Joe Farebrother
|
b4ed77343b
|
Add change note + fix qldoc
|
2024-03-14 22:25:36 +00:00 |
|
Joe Farebrother
|
3e61be1b6a
|
Add test cases
|
2024-03-14 22:25:36 +00:00 |
|
Harry Maclean
|
dd5eb982ec
|
Merge pull request #15524 from hmac/hmac-process-spawn
Ruby: Add some more command injection sinks
|
2024-03-13 09:53:10 +00:00 |
|
Tom Hvitved
|
24e35f6f3d
|
Update expected test output
|
2024-03-08 10:00:43 +01:00 |
|
Tom Hvitved
|
e793a1e9fe
|
Ruby: Add variable capture spurious flow test
|
2024-03-08 10:00:42 +01:00 |
|
Anders Schack-Mulligen
|
0dbe8c3d8a
|
Merge pull request #15140 from hvitved/dataflow/pruned-ctx-sensitivity
Data flow: prune context-sensitivity relations
|
2024-03-06 10:04:48 +01:00 |
|
Joe Farebrother
|
dcc6f83d3b
|
Merge pull request #15782 from joefarebrother/ruby-typhoeus
Ruby: Model `Typhoeus::Request.new`
|
2024-03-05 16:55:38 +00:00 |
|
Harry Maclean
|
91cb2a37fd
|
Ruby: Model Process.exec
|
2024-03-05 10:19:22 +00:00 |
|
Tom Hvitved
|
bd7b2c4cc6
|
Update expected output
|
2024-03-05 10:44:13 +01:00 |
|
Harry Maclean
|
179aaa1342
|
Ruby: model Open4.popen4ext
|
2024-03-05 09:35:18 +00:00 |
|
Peter Stöckli
|
4adc373dfe
|
Ruby: more test cases for code injection via method
|
2024-03-01 16:01:07 +01:00 |
|
Joe Farebrother
|
65b30c1dff
|
Add tests and qldoc
|
2024-03-01 14:46:55 +00:00 |
|
Peter Stöckli
|
a693c6d9b4
|
Ruby: sinks for code injection via calls to method
|
2024-03-01 14:42:22 +01:00 |
|
Joe Farebrother
|
0b7b7ea1b8
|
Add test cases and improve controller model
|
2024-03-01 09:57:24 +00:00 |
|
Tom Hvitved
|
914a605a87
|
Ruby: Rework hidden synthetic data-flow nodes
|
2024-02-27 15:33:58 +01:00 |
|
Tom Hvitved
|
994d990f37
|
Ruby: Add another data flow test
|
2024-02-27 15:33:58 +01:00 |
|
Joe Farebrother
|
3ab6f222d0
|
Merge pull request #15718 from joefarebrother/ruby-arel-sqlliteral
Ruby: Model Arel::Nodes::SqlLiteral.new
|
2024-02-27 12:43:47 +00:00 |
|
Harry Maclean
|
beef9965cc
|
Ruby: Model Open4 library
Also remove duplicate modeling of Process.spawn.
|
2024-02-26 11:26:38 +00:00 |
|
Joe Farebrother
|
386defc3c7
|
Update test output
|
2024-02-26 11:21:03 +00:00 |
|
Tom Hvitved
|
5b6e76c030
|
Move View CFG implementation from Ruby/Swift into shared library
|
2024-02-26 11:23:49 +01:00 |
|
Harry Maclean
|
f19a5a9837
|
Ruby: Add tests for Gemfile modeling
|
2024-02-23 11:13:16 +00:00 |
|
Harry Maclean
|
fbc689227d
|
Merge pull request #15604 from p-/p--rails-more-request-sources
Ruby: add additional sources on the request object of Rails
|
2024-02-22 16:35:59 +00:00 |
|
Joe Farebrother
|
67e8f17c4c
|
Merge pull request #15619 from joefarebrother/ruby-activerecord-connection
Ruby: Add additional sql sinks for ActiveRecord connection methods
|
2024-02-22 14:02:31 +00:00 |
|
Joe Farebrother
|
92bdd637a3
|
Address reveiw comment - add create nd remove select_insert
|
2024-02-22 09:55:46 +00:00 |
|
Tom Hvitved
|
23869fc8e6
|
Ruby: Fix bug in allowParameterReturnInSelf
|
2024-02-22 09:43:52 +01:00 |
|
Tom Hvitved
|
007d08ea63
|
Ruby: Add another variable capture test
|
2024-02-22 09:39:01 +01:00 |
|
Joe Farebrother
|
e36b9f4d3c
|
Add tests and change note
|
2024-02-15 15:26:20 +00:00 |
|
Peter Stöckli
|
2f7b946c9f
|
Ruby: add sources on request object of Rails
|
2024-02-13 15:52:18 +01:00 |
|
Harry Maclean
|
3d9f9afa77
|
Merge pull request #15566 from hmac/hmac-actioncontroller-regex
Ruby: Fix ActionController path regex
|
2024-02-12 14:14:57 +00:00 |
|
Harry Maclean
|
99497e5f3c
|
Merge pull request #15521 from hmac/hmac-ar-connection
Ruby: Recognise more ActiveRecord connections
|
2024-02-12 14:06:50 +00:00 |
|
Tom Hvitved
|
37d774176b
|
Ruby: Fix SSA inconsistency
|
2024-02-09 14:49:26 +01:00 |
|
Tom Hvitved
|
1ea7717714
|
Capture flow: Take overwrites in nested scopes into account
|
2024-02-09 14:49:23 +01:00 |
|
Tom Hvitved
|
0c43ad45b4
|
Ruby: Add another captured variable data flow test
|
2024-02-09 14:48:36 +01:00 |
|
Anders Schack-Mulligen
|
35a3aa0a09
|
Ruby: Add empty provenance column to expected files.
|
2024-02-09 11:32:08 +01:00 |
|
Harry Maclean
|
3a90d78c36
|
Ruby: Fix Rails view file regex
This picks up non-nested template files correctly.
|
2024-02-09 09:41:43 +00:00 |
|
Harry Maclean
|
48890b446d
|
Ruby: Add more actioncontroller tests
|
2024-02-09 09:31:35 +00:00 |
|
Harry Maclean
|
f792b58421
|
Ruby: Recognise more ActiveRecord connections
|
2024-02-05 16:45:59 +00:00 |
|
Tom Hvitved
|
8972133d4b
|
Merge pull request #15498 from hvitved/ruby/ctx-sensitivity-test
Ruby: Add another dataflow test
|
2024-02-01 12:46:53 +01:00 |
|
Tom Hvitved
|
792f302bd4
|
Ruby: Add another dataflow test
|
2024-02-01 10:52:06 +01:00 |
|
Harry Maclean
|
4cfdf8b7a3
|
Ruby: Add test case for view without ERB template
|
2024-01-30 20:30:59 +01:00 |
|
Tom Hvitved
|
d2d017dd64
|
Ruby: Model flow through ViewComponent render methods
|
2024-01-30 20:30:58 +01:00 |
|
Tom Hvitved
|
817a2b71a8
|
Add more tests
|
2024-01-30 20:30:58 +01:00 |
|
Harry Maclean
|
5b3a2b35b7
|
Update expected file
|
2024-01-30 20:30:58 +01:00 |
|
Harry Maclean
|
75a37486c9
|
Add WIP query for erb flow
|
2024-01-30 20:30:58 +01:00 |
|
Harry Maclean
|
bf3b86b402
|
Add test for erb flow
|
2024-01-30 20:30:58 +01:00 |
|
Tom Hvitved
|
2d95ac9d5f
|
Merge pull request #15468 from hvitved/ruby/ctx-sensitivity-rework
|
2024-01-30 20:27:43 +01:00 |
|
Harry Maclean
|
f230e618a3
|
Ruby: Update tests
|
2024-01-30 09:43:56 +00:00 |
|
Tom Hvitved
|
503d2f7b95
|
Ruby: Rework mayBenefitFromCallContext
|
2024-01-30 09:57:29 +01:00 |
|
Tom Hvitved
|
295198744b
|
Ruby: Handle captured yield calls
|
2024-01-10 14:25:15 +01:00 |
|
Tom Hvitved
|
55be4c39ef
|
Ruby: Add data flow call sensitivity test
|
2024-01-10 14:25:12 +01:00 |
|