Jami Cogswell
|
76433a31f7
|
Java: generalize sanitizer and add tests
|
2025-03-10 18:56:01 -04:00 |
|
Jami Cogswell
|
ab3690f666
|
Java: initial sanitizer
|
2025-03-10 18:55:56 -04:00 |
|
Jami Cogswell
|
94080a6e47
|
Java: initial tests
|
2025-03-10 18:55:54 -04:00 |
|
Jami
|
ad63dd946c
|
Apply suggestions from docs review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2025-03-10 09:01:04 -04:00 |
|
REDMOND\brodes
|
32d29ffde3
|
Changed casing on TCipherType, Added some initial fixes for hash support, started developing openssl hashing modeling.
|
2025-03-07 10:02:36 -05:00 |
|
Anders Schack-Mulligen
|
d075466958
|
Merge pull request #18941 from aschackmull/ssa/refactor4
Ssa: Extend consistency checks and reduce phi read nodes
|
2025-03-07 15:18:02 +01:00 |
|
Anders Schack-Mulligen
|
3508ca89e6
|
Java: Restrict SSA reads to the reachable CFG.
|
2025-03-07 11:13:53 +01:00 |
|
REDMOND\brodes
|
b9bd199432
|
Regression fixes for JCA
|
2025-03-06 13:39:23 -05:00 |
|
Anders Schack-Mulligen
|
da579c27fc
|
Merge pull request #18934 from aschackmull/ssa/refactor5
SSA: Replace the Guards interface in the SSA data flow integration.
|
2025-03-06 15:11:52 +01:00 |
|
Anders Schack-Mulligen
|
947a85ed28
|
Java: Enable SSA consistency queries.
|
2025-03-06 12:47:38 +01:00 |
|
Lukas Abfalterer
|
32e1589745
|
Update java/ql/src/change-notes/2025-03-03-fix-improper-intent-verification-query.md
Co-authored-by: Edward Minnix III <egregius313@github.com>
|
2025-03-06 09:57:16 +01:00 |
|
Owen Mansel-Chan
|
f2947f7066
|
Fix indentation
|
2025-03-05 14:13:53 +00:00 |
|
Jami Cogswell
|
0eec951218
|
Java: update change note to mention removal from Community Packs
|
2025-03-05 08:55:51 -05:00 |
|
Lukas Abfalterer
|
b4c75d832c
|
Merge branch 'main' into cwe-925
|
2025-03-05 14:15:07 +01:00 |
|
Anders Schack-Mulligen
|
c6761db2fc
|
SSA: Replace the Guards interface in the SSA data flow integration.
|
2025-03-05 13:29:31 +01:00 |
|
Lukas Abfalterer
|
41e9a837e5
|
Fix naming
Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
|
2025-03-05 12:50:54 +01:00 |
|
Anders Schack-Mulligen
|
709d36b502
|
Merge pull request #18869 from aschackmull/ssa/refactor3
Ssa: Update qltests including consistency checks
|
2025-03-05 11:40:27 +01:00 |
|
Lukas Abfalterer
|
c9b75afc2a
|
Fix QLL and add change notes with tests
|
2025-03-05 10:23:35 +01:00 |
|
Jami Cogswell
|
82062e2847
|
Java: update test
|
2025-03-04 11:15:00 -05:00 |
|
Jami Cogswell
|
746f022cfa
|
Java: add 'Spring' prefix to public class names
|
2025-03-04 10:34:16 -05:00 |
|
Anders Schack-Mulligen
|
9e03b12ba0
|
C#/Java/Ruby/Rust/SSA: Replace DefinitionExt with SourceVariable in data flow integration predicates.
|
2025-03-04 12:24:21 +01:00 |
|
REDMOND\brodes
|
8865d89fe9
|
Removing old ReusedNonce query.
|
2025-03-03 16:51:30 -05:00 |
|
REDMOND\brodes
|
2ee1681126
|
Adding a proof-of-concept PossibleReusedNonce query.
|
2025-03-03 15:09:27 -05:00 |
|
REDMOND\brodes
|
14cb2bb12f
|
Updates to insecure or unknown nonce at operation.
|
2025-03-03 14:42:50 -05:00 |
|
REDMOND\brodes
|
076f53147d
|
Proof-of-concept query for InsecureOrUnknownNonceAtOperation
|
2025-03-03 13:53:16 -05:00 |
|
github-actions[bot]
|
58f355ae5a
|
Post-release preparation for codeql-cli-2.20.6
|
2025-03-03 18:18:15 +00:00 |
|
Nicolas Will
|
627790f98b
|
Clean up consumer and instance interfaces
|
2025-03-03 19:06:53 +01:00 |
|
github-actions[bot]
|
fa850cccb1
|
Release preparation for version 2.20.6
|
2025-03-03 17:13:19 +00:00 |
|
Lukas Abfalterer
|
a3749530d6
|
The query should only report cases when the method is not empty.
|
2025-03-03 10:20:46 +01:00 |
|
Jami Cogswell
|
b0b95965f6
|
Java: add change note
|
2025-03-02 17:13:37 -05:00 |
|
Jami Cogswell
|
fbf7513f37
|
Java: handle lock state check stored in variable
|
2025-03-02 17:01:18 -05:00 |
|
Nicolas Will
|
cf33cf7653
|
Add input and output nodes and fix cross product
|
2025-02-28 15:21:46 +01:00 |
|
Chris Smowton
|
79e581f555
|
Change note
|
2025-02-28 11:23:10 +00:00 |
|
Chris Smowton
|
1577b40b45
|
Accept test changes
|
2025-02-28 11:23:07 +00:00 |
|
Chris Smowton
|
178e90c2f1
|
Update test expectations for JDK24 upgrade
|
2025-02-28 11:23:06 +00:00 |
|
Nicolas Will
|
0354afc365
|
Make ArtifactConsumers instances of some Artifacts
TODO: refactor the interfaces
|
2025-02-27 15:54:38 +01:00 |
|
Nicolas Will
|
04f4683399
|
Rewrite handling of known unknowns and data-flow
|
2025-02-27 05:42:02 +01:00 |
|
Alex Eyers-Taylor
|
5e3ccc0cca
|
Java: Simplify interpretOutput
|
2025-02-26 18:20:46 +00:00 |
|
Nicolas Will
|
f55f27b0d9
|
Expand handling of generic artifact sources
|
2025-02-25 18:22:38 +01:00 |
|
Anders Schack-Mulligen
|
994a8eea39
|
Merge pull request #18857 from aschackmull/ssa/refactor-df-integr
Ssa: Refactor the data flow integration module
|
2025-02-25 15:04:11 +01:00 |
|
Anders Schack-Mulligen
|
2c3b48946d
|
Merge pull request #18824 from aschackmull/java/basessa
Java: Switch BaseSSA to use shared SSA lib.
|
2025-02-25 14:23:46 +01:00 |
|
Jonas Jensen
|
2edc9af1e0
|
Merge pull request #18848 from jbj/StaticInitializationVector-postprocess
Java: StaticInitializationVector with postprocess
|
2025-02-25 12:44:16 +01:00 |
|
Nicolas Will
|
eb91ecf1fb
|
Add generic artifact data-flow
The relation between RNG and other artifacts has been added
Nonce has been completed to report its source
|
2025-02-25 02:53:13 +01:00 |
|
Owen Mansel-Chan
|
74a249597a
|
Merge pull request #18607 from owen-mc/java/xss-content-type-sanitizer
Java: Add XSS Sanitizer for `HttpServletResponse.setContentType` with safe values
|
2025-02-24 23:39:18 +00:00 |
|
Jami Cogswell
|
c2e859c756
|
Java: add change note
|
2025-02-24 18:33:45 -05:00 |
|
Jami Cogswell
|
26e396732a
|
Java: edit qhelp
|
2025-02-24 18:33:43 -05:00 |
|
Jami Cogswell
|
53cb30dcd0
|
Java: update metadata, move from CWE-016 to CWE-200
|
2025-02-24 18:33:41 -05:00 |
|
Jami Cogswell
|
6fe7c7a233
|
Java: some refactoring
|
2025-02-24 18:33:29 -05:00 |
|
Jami Cogswell
|
f65a5b9a66
|
Java: add test for qhelp good example
|
2025-02-24 18:27:45 -05:00 |
|
Jami Cogswell
|
9e51b014d2
|
Java: handle example in Spring docs
|
2025-02-24 18:27:43 -05:00 |
|