yo-h
|
d315864383
|
Merge pull request #3108 from aschackmull/java/finalizemethod
Java: Fixup FinalizeMethod definition.
|
2020-03-23 18:27:57 -04:00 |
|
Anders Schack-Mulligen
|
f29f0f418f
|
Dataflow: Exclude flow param-param flow through with identical params.
|
2020-03-23 17:27:53 +01:00 |
|
Anders Schack-Mulligen
|
4bc0cb0d28
|
Java: Fixup FinalizeMethod definition.
|
2020-03-23 11:11:00 +01:00 |
|
Anders Schack-Mulligen
|
6d3717cff8
|
Java: Sharpen return type of LambdaExpr.getStmtBody().
|
2020-03-23 10:27:36 +01:00 |
|
Anders Schack-Mulligen
|
c78906500d
|
Java: Fix missing jump step from PostUpdate to capture.
|
2020-03-23 10:24:25 +01:00 |
|
Anders Schack-Mulligen
|
888c504f55
|
Merge pull request #2903 from hvitved/dataflow/performance
Data flow: Refactoring + performance improvements
|
2020-03-23 10:01:20 +01:00 |
|
yo-h
|
16f2957029
|
Merge pull request #3081 from aschackmull/java/urldecoder-step
Java: Add URLDecoder.decode as taint step.
|
2020-03-20 13:53:20 -04:00 |
|
luchua-bc
|
d9327705d2
|
Fix the issue of mixed tabs and spaces
|
2020-03-20 08:16:45 -04:00 |
|
luchua-bc
|
dfb42ecf42
|
Address sensitive info logging
|
2020-03-20 08:14:48 -04:00 |
|
Tom Hvitved
|
937924571c
|
Data flow: Sync files
|
2020-03-18 18:16:27 +01:00 |
|
Tom Hvitved
|
3bd6429072
|
Data flow: Sync files
|
2020-03-18 13:28:26 +01:00 |
|
Anders Schack-Mulligen
|
396678fd55
|
Java: Add apache Base64 taint steps.
|
2020-03-18 10:54:40 +01:00 |
|
Tom Hvitved
|
2e8bd5ccba
|
Data flow: Sync files
|
2020-03-17 15:16:12 +01:00 |
|
Anders Schack-Mulligen
|
9c9e302a73
|
Java: Add URLDecoder.decode as taint step.
|
2020-03-17 10:19:02 +01:00 |
|
Tom Hvitved
|
f935f5eaca
|
Data flow: Sync files
|
2020-03-13 13:58:05 +01:00 |
|
Anders Schack-Mulligen
|
9fc75f1f92
|
Merge pull request #2850 from SpaceWhite/CWE-094
ScriptEngine java code injection
|
2020-03-13 13:43:09 +01:00 |
|
Anders Schack-Mulligen
|
2a2484ee0f
|
Merge pull request #2800 from SpaceWhite/CWE-643
CWE-643 XPathInjection on java
|
2020-03-13 13:40:17 +01:00 |
|
Anders Schack-Mulligen
|
99c55b6edb
|
Java: Add taint steps for java.util.Queue methods.
|
2020-03-12 15:02:06 +01:00 |
|
SpaceWhite
|
300aee39be
|
nit: add dot to qhelp
|
2020-03-12 20:38:03 +09:00 |
|
SpaceWhite
|
bb1ea94c54
|
Nit: Fix qhelp and ql autoformat
|
2020-03-12 20:35:01 +09:00 |
|
SpaceWhite
|
822bfcd36c
|
Nit: fix qhelp
|
2020-03-12 20:25:23 +09:00 |
|
Anders Schack-Mulligen
|
e1a0c2d846
|
Java: Add minor test case to typeflow qltest.
|
2020-03-11 13:13:19 +01:00 |
|
Anders Schack-Mulligen
|
a9d76cbe64
|
Dataflow: Add consistency checks for toString and location.
|
2020-03-11 10:29:48 +01:00 |
|
Tom Hvitved
|
bd6c23d165
|
Merge pull request #3020 from aschackmull/dataflow/type-pruning-bigstep
Dataflow: Fix bug in type pruning.
|
2020-03-10 14:21:21 +01:00 |
|
Anders Schack-Mulligen
|
e97c72cd5d
|
Dataflow: Adjust imports.
|
2020-03-10 11:34:09 +01:00 |
|
Anders Schack-Mulligen
|
a2bbacf58d
|
Java/C++/C#: Fix performance issue in partial paths exploration.
|
2020-03-09 11:30:59 +01:00 |
|
Anders Schack-Mulligen
|
4298a3a931
|
Java: Add test.
|
2020-03-09 11:16:59 +01:00 |
|
Anders Schack-Mulligen
|
f491fcd5ae
|
Java/C++/C#: Sync.
|
2020-03-09 11:05:13 +01:00 |
|
Anders Schack-Mulligen
|
7a74634cfd
|
Java/C++/C#: Simplify.
|
2020-03-09 11:04:28 +01:00 |
|
Anders Schack-Mulligen
|
cf84a53573
|
Java/C++/C#: Fix bug in type pruning.
|
2020-03-09 11:04:24 +01:00 |
|
SpaceWhite
|
5e912cbf8e
|
Move directory to experimental
|
2020-03-07 11:55:32 +09:00 |
|
SpaceWhite
|
8cdc2bb268
|
Merge branch 'master' into CWE-094
|
2020-03-07 11:54:31 +09:00 |
|
SpaceWhite
|
b7af1645aa
|
Move directory to experimental
|
2020-03-07 11:49:33 +09:00 |
|
SpaceWhite
|
2ec107bc2d
|
Merge branch 'master' into CWE-643
|
2020-03-07 11:47:53 +09:00 |
|
Anders Schack-Mulligen
|
4601639bad
|
Java: Document a FP in a test.
|
2020-03-03 13:39:26 +01:00 |
|
Anders Schack-Mulligen
|
b210009eec
|
Merge pull request #2923 from yo-h/java-customizations
Java: add `Customizations.qll`
|
2020-03-02 09:58:34 +01:00 |
|
semmle-qlci
|
ec90627a64
|
Merge pull request #2909 from yo-h/experimental
Approved by aschackmull, jbj, max-schaefer, tausbn
|
2020-02-28 03:15:58 +00:00 |
|
yo-h
|
f8bf055fe1
|
Merge pull request #2927 from aschackmull/java/taintgettersetter-tests
Java: Add some more taint-getter-setter tests.
|
2020-02-27 22:12:25 -05:00 |
|
Anders Schack-Mulligen
|
8e2b56cfd0
|
Java: Include count in messages.
|
2020-02-27 13:10:42 +01:00 |
|
Anders Schack-Mulligen
|
33f6392be5
|
Java: Add some more taint-getter-setter tests.
|
2020-02-27 10:47:25 +01:00 |
|
Anders Schack-Mulligen
|
0c30d7cced
|
Java: Update test output.
|
2020-02-27 10:28:12 +01:00 |
|
Anders Schack-Mulligen
|
a09e479033
|
Java: Change relevantNode to a class, and add two more checks.
|
2020-02-27 10:14:14 +01:00 |
|
yo-h
|
bd91bc0b29
|
Java: add Customizations.qll
|
2020-02-26 13:18:13 -05:00 |
|
Anders Schack-Mulligen
|
ce70b86604
|
Java: Add data-flow consistency checks.
|
2020-02-26 14:17:07 +01:00 |
|
Anders Schack-Mulligen
|
508b6050a8
|
Java: Remove some irrelevant bounds from TypeFlow.
|
2020-02-26 13:51:25 +01:00 |
|
Jonas Jensen
|
db33c360bc
|
Merge pull request #2910 from aschackmull/dataflow/cleanup
Java/C++: Minor dataflow cleanup.
|
2020-02-25 12:47:10 +01:00 |
|
Anders Schack-Mulligen
|
fba8772411
|
Java/C++: Minor dataflow cleanup.
|
2020-02-25 09:40:25 +01:00 |
|
yo-h
|
43bcd5b26c
|
Add guidelines for experimental CodeQL queries and libraries
|
2020-02-24 15:08:31 -05:00 |
|
Anders Schack-Mulligen
|
67b32796dd
|
Merge pull request #853 from joshhale/tweak-cwe-078-example
doc: remove - from command arguments
|
2020-02-24 16:15:58 +01:00 |
|
Grzegorz Golawski
|
fda4ab155a
|
CodeQL query to detect open Spring Boot actuator endpoints
|
2020-02-23 20:03:41 +01:00 |
|