masterofnow
|
99b273d308
|
Apply suggestions from code review
Added suggestion from atorralba.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-16 12:00:45 +08:00 |
|
Chris Smowton
|
84c86f256a
|
Add buildless tests
|
2023-12-15 22:37:55 +00:00 |
|
Eric Bickle
|
95ce7c9ba4
|
Merge branch 'main' into fix/update-gson-model
|
2023-12-15 10:15:53 -08:00 |
|
Ed Minnix
|
09a0730491
|
QLdoc fix
|
2023-12-15 11:13:09 -05:00 |
|
Ed Minnix
|
02581a3850
|
Move class for getProperty method call to Properties.qll
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
73cb01fc89
|
Remove integration test (ported to query test)
The `.properties` file extractor has been enabled by default, so the
test about sources from `getProperty` calls can be ported to a query test.
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
fc53727b9d
|
Bump change note date
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
8826eaf1a3
|
Move test case to query tests
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
afefccf8f7
|
Update change note
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
0d12981d6a
|
Bump change note
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
078a33eecc
|
Updated change note
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
1c3993e632
|
QLDocs
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
8e55ced288
|
Update test to use MaybeBrokenCryptoAlgorithm
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
83c6ece405
|
Move weak hashing into MaybeBrokenCryptoAlgorithm
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
fbc2a33597
|
Replace MethodAccess with MethodCall
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
c20ea1f629
|
Bump change note date
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
cb0ea350b5
|
Improve docs
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
0efca8200d
|
Weak Hashing query wording
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
86b57a11ac
|
Bump change note date
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
25fa8d5ae7
|
Move some logic to class
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
4ff6c1e2ea
|
Test case
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
93cf5b8eb9
|
Weak Hashing Property initial query
|
2023-12-15 11:09:07 -05:00 |
|
Anders Schack-Mulligen
|
337e5e458c
|
Update java/ql/lib/semmle/code/java/security/InsufficientKeySize.qll
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-15 08:48:50 +01:00 |
|
Anders Schack-Mulligen
|
7623432c76
|
Java: Remove/deprecate FlowStateString-based extension points.
|
2023-12-14 15:15:58 +01:00 |
|
Anders Schack-Mulligen
|
a1068ce2f9
|
Dataflow: deprecate references
|
2023-12-14 15:05:33 +01:00 |
|
Tom Hvitved
|
c8b4a215bc
|
Merge pull request #14573 from hvitved/flow-summary-impl-param
Move `FlowSummaryImpl.qll` to `dataflow` pack
|
2023-12-14 12:24:15 +01:00 |
|
Tom Hvitved
|
098afb935b
|
Address more review comments
|
2023-12-14 09:48:45 +01:00 |
|
Ed Minnix
|
717e69ac0e
|
Add properties file references
|
2023-12-13 16:54:55 -05:00 |
|
Jeroen Ketema
|
99e65df6ce
|
Merge remote-tracking branch 'upstream/rc/3.12' into mb12
|
2023-12-13 15:43:39 +01:00 |
|
Tony Torralba
|
66b54f03b7
|
Rename test
|
2023-12-13 11:15:27 +01:00 |
|
Tony Torralba
|
d955dce72a
|
Improve source of randomness detection
Also sanitize flow out of sinks to avoid overlapping paths
|
2023-12-13 11:15:27 +01:00 |
|
Tony Torralba
|
fc45621ab1
|
Add pac4j JWT cryptographic key sinks
|
2023-12-13 11:15:27 +01:00 |
|
Tony Torralba
|
7bc907840c
|
Fix tests
|
2023-12-13 11:15:27 +01:00 |
|
Tony Torralba
|
3a5d711711
|
Add cookie sinks
|
2023-12-13 11:15:27 +01:00 |
|
Tony Torralba
|
435d1f97a3
|
Add sink for OpenSAML's RequestType.setID
|
2023-12-13 11:15:27 +01:00 |
|
masterofnow
|
e1b8fabf7f
|
Use global instead of local taint tracking.
|
2023-12-13 13:50:34 +08:00 |
|
masterofnow
|
8538c12267
|
Merge branch 'github:main' into LoadClassNoSignatureCheck
|
2023-12-13 13:47:40 +08:00 |
|
github-actions[bot]
|
9b20665d75
|
Add changed framework coverage reports
|
2023-12-13 00:16:25 +00:00 |
|
Tony Torralba
|
bd8f35bef7
|
Java: Fix FPs in Missing certificate pinning
Local URIs should never require pinning
|
2023-12-12 18:02:12 +01:00 |
|
Tony Torralba
|
27be5ba14b
|
Merge pull request #15073 from atorralba/atorralba/java/remove-invalid-ognl-sinks
Java: Remove invalid OGNL sinks
|
2023-12-12 16:52:31 +01:00 |
|
Tony Torralba
|
fad53a25c0
|
Update java/ql/lib/ext/struts2.model.yml
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2023-12-12 14:58:47 +01:00 |
|
Tony Torralba
|
103110f9c2
|
Java: Remove invalid OGNL sinks
Fixes #15053
|
2023-12-12 13:39:51 +01:00 |
|
Edward Minnix III
|
06eef93f89
|
Docs review suggestions
|
2023-12-11 11:18:40 -05:00 |
|
Edward Minnix III
|
ce20c4ae03
|
Docs review suggestions
Co-authored-by: Ben Ahmady <32935794+subatoi@users.noreply.github.com>
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
7362158229
|
Fix test case
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
1271cd3348
|
Remove unnecessary crypto sinks
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
3ca039bc8f
|
Rename to InsecureRandomness
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
6e70e6c85a
|
Use pre-exisiting type for SecureRandom
|
2023-12-11 11:18:39 -05:00 |
|
Edward Minnix III
|
4678302edb
|
Update query metadata
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
bbf99375c7
|
Alter cookie sinks to instead focus on creation of a cookie
|
2023-12-11 11:18:39 -05:00 |
|