erik-krogh
|
d989359656
|
add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-15 16:47:02 +02:00 |
|
Tom Hvitved
|
826b6219a0
|
Ruby: Include self parameters in type tracking flow-through logic
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
3cdb27725a
|
Ruby: Add more call graph tests
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
9dede31c0d
|
Merge pull request #13077 from hvitved/ruby/track-regexp-improvements
Ruby: Improvements to `RegExpTracking`
|
2023-05-15 16:02:00 +02:00 |
|
Maiky
|
3c00235375
|
Add SqlSanitization to Concepts and turn private
|
2023-05-15 15:56:52 +02:00 |
|
Maiky
|
f46620c455
|
Var only used in one side of disjunct
|
2023-05-15 15:09:44 +02:00 |
|
Harry Maclean
|
48f22681a5
|
Merge pull request #13029 from hmac/ruby-autobuilder-refactor
Shared: Share autobuilder code between Ruby and QL
|
2023-05-12 18:24:06 +07:00 |
|
Maiky
|
0227b94ab5
|
Edit change note
|
2023-05-11 15:40:36 +02:00 |
|
Maiky
|
071a77cedc
|
Ruby : XPath Injection Query (CWE-643)
|
2023-05-11 15:29:54 +02:00 |
|
Tom Hvitved
|
425ebba278
|
Address review comments
|
2023-05-10 14:04:41 +02:00 |
|
Kasper Svendsen
|
e6ca3fe272
|
Ruby: Enable implicit this warnings
|
2023-05-10 13:03:39 +02:00 |
|
Kasper Svendsen
|
6b8a7c2f6f
|
Ruby: Make implicit this receivers explicit
|
2023-05-10 13:03:39 +02:00 |
|
Tom Hvitved
|
51087d090b
|
Address review comments
|
2023-05-10 09:42:41 +02:00 |
|
Tom Hvitved
|
60b0f25a9a
|
Ruby: Improvements to RegExpTracking
|
2023-05-10 09:35:59 +02:00 |
|
Calum Grant
|
3d713ed4a9
|
Merge pull request #13067 from hvitved/ruby/no-self-flow
Ruby: Remove local identity flow steps
|
2023-05-09 09:33:35 +01:00 |
|
Michael Nebel
|
4ac0396b67
|
Go/Python/Ruby/Swift: Sync files and make dummy implementation.
|
2023-05-08 16:18:59 +02:00 |
|
Tom Hvitved
|
2f95af8ef2
|
Ruby: Remove self edges
|
2023-05-08 10:26:01 +02:00 |
|
Maiky
|
3960853af0
|
CWE-089 Add Sequel SQL Injection Sink
|
2023-05-07 23:56:56 +02:00 |
|
Maiky
|
6a3d995b35
|
Add Mysql2 as SQL Injection Sink
|
2023-05-06 12:25:25 +02:00 |
|
Mathias Vorreiter Pedersen
|
09ba9a74ce
|
Merge pull request #12959 from MathiasVP/identity-consistency-check
DataFlow: Add an "identity-step" consistency check
|
2023-05-05 10:03:20 +01:00 |
|
Harry Maclean
|
9203efbdc4
|
Shared: Share autobuilder code between Ruby and QL
|
2023-05-05 07:20:14 +00:00 |
|
Sim4n6
|
1247403d43
|
Updated expected results file
|
2023-05-04 08:56:45 +01:00 |
|
Mathias Vorreiter Pedersen
|
77001a070b
|
Merge branch 'main' into identity-consistency-check
|
2023-05-03 22:01:06 +01:00 |
|
Mathias Vorreiter Pedersen
|
924854c6dc
|
Ruby: Accept consistency changes.
|
2023-05-03 20:32:33 +01:00 |
|
Sim4n6
|
14ca20e782
|
removed redundant imports
|
2023-05-03 17:43:54 +01:00 |
|
Alex Ford
|
e7213e92cf
|
Merge remote-tracking branch 'origin/main' into rb/sqlite3
|
2023-05-03 15:18:07 +01:00 |
|
Alex Ford
|
6e6eee2dab
|
Ruby: add test case for instance variable flow with sqlite3
|
2023-05-03 15:16:16 +01:00 |
|
Alex Ford
|
a26f9736f1
|
Ruby: add change note for sqlite3 support
|
2023-05-03 15:12:06 +01:00 |
|
Erik Krogh Kristensen
|
f29db40371
|
Merge pull request #13011 from kaspersv/kaspersv/explicit-this-receivers-shared2
JS, Python, Ruby: Make implicit this receivers explicit
|
2023-05-03 15:34:59 +02:00 |
|
Kasper Svendsen
|
ea75996932
|
Merge pull request #13005 from kaspersv/kaspersv/ruby-explicit-this-receivers
Ruby: Make implicit this receivers explicit
|
2023-05-03 14:57:43 +02:00 |
|
Ian Lynagh
|
b56b843d13
|
Merge pull request #12987 from github/post-release-prep/codeql-cli-2.13.1
Post-release preparation for codeql-cli-2.13.1
|
2023-05-03 13:12:10 +01:00 |
|
Kasper Svendsen
|
aca2ace843
|
JS, Python, Ruby: Make implicit this receivers explicit
|
2023-05-03 13:51:51 +02:00 |
|
Kasper Svendsen
|
68cf33e791
|
Ruby: Make implicit this receivers explicit
|
2023-05-03 12:25:01 +02:00 |
|
Alex Ford
|
82c025020d
|
Merge remote-tracking branch 'origin/main' into maikypedia/ruby-ssti
|
2023-05-02 16:18:41 +01:00 |
|
Alex Ford
|
a571bc64ac
|
ruby: regenerate TemplateInjection.expected
|
2023-05-02 16:14:20 +01:00 |
|
Sim4n6
|
019b85beb6
|
Add Unicode Bypass Validation query, test and help file
|
2023-05-02 15:36:39 +01:00 |
|
Anders Schack-Mulligen
|
353d5f82a6
|
Merge pull request #12984 from aschackmull/dataflow/instanceof-node
Dataflow: Replace "extends Node" with "instanceof Node".
|
2023-05-02 13:52:33 +02:00 |
|
github-actions[bot]
|
18d4af994d
|
Post-release preparation for codeql-cli-2.13.1
|
2023-05-02 10:50:20 +00:00 |
|
Anders Schack-Mulligen
|
ca09649679
|
Dataflow: Forward hasLocationInfo.
|
2023-05-02 10:48:32 +02:00 |
|
Asger F
|
f59c149bae
|
Ruby: add SQL injection sinks to meta query
|
2023-05-02 10:46:55 +02:00 |
|
Anders Schack-Mulligen
|
5927bb2030
|
Dataflow: Replace "extends Node" with "instanceof Node".
|
2023-05-02 09:48:34 +02:00 |
|
Maiky
|
5d15ec99c8
|
Change expected file to new
|
2023-05-02 09:26:41 +02:00 |
|
github-actions[bot]
|
3bd29171fb
|
Release preparation for version 2.13.1
|
2023-04-28 12:14:35 +00:00 |
|
Mathias Vorreiter Pedersen
|
e506f638fc
|
DataFlow: Sync identical files.
|
2023-04-27 18:40:33 +01:00 |
|
Anders Schack-Mulligen
|
71ae0909d8
|
Dataflow: Enforce type pruning in all forward stages.
|
2023-04-27 14:55:26 +02:00 |
|
Anders Schack-Mulligen
|
9140cbefc0
|
Dataflow: Sync.
|
2023-04-27 14:55:23 +02:00 |
|
Anders Schack-Mulligen
|
246d904712
|
Merge pull request #12948 from aschackmull/dataflow/pathnode-type-tostring
Dataflow: Add type to PathNode.toString.
|
2023-04-27 14:14:10 +02:00 |
|
Tom Hvitved
|
f888382d35
|
Merge pull request #12906 from hvitved/ruby/track-block-no-self
Ruby: Prevent flow into `self` in `trackBlock`
|
2023-04-27 12:48:05 +02:00 |
|
Tom Hvitved
|
fc66aacf92
|
Merge pull request #12922 from hvitved/ruby/controller-template-file-join
Ruby: Fix bad join in `controllerTemplateFile`
|
2023-04-26 21:26:54 +02:00 |
|
Anders Schack-Mulligen
|
d681671356
|
Dataflow: Sync.
|
2023-04-26 14:45:07 +02:00 |
|