Mathias Vorreiter Pedersen
|
976adc3c7c
|
C++: Fixup queries to keep the old results.
|
2023-11-21 17:50:08 +00:00 |
|
Mathias Vorreiter Pedersen
|
75f860595a
|
Merge pull request #14838 from MathiasVP/no-dtt-in-arithmetic-with-extreme-values
C++: Convert `cpp/arithmetic-with-extreme-values` away from `DefaultTaintTracking`
|
2023-11-20 16:39:58 +00:00 |
|
Chris Campbell
|
27a2781954
|
Merge branch 'github:main' into main
|
2023-11-20 12:15:45 +00:00 |
|
Arthur Baars
|
db180d9872
|
Merge pull request #14823 from github/post-release-prep/codeql-cli-2.15.3
Post-release preparation for codeql-cli-2.15.3
|
2023-11-19 12:13:42 +01:00 |
|
Mathias Vorreiter Pedersen
|
c65c2489cf
|
C++: Rewrite 'cpp/arithmetic-with-extreme-values' away from 'DefaultTaintTracking'.
|
2023-11-17 16:38:35 +00:00 |
|
github-actions[bot]
|
bad499e360
|
Post-release preparation for codeql-cli-2.15.3
|
2023-11-17 14:35:41 +00:00 |
|
Chris Campbell
|
114b694553
|
Remove @precision values, correct missing tags
|
2023-11-16 15:50:41 +00:00 |
|
Mathias Vorreiter Pedersen
|
c5d2866948
|
Merge pull request #14812 from MathiasVP/no-dtt-in-Integer-overflow-tainted
C++: Convert `cpp/integer-overflow-tainted` away from DefaultTaintTracking
|
2023-11-16 15:24:13 +00:00 |
|
Mathias Vorreiter Pedersen
|
30f0b8ab2b
|
Merge pull request #14808 from jketema/jketema/del-fmt-global
C++: Delete `cpp/tainted-format-string-through-global`
|
2023-11-16 13:44:21 +00:00 |
|
github-actions[bot]
|
6ec9b95072
|
Release preparation for version 2.15.3
|
2023-11-16 13:07:16 +00:00 |
|
Mathias Vorreiter Pedersen
|
078f223052
|
C++: Rewrite 'cpp/cpp/integer-overflow-tainted' away from DefaultTaintTracking.
|
2023-11-16 12:01:38 +00:00 |
|
Henry Mercer
|
de83929a60
|
Remove LoC metrics from the analysis summary
|
2023-11-16 11:36:44 +00:00 |
|
Mathias Vorreiter Pedersen
|
5c0fb2030d
|
C++: Move change note.
|
2023-11-16 09:57:08 +00:00 |
|
Jeroen Ketema
|
2eb67549e6
|
C++: Tweak change note slightly
|
2023-11-16 10:56:47 +01:00 |
|
Jeroen Ketema
|
afe318edbe
|
C++: Delete cpp/tainted-format-string-through-global
|
2023-11-16 10:52:05 +01:00 |
|
Mathias Vorreiter Pedersen
|
4d4ca6b948
|
Merge pull request #14794 from MathiasVP/catch-more-return-stack-allocated-memory
C++: Catch more returns of stack-allocated memory
|
2023-11-15 19:23:24 +00:00 |
|
Jeroen Ketema
|
46e6e72593
|
C++: Address review comments
|
2023-11-15 14:57:53 +01:00 |
|
Jeroen Ketema
|
92c18960c5
|
C++: Rewrite cpp/uncontrolled-process-operation to not use DefaultTaintTracking
|
2023-11-15 14:57:53 +01:00 |
|
Mathias Vorreiter Pedersen
|
bae7e10e46
|
C++: Also add MSVC-related 'alloca'-like functions.
|
2023-11-15 12:07:17 +00:00 |
|
Mathias Vorreiter Pedersen
|
6730f57d5c
|
C++: Also flag up 'alloca' and friends.
|
2023-11-15 11:51:57 +00:00 |
|
Mathias Vorreiter Pedersen
|
1623bba18a
|
Merge branch 'main' into no-dtt-in-tainted-arithmetic
|
2023-11-14 13:35:15 +00:00 |
|
Mathias Vorreiter Pedersen
|
c950e26b3e
|
C++: Rewrite 'cpp/cpp/tainted-arithmetic' away from DefaultTaintTracking.
|
2023-11-14 12:19:12 +00:00 |
|
Mathias Vorreiter Pedersen
|
967bbbc1a7
|
C++: Block flow out of sinks that are qualifiers. This removes the new result duplication and keeps the new result.
|
2023-11-14 09:29:47 +00:00 |
|
Mathias Vorreiter Pedersen
|
cc6268339b
|
C++: Fix failing test and accept test cases.
|
2023-11-13 15:57:22 +00:00 |
|
Mathias Vorreiter Pedersen
|
7048190929
|
Update cpp/ql/src/Security/CWE/CWE-120/UnboundedWrite.ql
Co-authored-by: Jeroen Ketema <93738568+jketema@users.noreply.github.com>
|
2023-11-09 12:39:10 +00:00 |
|
Mathias Vorreiter Pedersen
|
38bd893c81
|
Merge branch 'main' into no-dtt-in-unbounded-write
|
2023-11-08 15:06:59 +00:00 |
|
Mathias Vorreiter Pedersen
|
e90803a81c
|
C++: Rewrite 'cpp/unbounded-write' away from DefaultTaintTracking.
|
2023-11-08 14:57:04 +00:00 |
|
Mathias Vorreiter Pedersen
|
6669cf805f
|
C++: Add change note.
|
2023-11-07 09:32:07 +00:00 |
|
Mathias Vorreiter Pedersen
|
022c9eb3cd
|
C++: Add a barrier feature to 'MustFlow'.
|
2023-11-07 09:23:42 +00:00 |
|
Mathias Vorreiter Pedersen
|
1dc08941f8
|
C++: Use 'MustFlow' in 'cpp/uninitialized-local'.
|
2023-11-07 09:23:41 +00:00 |
|
Mathias Vorreiter Pedersen
|
679d64f0e8
|
Merge pull request #14647 from microsoft/24-odbc-model-instantiation-upstream2
C++: Adding a model implementation for ODBC.
|
2023-11-02 19:42:27 +00:00 |
|
Mathias Vorreiter Pedersen
|
37a536baf9
|
Merge pull request #14650 from jketema/invalid-experimental
C++: Drop `experimental` tag from `cpp/invalid-pointer-deref`
|
2023-10-31 20:14:25 +01:00 |
|
Jeroen Ketema
|
3478890090
|
C++: Drop experimental tag from cpp/invalid-pointer-deref
|
2023-10-31 19:46:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
b79a5fee14
|
Merge pull request #14637 from MathiasVP/dataflow-for-realloc
C++: Add a taint model for `realloc`
|
2023-10-31 18:24:04 +01:00 |
|
Benjamin Rodes
|
b9ac038de2
|
Moving change log.
|
2023-10-31 09:21:01 -07:00 |
|
Benjamin Rodes
|
07ded4278f
|
Change log
|
2023-10-31 09:14:47 -07:00 |
|
Mathias Vorreiter Pedersen
|
4a1bf95a87
|
C++: Expose a public memset model and use it in the exposure queries.
|
2023-10-31 11:17:51 +00:00 |
|
github-actions[bot]
|
2b939fdf08
|
Post-release preparation for codeql-cli-2.15.2
|
2023-10-30 16:06:51 +00:00 |
|
github-actions[bot]
|
4641990021
|
Release preparation for version 2.15.2
|
2023-10-30 11:05:53 +00:00 |
|
github-actions[bot]
|
8dcd8b9e5b
|
Post-release preparation for codeql-cli-2.15.1
|
2023-10-17 20:24:00 +00:00 |
|
github-actions[bot]
|
3b3c036626
|
Release preparation for version 2.15.1
|
2023-10-16 17:49:39 +00:00 |
|
Mathias Vorreiter Pedersen
|
ba27a0d515
|
Update cpp/ql/src/change-notes/2023-10-16-redundant-null-check-simple.md
Co-authored-by: Jeroen Ketema <93738568+jketema@users.noreply.github.com>
|
2023-10-16 12:48:53 +02:00 |
|
Mathias Vorreiter Pedersen
|
32d82380f1
|
C++: Add change note.
|
2023-10-16 11:08:27 +01:00 |
|
Mathias Vorreiter Pedersen
|
20c3984872
|
C++: Add the 'security' tag and add a 'security-severity' rating to 'cpp/redundant-null-check-simple'.
|
2023-10-16 09:54:36 +01:00 |
|
Tony Torralba
|
ae8e237f2c
|
Merge pull request #14494 from atorralba/atorralba/remove-library
Java/C/C#: Remove library annotations
|
2023-10-16 09:01:40 +02:00 |
|
Jeroen Ketema
|
d56a9f0781
|
Merge pull request #14424 from jketema/rewrite-cgi-xss
C++: Rewrite `cpp/cgi-xss` to not use default taint tracking
|
2023-10-13 17:57:04 +02:00 |
|
Jeroen Ketema
|
61676277e8
|
C++: Fix barrier in cpp/cgi-xss
|
2023-10-13 14:05:47 +02:00 |
|
Tony Torralba
|
0cea3f8531
|
Remove library annotations
|
2023-10-13 12:46:56 +02:00 |
|
Mathias Vorreiter Pedersen
|
64fa6c8bbd
|
C++: Remove the hacky flow state since this is no longer needed after #13717.
|
2023-10-12 13:58:36 +01:00 |
|
Henry Mercer
|
1a370bfbbe
|
Merge pull request #14443 from github/post-release-prep/codeql-cli-2.15.0
Post-release preparation for codeql-cli-2.15.0
|
2023-10-11 17:39:04 +01:00 |
|