erik-krogh
|
6e001ec062
|
deprecate SqlInjectionSink - it's not used anywhere
|
2023-06-14 08:31:57 +02:00 |
|
erik-krogh
|
ae8bf5ed3c
|
delete old deprecations
|
2023-06-14 08:31:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
f1de753400
|
python: add changenote
|
2023-06-13 21:59:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
4b4b9bf9da
|
python: add missing summaries
For append/add:
The new results in the experimental tar slip query
show that we do not recognize the sanitisers.
|
2023-06-13 20:22:21 +02:00 |
|
Rasmus Lerchedahl Petersen
|
b72c93ff4f
|
python: remove remaining explicit taint steps
|
2023-06-13 20:22:20 +02:00 |
|
yoff
|
1d65284011
|
Merge pull request #13209 from yoff/python/container-summaries-2
python: Container summaries, part 2
|
2023-06-13 18:17:09 +02:00 |
|
Rasmus Lerchedahl Petersen
|
775f3eaf56
|
python: make copy a dataflow step
|
2023-06-13 17:07:41 +02:00 |
|
Rasmus Lerchedahl Petersen
|
e11f6b5107
|
ruby/python: adjust shared file
- move `isNonLocal` to the top
- missing backtics
|
2023-06-13 11:49:30 +02:00 |
|
Rasmus Lerchedahl Petersen
|
203f8226cb
|
ruby/python: make SummaryTypeTracker private
|
2023-06-13 11:32:06 +02:00 |
|
Anders Schack-Mulligen
|
2d616d494e
|
C#/Ruby: Add fields as per review comments.
|
2023-06-13 11:26:30 +02:00 |
|
yoff
|
2a5173c331
|
Update python/ql/lib/semmle/python/frameworks/Stdlib.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-06-13 10:04:46 +02:00 |
|
Rasmus Wriedt Larsen
|
6526364045
|
Python: Add modeling of flask.render_template_string
|
2023-06-12 21:18:31 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Anders Schack-Mulligen
|
5062442982
|
Go/Python/Ruby/Swift: Add stub.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
98f51d7f29
|
Dataflow: Sync.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
6020e4d0e3
|
C#/Go/Python/Ruby/Swift: Fix some more references.
|
2023-06-09 15:30:38 +02:00 |
|
Rasmus Lerchedahl Petersen
|
7e87a7c1f7
|
python: rewrite argumentPositionMatch
to not use the call graph.
|
2023-06-09 15:29:13 +02:00 |
|
Anders Schack-Mulligen
|
1e3b960c1b
|
Python: Adjust to FlowSummaryImpl changes.
|
2023-06-09 15:27:17 +02:00 |
|
Anders Schack-Mulligen
|
2cc5bde925
|
Dataflow: Sync.
|
2023-06-09 15:27:17 +02:00 |
|
erik-krogh
|
42d67d0137
|
add change-note
|
2023-06-09 15:24:12 +02:00 |
|
erik-krogh
|
6dfeb2536b
|
delete old deprecations
|
2023-06-09 15:12:23 +02:00 |
|
Rasmus Lerchedahl Petersen
|
b294f48dbe
|
Merge branch 'main' of https://github.com/github/codeql into python-ruby/track-through-summaries-pm
|
2023-06-09 14:16:34 +02:00 |
|
Anders Schack-Mulligen
|
d230509905
|
Dataflow: Address review comments.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
4399138c82
|
Dataflow: Fix QL4QL alert.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
53f2b8aab0
|
Dataflow: Sync.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
fd832416d8
|
Dataflow: Add empty type strengthening predicate for languages without type pruning.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
e8cea79f1d
|
Dataflow: Sync.
|
2023-06-09 08:37:35 +02:00 |
|
Jami Cogswell
|
da58b2afc8
|
Shared: move shared file to 'shared' folder and add parameterized module for 'getInvalidModelKind'
|
2023-06-08 20:05:27 -04:00 |
|
github-actions[bot]
|
e4be303a23
|
Release preparation for version 2.13.4
|
2023-06-08 19:57:37 +00:00 |
|
Tom Hvitved
|
cee70883f0
|
Merge pull request #12964 from hvitved/ruby/remove-synth-returns
Ruby: Remove canonical return nodes
|
2023-06-08 10:07:48 +02:00 |
|
Rasmus Lerchedahl Petersen
|
6ddf1f7eaf
|
ruby/python: remove predicates from interface
|
2023-06-07 14:07:08 +02:00 |
|
Tom Hvitved
|
48ac3e58ee
|
Python: Use CallGraphConstruction in call graph construction
|
2023-06-07 09:02:03 +02:00 |
|
Tom Hvitved
|
4bf124bffe
|
Ruby/Python: Add CallGraphConstruction module for recursive type-tracking based call graph construction
|
2023-06-07 09:02:03 +02:00 |
|
Jami Cogswell
|
5a23421d9a
|
Shared: minor updates to comments
|
2023-06-05 13:46:56 -04:00 |
|
Jami Cogswell
|
9d5972acc2
|
Shared: update qldocs
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
3f1dc8e5c7
|
Shared: add outdated Swift sink kinds
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
62ac0dc471
|
Shared: add outdated sink kind msg to 'getInvalidModelKind' for all languages
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
76f5dca861
|
Shared: move 'OutdatedSinkKind' to shared file and add outdated JS and C# sink kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7b629f5d63
|
Shared: include 'qltest%' and 'test-%'
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
254e447923
|
JS/Python/Ruby: update getInvalidModelKind
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7317c29eea
|
Shared: update kind information
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
0ab1848b70
|
JS/Python/Ruby: use 'SharedModelValidation' file
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
ddb5d92ef8
|
Shared: add source, summary, and neutral shared valid kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
869f820fcf
|
Shared: add 'SharedModelValidation' file as experiment
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
e24e3a6115
|
JS/Python/Ruby: add getInvalidModelKind as experiment
|
2023-06-05 12:18:33 -04:00 |
|
Rasmus Lerchedahl Petersen
|
6755bb32fb
|
Python: do not add read steps for collections
|
2023-06-01 15:18:05 +02:00 |
|
Michael Nebel
|
06b02eb3ce
|
Sync files.
|
2023-06-01 09:30:31 +02:00 |
|
Arthur Baars
|
c211b704f3
|
Merge pull request #13272 from github/post-release-prep/codeql-cli-2.13.3
Post-release preparation for codeql-cli-2.13.3
|
2023-05-31 15:33:12 +02:00 |
|
Arthur Baars
|
490d22d123
|
Merge remote-tracking branch 'upstream/main' into post-release-prep/codeql-cli-2.13.3
|
2023-05-30 21:31:28 +02:00 |
|
Rasmus Lerchedahl Petersen
|
820b5f235e
|
python: add change note
|
2023-05-30 13:36:10 +02:00 |
|