Tom Hvitved
|
eaa84cb819
|
Ruby: Include underlying SSA parameter definition in localFlowSsaParamCaptureInput
|
2023-05-23 13:56:29 +02:00 |
|
Tom Hvitved
|
349de77474
|
Ruby: Include both self parameters and SSA definitions in call graph construction
|
2023-05-23 12:28:06 +02:00 |
|
erik-krogh
|
c7e21ee9ae
|
add really long regex as a test-case
|
2023-05-23 09:56:06 +02:00 |
|
Erik Krogh Kristensen
|
50cb5ea184
|
Merge pull request #13164 from erik-krogh/polyQhelp
ReDoS: add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-23 09:25:15 +02:00 |
|
github-actions[bot]
|
7aa23cf11d
|
Release preparation for version 2.13.3
|
2023-05-22 20:47:00 +00:00 |
|
Arthur Baars
|
bec2b7fef9
|
QL/Ruby: update dbscheme stats
|
2023-05-22 19:37:58 +02:00 |
|
Arthur Baars
|
294cc930e6
|
Ruby: add upgrade/downgrade scripts
|
2023-05-22 19:37:51 +02:00 |
|
Arthur Baars
|
d2bc66e393
|
QL: switch to shared YAML extractor
|
2023-05-22 19:28:59 +02:00 |
|
Arthur Baars
|
6d7e95a142
|
QL/Ruby: included shared extractor code in cache key
|
2023-05-22 19:28:59 +02:00 |
|
Arthur Baars
|
9f83dd5c7a
|
Tree-sitter extractor: extract shared dbscheme fragments into 'prefix.dbscheme'
|
2023-05-22 19:28:51 +02:00 |
|
Tom Hvitved
|
20efe81f10
|
Update ruby/ql/lib/codeql/ruby/typetracking/TypeTrackerSpecific.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2023-05-22 12:43:05 +02:00 |
|
Tom Hvitved
|
33be52f0b7
|
Ruby: Allow for flow out of callbacks passed to summarized methods in type tracking
|
2023-05-22 11:01:08 +02:00 |
|
erik-krogh
|
710b309142
|
apply suggestions from doc review
|
2023-05-21 22:18:48 +02:00 |
|
erik-krogh
|
10bf17c33e
|
Merge branch 'main' into polyQhelp
|
2023-05-21 22:17:06 +02:00 |
|
Tom Hvitved
|
128168a7e7
|
Ruby: Allow for flow through callbacks to summarized methods in type tracking
|
2023-05-21 20:51:45 +02:00 |
|
Sim4n6
|
97e8e0bd8e
|
Add String Manipulation Method Calls & CGI.escapeHTML() support
|
2023-05-21 11:52:29 +01:00 |
|
Sim4n6
|
f7f0564e36
|
added one more test
|
2023-05-20 18:00:27 +01:00 |
|
Sim4n6
|
0a0a6dde40
|
Replaced CGI.escapeHTML() with the html_escape()
|
2023-05-20 17:59:39 +01:00 |
|
Sim4n6
|
ad754f1385
|
use of all normalization forms without the ":" prefix
|
2023-05-20 17:59:08 +01:00 |
|
Sim4n6
|
f5ff50880c
|
Updated qhelp for the use of html_escape()
|
2023-05-20 17:58:24 +01:00 |
|
Sim4n6
|
cc3cc1faef
|
Merge branch 'ruby-UBV' of https://github.com/sim4n6/codeql-pun into ruby-UBV
|
2023-05-20 12:59:50 +01:00 |
|
Sim4n6
|
d11cb9195c
|
Use of CGI.escapeHTML() in test samples
|
2023-05-20 12:57:50 +01:00 |
|
Sim4n6
|
e345d7dca4
|
Update ruby/ql/src/experimental/cwe-176/examples/unicode_normalization.rb
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2023-05-20 12:54:03 +01:00 |
|
Sim4n6
|
7cd1fd4bbf
|
CWE-179 and CWE-180 are included in metadata
|
2023-05-20 12:51:45 +01:00 |
|
Sim4n6
|
957023ec44
|
nfd and nfkd are considered
|
2023-05-20 12:51:24 +01:00 |
|
Sim4n6
|
c9c7179a0b
|
Deleted the ugly flowchart.
|
2023-05-20 12:49:46 +01:00 |
|
Sim4n6
|
c3c65ca712
|
Qhelp formatting
|
2023-05-20 12:48:26 +01:00 |
|
Sim4n6
|
8dcf139b45
|
Update ruby/ql/src/experimental/cwe-176/UnicodeBypassValidation.qhelp
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2023-05-20 12:46:54 +01:00 |
|
Sim4n6
|
eb7e1de65b
|
Update ruby/ql/lib/codeql/ruby/experimental/UnicodeBypassValidationQuery.qll
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2023-05-20 12:43:05 +01:00 |
|
Sim4n6
|
69ca49f168
|
Deleted the UBV query change note.
|
2023-05-20 12:39:54 +01:00 |
|
erik-krogh
|
480e71fd69
|
avoid contractions
|
2023-05-17 08:42:45 +02:00 |
|
erik-krogh
|
83ca1495e0
|
trim the whitespace in the poly-redos examples
|
2023-05-15 16:47:24 +02:00 |
|
erik-krogh
|
d989359656
|
add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-15 16:47:02 +02:00 |
|
Tom Hvitved
|
826b6219a0
|
Ruby: Include self parameters in type tracking flow-through logic
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
3cdb27725a
|
Ruby: Add more call graph tests
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
9dede31c0d
|
Merge pull request #13077 from hvitved/ruby/track-regexp-improvements
Ruby: Improvements to `RegExpTracking`
|
2023-05-15 16:02:00 +02:00 |
|
Maiky
|
3c00235375
|
Add SqlSanitization to Concepts and turn private
|
2023-05-15 15:56:52 +02:00 |
|
Maiky
|
f46620c455
|
Var only used in one side of disjunct
|
2023-05-15 15:09:44 +02:00 |
|
Harry Maclean
|
48f22681a5
|
Merge pull request #13029 from hmac/ruby-autobuilder-refactor
Shared: Share autobuilder code between Ruby and QL
|
2023-05-12 18:24:06 +07:00 |
|
Maiky
|
0227b94ab5
|
Edit change note
|
2023-05-11 15:40:36 +02:00 |
|
Maiky
|
071a77cedc
|
Ruby : XPath Injection Query (CWE-643)
|
2023-05-11 15:29:54 +02:00 |
|
Tom Hvitved
|
425ebba278
|
Address review comments
|
2023-05-10 14:04:41 +02:00 |
|
Kasper Svendsen
|
e6ca3fe272
|
Ruby: Enable implicit this warnings
|
2023-05-10 13:03:39 +02:00 |
|
Kasper Svendsen
|
6b8a7c2f6f
|
Ruby: Make implicit this receivers explicit
|
2023-05-10 13:03:39 +02:00 |
|
Tom Hvitved
|
51087d090b
|
Address review comments
|
2023-05-10 09:42:41 +02:00 |
|
Tom Hvitved
|
60b0f25a9a
|
Ruby: Improvements to RegExpTracking
|
2023-05-10 09:35:59 +02:00 |
|
Calum Grant
|
3d713ed4a9
|
Merge pull request #13067 from hvitved/ruby/no-self-flow
Ruby: Remove local identity flow steps
|
2023-05-09 09:33:35 +01:00 |
|
Michael Nebel
|
4ac0396b67
|
Go/Python/Ruby/Swift: Sync files and make dummy implementation.
|
2023-05-08 16:18:59 +02:00 |
|
Tom Hvitved
|
2f95af8ef2
|
Ruby: Remove self edges
|
2023-05-08 10:26:01 +02:00 |
|
Maiky
|
3960853af0
|
CWE-089 Add Sequel SQL Injection Sink
|
2023-05-07 23:56:56 +02:00 |
|