Owen Mansel-Chan
|
fdd1e3fefe
|
Use MaD models for unsafe deserialization sinks when possible
Many of the unsafe deserialization sinks have to stay defined in QL
because they have custom logic that cannot be expressed in MaD models.
|
2025-07-16 14:42:07 +01:00 |
|
Tony Torralba
|
eecab9122a
|
Recognize the model generator involvement in the models' provenances
|
2024-03-14 08:56:23 +01:00 |
|
Tony Torralba
|
039bea1625
|
Java: Add more neutral JDK models
This is similar to https://github.com/github/codeql/pull/15766, in the sense that it adds neutral models to prevent the model generator from generating summaries for them. These models were spotted while evaluating https://github.com/github/codeql/pull/14919.
|
2024-03-13 16:59:38 +01:00 |
|
Michael Nebel
|
e86f1e4961
|
Java: Replace Argument[-1] with Argument[this].
|
2023-03-20 10:14:20 +01:00 |
|
Michael Nebel
|
bc02adb400
|
Java: Make the corresponding rename in all the data extensions.
|
2022-12-14 13:48:31 +01:00 |
|
Michael Nebel
|
9cb5ff1cdc
|
Java: Add data extensions for all manual models.
|
2022-11-28 12:30:34 +01:00 |
|