
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
8c7fdb969d
|
Kotlin: Regenerating StdLib models with already existing models
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
a144fa06dc
|
Kotlin: Add generated MaD for stdlib
|
2022-09-02 16:12:21 +02:00 |
|
Tamas Vajk
|
57d861337b
|
Kotlin: Add dataflow tests for stdlib calls
|
2022-09-02 16:12:21 +02:00 |
|
Michael Nebel
|
5511bc8e28
|
Java/Ruby/Swift: Sync files.
|
2022-09-02 15:17:24 +02:00 |
|
Ian Lynagh
|
07b3b15528
|
Merge pull request #10221 from tamasvajk/kotlin-internal
Kotlin: Change `Modifiable::isPublic` to not cover Kotlin `internal` members
|
2022-09-02 11:51:56 +01:00 |
|
Tamas Vajk
|
bea0ce9ff9
|
Fix review findings
|
2022-09-02 09:20:20 +02:00 |
|
Ian Lynagh
|
710ba3cb14
|
Merge pull request #10257 from igfoo/igfoo/hasModifier
Java: Correct hasModifier documentation
|
2022-09-01 15:49:06 +01:00 |
|
Edoardo Pirovano
|
8f332714f4
|
Merge pull request #10260 from github/edoardo/3.7-mergeback
Merge `rc/3.7` into `main`
|
2022-09-01 15:44:17 +01:00 |
|
Tamas Vajk
|
e66d2dddb6
|
Fix review findings
|
2022-09-01 14:07:27 +02:00 |
|
Ian Lynagh
|
7ed18f1b32
|
Java: Correct hasModifier documentation
|
2022-09-01 11:52:07 +01:00 |
|
Tony Torralba
|
bee4e4b40a
|
Add new AlarmManager sinks
|
2022-09-01 09:47:58 +02:00 |
|
Ian Lynagh
|
7dc5bdafe3
|
Merge pull request #10186 from github/post-release-prep/codeql-cli-2.10.4
Post-release preparation for codeql-cli-2.10.4
|
2022-08-31 17:29:57 +01:00 |
|
Anders Schack-Mulligen
|
784eef3f2c
|
Java: Support SCCs in TypeFlow.
|
2022-08-31 13:20:00 +02:00 |
|
Michael Nebel
|
1cb6d78d35
|
Merge pull request #10170 from michaelnebel/java/models-io
Java: Update models for commons-io and add negative models.
|
2022-08-31 11:05:09 +02:00 |
|
Ed Minnix
|
6485e73cd3
|
Added documentation for providesMainIntent pred
|
2022-08-30 13:00:44 -04:00 |
|
Ed Minnix
|
500a6f3b86
|
Add check for files which provide the app launcher
Adds support for filtering which applications include the
`android.intent.action.MAIN` intent.
|
2022-08-30 12:54:26 -04:00 |
|
Ed Minnix
|
b5c54f5a3b
|
Add check for android:allowBackup explicitly set
`android:allowBackup` has a default value of `true`. So we want to flag
any file which explicitly sets it.
|
2022-08-30 12:53:12 -04:00 |
|
Erik Krogh Kristensen
|
72942afe3e
|
Merge pull request #10220 from erik-krogh/overlapsWithNothing
print a correct range for ranges that doesn't contain any alpha-numeric chars
|
2022-08-30 15:38:34 +02:00 |
|
Anders Schack-Mulligen
|
4070860d2b
|
Merge pull request #10208 from aschackmull/java/dispatch-fixes
Java: A couple of small virtual dispatch fixes
|
2022-08-30 15:03:48 +02:00 |
|
Tamas Vajk
|
3513bb8eed
|
Kotlin: Change Modifiable::isPublic to not cover Kotlin internal members
|
2022-08-30 14:37:27 +02:00 |
|
erik-krogh
|
7fd426e748
|
print a correct range for ranges that doesn't contain any alpha-numeric chars
|
2022-08-30 13:57:11 +02:00 |
|
Tony Torralba
|
1f83c5833b
|
Merge pull request #10092 from zbazztian/zbazztian/string.replace-taint
Java: Add additional taint steps for java.lang.String methods
|
2022-08-30 12:24:37 +02:00 |
|
Erik Krogh Kristensen
|
8f0b999c31
|
Merge pull request #10207 from erik-krogh/fixRank
fix performance issue in the ReDoS query
|
2022-08-30 10:17:11 +02:00 |
|
erik-krogh
|
e2caf3e8c0
|
put a limit on the length of the equivalent range
|
2022-08-30 09:29:22 +02:00 |
|
erik-krogh
|
f47b097d7c
|
put a limit on the length of the equivalent range
|
2022-08-29 21:03:52 +02:00 |
|
Anders Schack-Mulligen
|
e26a7fc4f3
|
Merge pull request #10173 from zbazztian/spring-crudrepository
Java: Add data flow model for Spring's CrudRepository.save() method
|
2022-08-29 15:00:07 +02:00 |
|
Michael Nebel
|
e8d726606b
|
C#/Java: Add descriptive comment on negative summaries in ExternalFlow.
|
2022-08-29 14:29:32 +02:00 |
|
Michael Nebel
|
91abf79404
|
Java: Update negative summaries where static initializers has been excluded.
|
2022-08-29 14:29:32 +02:00 |
|
Michael Nebel
|
37aa6b2c5f
|
C#: Add file level QL Doc.
|
2022-08-29 14:29:32 +02:00 |
|
Michael Nebel
|
290c35e7c6
|
Java: Use negative summary models in unsupported external api telemetry query.
|
2022-08-29 14:28:55 +02:00 |
|
Michael Nebel
|
23e0ee66e0
|
Java: Add negative models for commons-io.
|
2022-08-29 14:28:55 +02:00 |
|
Michael Nebel
|
beb85c20f2
|
Java: Update commons-io generated positive models based on main.
|
2022-08-29 14:28:55 +02:00 |
|
Anders Schack-Mulligen
|
bd6acc0d75
|
Java: Refactor upcastCand, and track type flow for upcasts to unbound generics.
|
2022-08-29 13:57:39 +02:00 |
|
Anders Schack-Mulligen
|
fc415b32c2
|
Java: Bugfix in TypeFlow.
|
2022-08-29 13:50:13 +02:00 |
|
Anders Schack-Mulligen
|
e89b42fc11
|
Java: Allow dispatch to methods on abstract classes without subtypes.
|
2022-08-29 13:48:55 +02:00 |
|
erik-krogh
|
77949cbeb3
|
add context to the rankState predicate in ExponentialBackTracking.qll
|
2022-08-29 13:42:05 +02:00 |
|