Tony Torralba
|
29d4b6fadc
|
Re-add public classes that shouldn't be removed yet
|
2023-06-13 09:24:27 +02:00 |
|
Tony Torralba
|
2fd2c434f2
|
Apply suggestions from code review
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-06-13 09:24:15 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Anders Schack-Mulligen
|
97b2bdaa9f
|
Java: Fix types of summary parameter nodes.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
254d60c826
|
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-09 15:27:17 +02:00 |
|
Anders Schack-Mulligen
|
59636c43ca
|
Dataflow: Rename two private predicates.
|
2023-06-09 15:27:17 +02:00 |
|
Stephan Brandauer
|
1ae2fee309
|
Java: Update java/ql/lib/ext/okhttp3.model.yml
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-06-09 13:48:16 +02:00 |
|
Stephan Brandauer
|
44785b72ce
|
Java: Update java/ql/lib/ext/okhttp3.model.yml
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-06-09 13:46:09 +02:00 |
|
Anders Schack-Mulligen
|
1b7bbf6320
|
Merge pull request #13083 from aschackmull/dataflow/typestrengthen
Dataflow: Strengthen tracked types.
|
2023-06-09 13:23:30 +02:00 |
|
Anders Schack-Mulligen
|
44b09507ab
|
Merge pull request #13408 from aschackmull/java/loginjection-perf
Java: Add more negation context to reduce string ops and improve perf.
|
2023-06-09 08:44:27 +02:00 |
|
Anders Schack-Mulligen
|
68f1e40370
|
Java/C#: Add change notes.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
d230509905
|
Dataflow: Address review comments.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
4399138c82
|
Dataflow: Fix QL4QL alert.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
8a584b78ac
|
Dataflow: Enable type strengthening in partial flow.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
441ccef6c4
|
Dataflow: Bugfix, use arg type rather than strengthened param type.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
a0a9d30286
|
Java: Fix qltests.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
4633abe19e
|
Java: Autoformat
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
ad461a87b4
|
Dataflow: Strengthen tracked types.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
1d87f0793b
|
Dataflow: Minor refactor.
|
2023-06-09 08:37:35 +02:00 |
|
Jami Cogswell
|
da58b2afc8
|
Shared: move shared file to 'shared' folder and add parameterized module for 'getInvalidModelKind'
|
2023-06-08 20:05:27 -04:00 |
|
Jeroen Ketema
|
bff11c3d23
|
Apply suggestions from code review
|
2023-06-08 22:33:50 +02:00 |
|
github-actions[bot]
|
e4be303a23
|
Release preparation for version 2.13.4
|
2023-06-08 19:57:37 +00:00 |
|
Tony Torralba
|
abb775c616
|
Merge pull request #13409 from atorralba/atorralba/java/fix-gson-models
Java: Fix more problems in the Gson models
|
2023-06-08 17:36:40 +02:00 |
|
Tony Torralba
|
0e242cba7e
|
Update java/ql/lib/ext/retrofit2.model.yml
|
2023-06-08 14:59:10 +02:00 |
|
Tony Torralba
|
4608481d7b
|
Java: Fix more problems in the Gson models
Found during type strengthening work by @aschackmull
|
2023-06-08 14:53:09 +02:00 |
|
Anders Schack-Mulligen
|
5a2ac1b5ca
|
Java: Add more negation context to reduce string ops and improve perf.
|
2023-06-08 14:04:57 +02:00 |
|
Anders Schack-Mulligen
|
dabb4dd643
|
Java: Improve join-order for FunctionalInterface.
|
2023-06-08 13:02:54 +02:00 |
|
Stephan Brandauer
|
8f697ac1ee
|
Java: fix broken MaD export format
|
2023-06-08 12:02:50 +02:00 |
|
Stephan Brandauer
|
c6f10519fa
|
Merge branch 'main' into java/update-mad-decls-after-triage-2023-06-08T08-51-47
|
2023-06-08 12:00:07 +02:00 |
|
Anders Schack-Mulligen
|
cc45db7c76
|
Merge pull request #13394 from atorralba/atorralba/java/fix-gson-jsonarray-models
Java: Fix Gson's JsonArray.add models
|
2023-06-08 11:05:40 +02:00 |
|
Stephan Brandauer
|
bda938c544
|
Update MaD Declarations after Triage
|
2023-06-08 10:51:48 +02:00 |
|
Tony Torralba
|
c0135673fa
|
Fix JsonArray.addAll model
Properly test JsonArray.add(String) and JsonArray.addAll(JsonArray) as well
|
2023-06-07 16:18:32 +02:00 |
|
Tony Torralba
|
6d7234f8ed
|
Merge pull request #13225 from atorralba/atorralba/java/path-injection-mad-sinks-2
Java: Migrate path injection sinks to models-as-data (simplified)
|
2023-06-07 14:27:36 +02:00 |
|
Tony Torralba
|
35b4c438ff
|
Fix Gson's JsonArray.add models
When the type of the argument isn't JsonElement, the summary must be taint flow instead of value flow
|
2023-06-07 14:12:20 +02:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|
Tony Torralba
|
46b30453e3
|
Merge pull request #13386 from github/java/update-mad-decls-after-triage-2023-06-06T14-38-29
Java: Update MaD Declarations after Triage
|
2023-06-07 12:33:26 +02:00 |
|
Tony Torralba
|
27763d6bbe
|
Improve ZipSlip exclusion to take varargs into account
|
2023-06-07 09:25:56 +02:00 |
|
Tony Torralba
|
8001ae9669
|
Update java/ql/lib/semmle/code/java/security/ZipSlipQuery.qll
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-06-07 09:08:24 +02:00 |
|
Tony Torralba
|
60725e9580
|
Update java/ql/lib/ext/org.springframework.core.io.model.yml
|
2023-06-07 09:07:22 +02:00 |
|
Tony Torralba
|
2f12ae2e0d
|
Update java/ql/lib/ext/okhttp3.model.yml
|
2023-06-07 08:57:12 +02:00 |
|
Stephan Brandauer
|
b31131d33a
|
Merge pull request #13344 from github/java/update-mad-decls-after-triage-2023-06-01T12-58-13
Java: Update MaD Declarations after Triage
|
2023-06-06 17:08:50 +02:00 |
|
Stephan Brandauer
|
75cbcdd72e
|
Update MaD Declarations after Triage
|
2023-06-06 16:38:31 +02:00 |
|
Taus
|
f4fd908f7f
|
Java: Comment out sinks for which no query exists
|
2023-06-06 13:01:59 +02:00 |
|
Tony Torralba
|
1d8ca88aca
|
Add change note
|
2023-06-06 11:25:07 +02:00 |
|
Tony Torralba
|
72af634575
|
Kotlin: Add flow through use and with
|
2023-06-06 11:22:16 +02:00 |
|
Tony Torralba
|
1601846478
|
Add exclusion to the ZipSlip query to avoid FPs
|
2023-06-06 10:28:49 +02:00 |
|
Tony Torralba
|
0065e6e1d6
|
Apply suggestions from code review
Fix incorrect models-as-data rows
|
2023-06-06 10:04:22 +02:00 |
|
Tony Torralba
|
1ccec90c6f
|
Apply suggestions from code review
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-06-06 09:10:18 +02:00 |
|
Jami Cogswell
|
5a23421d9a
|
Shared: minor updates to comments
|
2023-06-05 13:46:56 -04:00 |
|
Jami Cogswell
|
6c46cd9c21
|
Java/C#/Go/Swift: move 'SharedModelValidation.qll' to internal folder
|
2023-06-05 13:11:08 -04:00 |
|