Jonathan Leitschuh
|
c4112e6d4c
|
Post refactor fixiup
|
2022-02-07 15:02:13 -05:00 |
|
Chris Smowton
|
de38638db6
|
Combine CWE-200 queries
|
2022-02-07 14:22:36 -05:00 |
|
Benjamin Muskalla
|
9af50f5216
|
Turn framework coverage into metric query
|
2022-02-07 12:08:18 +01:00 |
|
github-actions[bot]
|
b4ab86c020
|
Post-release preparation for codeql-cli-2.8.0
|
2022-02-06 23:34:07 +00:00 |
|
Artem Smotrakov
|
f53b2fcc62
|
Updated IgnoredHostnameVerification.ql to cover more uses of HostnameVerifier.verify()
|
2022-02-06 11:23:20 +00:00 |
|
Jonathan Leitschuh
|
1f47ea5164
|
Update to new change note format
|
2022-02-04 17:16:12 -05:00 |
|
Jonathan Leitschuh
|
0268dd9f0a
|
Add file creation sanitizer
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
0a621c2801
|
Fix the formatting in TempDirLocalInformationDisclosureFromMethodCall
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
d5c9af31b2
|
Fixup documentation/code from PR feedback
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
f7a4aac525
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a4b5573f53
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a8d25b63ac
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Chris Smowton
|
e795823d97
|
Autoformat TempDirUtils.qll
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
7e514e9ef9
|
Add QLdoc and fix Compiler Errors in Tests
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
cb30385684
|
Update java/ql/src/Security/CWE/CWE-200/TempDirUtils.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
66831989b7
|
Add QLdoc to TempDirUtils
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7e55c92eb4
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f6067d28f9
|
Fix file names and formatting from PR feedback
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
41b5011b81
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7929faedc0
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f910fd4719
|
Remove path flow tracking in 'TempDirLocalInformationDisclosureFromMethodCall'
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
e4c017e888
|
Apply suggestions from code review
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
13fed0e9b6
|
Temp Dir Info Disclosure: Final pass and add documentation
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
bc12e994b0
|
Add java.nio.file.Files API checks
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
ecad7534ae
|
Add mkdirs check
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
cf0ed81575
|
Add TempDir taint tracking for Files.write
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
3a15678b1e
|
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-04 17:10:23 -05:00 |
|
Benjamin Muskalla
|
eee03ebe3b
|
Merge pull request #7767 from bmuskalla/regenerateModelScript
Java: Regenerate framework models automatically
|
2022-02-04 13:29:46 +01:00 |
|
Benjamin Muskalla
|
bc5753cb20
|
Fix path expression
|
2022-02-04 11:43:18 +01:00 |
|
Benjamin Muskalla
|
b747391c74
|
Improve error handling and refactor base path
|
2022-02-04 11:26:19 +01:00 |
|
Tony Torralba
|
4f13bf8941
|
Merge pull request #6492 from atorralba/atorralba/android-cleartext-storage-database
Java: Create new query Cleartext storage of sensitive information in Android databases
|
2022-02-02 16:23:05 +01:00 |
|
github-actions[bot]
|
634134f283
|
Release preparation for version 2.8.0
|
2022-01-27 10:40:20 +00:00 |
|
Benjamin Muskalla
|
c1b5565e4d
|
Automation to regenerate framework models
|
2022-01-27 11:15:10 +01:00 |
|
Andrew Eisenberg
|
a7f755cf12
|
Add new groups for examples packs
Also, remove version numbers. Will make it easier to avoid publishing
the examples packs.
|
2022-01-26 14:49:18 -08:00 |
|
Edoardo Pirovano
|
1b539eb4dc
|
Merge branch rc/3.4 into main
|
2022-01-25 16:22:01 +00:00 |
|
Tony Torralba
|
b59fd4070f
|
Merge pull request #7136 from atorralba/atorralba/promote-insecure-trustmanager
Java: Promote Insecure TrustManager from experimental
|
2022-01-24 14:05:14 +01:00 |
|
luchua-bc
|
27043a09b3
|
File path injection with the JFinal framework
|
2022-01-23 18:07:48 +00:00 |
|
Tony Torralba
|
c5ed5fcaac
|
Apply suggestions from code review
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
|
2022-01-21 16:55:42 +01:00 |
|
Tony Torralba
|
ee84dae164
|
Fix predicate name
|
2022-01-21 16:55:42 +01:00 |
|
Tony Torralba
|
16b61f78e6
|
Fix QLDocs and the qhelp example
|
2022-01-21 16:55:42 +01:00 |
|
Tony Torralba
|
f0604e2e84
|
Added query for Cleartext Storage in Android Database
|
2022-01-21 16:55:42 +01:00 |
|
yoff
|
a77a6ec864
|
Merge pull request #7684 from erik-krogh/patches
small refactorizations across CodeQL
|
2022-01-21 15:04:14 +01:00 |
|
Tony Torralba
|
c7e1df5689
|
Update java/ql/src/Security/CWE/CWE-927/ImplicitPendingIntents.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-01-21 11:57:11 +01:00 |
|
Erik Krogh Kristensen
|
a235f8f023
|
remove redundant inline type casts
|
2022-01-21 11:46:33 +01:00 |
|
Erik Krogh Kristensen
|
f500bccbe4
|
add explicit this to member call
|
2022-01-21 11:46:33 +01:00 |
|
Erik Krogh Kristensen
|
ddfc3bc00f
|
use set literals instead of big disjunctions
|
2022-01-21 11:46:33 +01:00 |
|
Tony Torralba
|
3f6e035016
|
Docs improvements
|
2022-01-21 11:37:02 +01:00 |
|
Erik Krogh Kristensen
|
a77b2b0209
|
Merge pull request #7668 from erik-krogh/simplify-casts
simplify expressions that could be type-casts
|
2022-01-20 15:20:18 +01:00 |
|
github-actions[bot]
|
ab218421da
|
Post-release preparation for codeql-cli-2.7.6
|
2022-01-20 12:59:20 +00:00 |
|
Tony Torralba
|
8767d2db23
|
Don't capitalize the term content provider
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-20 13:23:52 +01:00 |
|