Tom Hvitved
|
05ec75558d
|
Java: Update test
|
2020-04-17 13:49:08 +02:00 |
|
Pavel Avgustinov
|
6737e99d65
|
Merge pull request #3209 from hmakholm/baselib-extractor
Add extractor field in base language QL packs
|
2020-04-09 15:24:49 +01:00 |
|
yo-h
|
697b273e32
|
Java 14: update expected test output
|
2020-04-07 22:22:10 -04:00 |
|
yo-h
|
9d2f76849b
|
Java 14: switch expressions are no longer in preview
|
2020-04-07 22:22:07 -04:00 |
|
Henning Makholm
|
d1ff3211ef
|
Add extractor fields to test qlpack.yml files.
|
2020-04-06 19:21:41 +02:00 |
|
Grzegorz Golawski
|
1d8da905ac
|
Make the test runnable via codeql test run
|
2020-04-03 21:44:13 +02:00 |
|
Grzegorz Golawski
|
f05b2af69d
|
Move to experimental
|
2020-04-03 00:27:51 +02:00 |
|
Grzegorz Golawski
|
cffe89f652
|
Merge branch 'master' into java-spring-boot-actuators
|
2020-04-02 22:06:25 +02:00 |
|
Anders Schack-Mulligen
|
b2769b42ed
|
Merge pull request #3117 from adityasharad/java/jackson-taint-steps
Java: Add taint steps through Jackson serialization methods.
|
2020-03-30 10:34:56 +02:00 |
|
Aditya Sharad
|
a6e039b284
|
Java: Add tests for Jackson taint steps.
Add stubs for jackson-databind-2.10.
Based on http://fasterxml.github.io/jackson-databind/javadoc/2.10.
Test taint through Jackson serialization APIs.
|
2020-03-24 12:59:24 -07:00 |
|
Anders Schack-Mulligen
|
d8edae96df
|
Java: Add test.
|
2020-03-24 15:24:17 +01:00 |
|
Anders Schack-Mulligen
|
e1a0c2d846
|
Java: Add minor test case to typeflow qltest.
|
2020-03-11 13:13:19 +01:00 |
|
Anders Schack-Mulligen
|
4298a3a931
|
Java: Add test.
|
2020-03-09 11:16:59 +01:00 |
|
Anders Schack-Mulligen
|
4601639bad
|
Java: Document a FP in a test.
|
2020-03-03 13:39:26 +01:00 |
|
semmle-qlci
|
ec90627a64
|
Merge pull request #2909 from yo-h/experimental
Approved by aschackmull, jbj, max-schaefer, tausbn
|
2020-02-28 03:15:58 +00:00 |
|
yo-h
|
f8bf055fe1
|
Merge pull request #2927 from aschackmull/java/taintgettersetter-tests
Java: Add some more taint-getter-setter tests.
|
2020-02-27 22:12:25 -05:00 |
|
Anders Schack-Mulligen
|
33f6392be5
|
Java: Add some more taint-getter-setter tests.
|
2020-02-27 10:47:25 +01:00 |
|
Anders Schack-Mulligen
|
0c30d7cced
|
Java: Update test output.
|
2020-02-27 10:28:12 +01:00 |
|
yo-h
|
43bcd5b26c
|
Add guidelines for experimental CodeQL queries and libraries
|
2020-02-24 15:08:31 -05:00 |
|
Grzegorz Golawski
|
fda4ab155a
|
CodeQL query to detect open Spring Boot actuator endpoints
|
2020-02-23 20:03:41 +01:00 |
|
semmle-qlci
|
ecad925101
|
Merge pull request #2631 from hvitved/dataflow/generalize-flow-summaries
Approved by aschackmull
|
2020-02-17 18:22:46 +00:00 |
|
Anders Schack-Mulligen
|
75f7671e75
|
Java: Fix .expected
|
2020-02-06 10:27:44 +01:00 |
|
Anders Schack-Mulligen
|
ba86dea657
|
Java: Improve taint step modeling to use postupdate nodes.
|
2020-02-05 15:33:29 +01:00 |
|
Anders Schack-Mulligen
|
7d19eb7c05
|
Java: Add LICENSE.txt
|
2020-02-05 09:38:16 +01:00 |
|
Tom Hvitved
|
15ee1e37b9
|
Java: Follow-up changes
|
2020-02-04 14:09:12 +01:00 |
|
Anders Schack-Mulligen
|
2b1723dd88
|
Java: Move some taint tests.
|
2020-02-04 13:21:31 +01:00 |
|
Anders Schack-Mulligen
|
3b81c3b95c
|
Merge pull request #2651 from ggolawski/java-ldap-injection
Java LDAP Injection (CWE-90)
|
2020-01-31 16:43:52 +01:00 |
|
yo-h
|
b542b08c95
|
Merge pull request #2726 from aschackmull/java/outputstream-write-taint
Java: Improve taint for OutputStream.write and InputStream.read.
|
2020-01-30 18:24:00 -05:00 |
|
yo-h
|
563be9f817
|
Merge pull request #2719 from aschackmull/java/deprecate-parexpr
Java: Deprecate ParExpr
|
2020-01-30 18:23:13 -05:00 |
|
Grzegorz Golawski
|
3fd8d9eb5c
|
Rename CWE-90 into CWE-090
|
2020-01-30 22:33:20 +01:00 |
|
yo-h
|
dd517a433a
|
Merge pull request #2671 from aschackmull/java/null-flow
Java: Allow null literals as sources in data flow.
|
2020-01-30 09:47:46 -05:00 |
|
Anders Schack-Mulligen
|
9bea581a23
|
Java: Improve taint for OutputStream.write and InputStream.read.
|
2020-01-30 14:29:56 +01:00 |
|
Anders Schack-Mulligen
|
ea3d7b1b2f
|
Java: Adjust stubs and unit test.
|
2020-01-30 11:27:33 +01:00 |
|
Anders Schack-Mulligen
|
75c549baa1
|
Java: Deprecate ParExpr.
|
2020-01-30 10:52:16 +01:00 |
|
Anders Schack-Mulligen
|
9391058363
|
Java: Add unit test for ldap injection.
|
2020-01-29 11:37:33 +01:00 |
|
yo-h
|
97069a7988
|
Merge pull request #2683 from aschackmull/java/lshift32
Java: Add new query for large left shifts and bugfix ConstantExpAppearsNonConstant.
|
2020-01-28 13:30:26 -05:00 |
|
Anders Schack-Mulligen
|
4bd332ddca
|
Java: Add Expr.isParenthesized, adjust VarAccess.toString, and fix tests.
|
2020-01-28 10:15:48 +01:00 |
|
Anders Schack-Mulligen
|
4cb28d9b1d
|
Java: Add new query for large left shifts and bugfix ConstantExpAppearsNonConstant.
|
2020-01-28 10:13:34 +01:00 |
|
Chris Gavin
|
0e8d435ca1
|
Java: Add a test for java/suspicious-date-format.
|
2020-01-27 11:57:59 +00:00 |
|
Esben Sparre Andreasen
|
8deefd60a7
|
java: fixup whitespace/tabs in test
|
2020-01-24 11:01:38 +01:00 |
|
Esben Sparre Andreasen
|
57b3a55b48
|
java: sharpen java/maven/non-https-url to allow localhost URLs
|
2020-01-24 08:51:54 +01:00 |
|
Esben Sparre Andreasen
|
a5558809f4
|
java: add more tests for java/maven/non-https-url
|
2020-01-24 08:49:59 +01:00 |
|
Anders Schack-Mulligen
|
b92203a87f
|
Java: Allow null literals as sources in data flow.
|
2020-01-22 12:04:42 +01:00 |
|
Anders Schack-Mulligen
|
2dca188288
|
Java: Document two FPs with unit tests.
|
2020-01-17 09:57:11 +01:00 |
|
Tom Hvitved
|
f7278d36e1
|
Merge pull request #2498 from aschackmull/java/taint-getter
Java/C++/C#: Add support for taint-getter/setter summaries in data flow.
|
2020-01-15 09:55:19 +01:00 |
|
Anders Schack-Mulligen
|
ad92d6fe0f
|
Merge pull request #2607 from yo-h/java-alert-suppression-block-comment
Java: allow single-line `/* ... */` comments for alert suppression
|
2020-01-10 11:05:23 +01:00 |
|
yo-h
|
1078424f79
|
Java: allow single-line /* ... */ comments for alert suppression
|
2020-01-08 09:19:25 -05:00 |
|
Anders Schack-Mulligen
|
e74aa33f9d
|
Java: Include non-null final fields in clearlyNotNull.
|
2020-01-03 16:24:54 +01:00 |
|
Anders Schack-Mulligen
|
7e987c570f
|
Merge pull request #2413 from JLLeitschuh/feature/JLL/maven_insecure_artifact_resolution
Java: Use of HTTP/FTP to download/upload Maven artifacts
|
2020-01-02 14:47:30 +01:00 |
|
Anders Schack-Mulligen
|
bca79cd4d6
|
Java/C++/C#: Add support for taint-getter/setter summaries.
|
2019-12-16 16:15:48 +01:00 |
|