Erik Krogh Kristensen
|
59cc099008
|
add missing qldoc
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
d77c28f6a7
|
add qhelp for unsafe-code-construction
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
d790f3ccbb
|
add test for unsafe-code-construction query
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
198a464346
|
add js/unsafe-code-construction query
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
955ad8c458
|
add JSON.stringify as a code-injection sanitizer
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
68a5c1f5b5
|
add code-injection sink for calls to node
|
2022-02-07 13:34:18 +01:00 |
|
Nick Rolfe
|
b3b2bba618
|
Ruby: make some generated predicates final
|
2022-02-07 12:17:50 +00:00 |
|
Nick Rolfe
|
b43cc23277
|
Ruby: add db downgrade script
|
2022-02-07 12:10:36 +00:00 |
|
Nick Rolfe
|
e8855c3718
|
Ruby: add db upgrade script
|
2022-02-07 12:10:36 +00:00 |
|
Nick Rolfe
|
388d361ec3
|
Ruby: put AST node locations in a single table
|
2022-02-07 12:10:36 +00:00 |
|
Michael Nebel
|
99f89f1fe2
|
C#: Update db stats file.
|
2022-02-07 12:57:10 +01:00 |
|
Mathias Vorreiter Pedersen
|
55e69d421c
|
Merge pull request #7849 from Yonah125/main
C/C++: Useless Test : verification of "Fully converted" Type
|
2022-02-07 11:46:51 +00:00 |
|
Benjamin Muskalla
|
2f94356899
|
Run daily
|
2022-02-07 12:12:29 +01:00 |
|
Benjamin Muskalla
|
bd417769ce
|
Add workflow to upload metrics
|
2022-02-07 12:08:18 +01:00 |
|
Benjamin Muskalla
|
a1432c47dc
|
Exclude framework coverage query from suites
We don't want to run this query on any database but rather
in a specific setup. Exclude from suites by default.
|
2022-02-07 12:08:18 +01:00 |
|
Benjamin Muskalla
|
9af50f5216
|
Turn framework coverage into metric query
|
2022-02-07 12:08:18 +01:00 |
|
Jeroen Ketema
|
1f2865c7cc
|
Merge pull request #7798 from jketema/missing-open-arg
C++: Add query for missing mode argument in `open`/`openat` calls
|
2022-02-07 12:01:44 +01:00 |
|
BACK Yonah
|
61dc9ef12e
|
C/C++: AutoFormat fix
|
2022-02-07 11:41:17 +01:00 |
|
Rasmus Wriedt Larsen
|
32cd7d6fa7
|
Add groups to all consistency-queries/qlpack.yml
as discussed in PR review
|
2022-02-07 11:15:48 +01:00 |
|
Tom Hvitved
|
dc09e87cb2
|
Ruby: Use SimpleSummarizedCallable in a few more places
|
2022-02-07 11:05:32 +01:00 |
|
Erik Krogh Kristensen
|
0584a6acaf
|
recognize a nodejs re-exports in a loop
|
2022-02-07 10:12:38 +01:00 |
|
Michael Nebel
|
b2e18ebae1
|
C#: Lambda improvements change note.
|
2022-02-07 09:22:46 +01:00 |
|
Michael Nebel
|
782d6da754
|
C#: Support for lambda expression explicit return types and lambda attributes.
|
2022-02-07 09:19:47 +01:00 |
|
github-actions[bot]
|
b4ab86c020
|
Post-release preparation for codeql-cli-2.8.0
|
2022-02-06 23:34:07 +00:00 |
|
Arthur Baars
|
ac03fab986
|
Merge pull request #7753 from aibaars/ruby-3.1
Ruby 3.1 features
|
2022-02-06 21:06:16 +01:00 |
|
Erik Krogh Kristensen
|
ab2d3a7ca0
|
Merge pull request #7828 from Naman-ntc/main
JS: Adding model for `.get` function of `Map` in Unvalidated Dynamic Method Call
|
2022-02-04 20:19:02 +01:00 |
|
Erik Krogh Kristensen
|
f00d723c49
|
Merge pull request #7843 from erik-krogh/CVE-2021-23484
JS: add file sources from `jszip` to `js/zip-slip`
|
2022-02-04 20:17:43 +01:00 |
|
BACK Yonah
|
21fdc53d62
|
C/C++: Using UnspecifiedType instead of Type
|
2022-02-04 19:12:15 +01:00 |
|
Nick Rolfe
|
9744cf2457
|
Ruby: apply suggested simplification from review
|
2022-02-04 17:14:47 +00:00 |
|
Nick Rolfe
|
aaff3226c9
|
Ruby: prefer ...isInt(x) over x = ...getInt()
|
2022-02-04 17:10:22 +00:00 |
|
BACK Yonah
|
b2ca25abef
|
Merge branch 'main' of https://github.com/github/codeql
|
2022-02-04 18:09:19 +01:00 |
|
BACK Yonah
|
f4a1d1d5e6
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:05:03 +01:00 |
|
Nick Rolfe
|
45962f1cad
|
Ruby: make this unique for each method
Even when summaries are shared in a single class.
|
2022-02-04 17:03:55 +00:00 |
|
BACK Yonah
|
34320cb57b
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:03:29 +01:00 |
|
Ian Wright
|
6c3daf49f9
|
Merge pull request #7785 from github/z80coder/impose-length-restriction
Restrict AST nodes according to string length
|
2022-02-04 16:35:04 +00:00 |
|
Nick Rolfe
|
7a9ddc28bf
|
Ruby: address some more feedback on array flow summaries
|
2022-02-04 16:33:27 +00:00 |
|
Henry Mercer
|
bb1e89d261
|
Merge pull request #7848 from github/henrymercer/js-ml-powered-codeowners
JS: Add codeowners for ML-powered queries
|
2022-02-04 16:08:56 +00:00 |
|
Michael Nebel
|
6ee30843bb
|
C#: Add lambda attributes test cases.
|
2022-02-04 16:54:49 +01:00 |
|
Henry Mercer
|
22ef35e13a
|
JS: Add codeowners for ML-powered queries
Create a new reviewers team @github/codeql-ml-powered-queries-reviewers
for reviewing ML-powered queries and the associated CodeQL libraries.
|
2022-02-04 15:49:44 +00:00 |
|
Ian Wright
|
be5e8dae05
|
Update javascript/ql/experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling/FunctionBodyFeatures.qll
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-02-04 15:41:50 +00:00 |
|
Michael Nebel
|
7b3ba3cb96
|
C#: Modify database schema to allow lambda expression to be attributable and extract the lambda expression attributes.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
f412d49ba4
|
C#: Add some examples lambdas with different kind of attributes and update existing testcases.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
bb3f9cea3a
|
C#: Update test cases(s) expected output.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
7520948ec4
|
C#: Add test case for finding lambdas with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
83a5ef4961
|
C#: Examples of lambda expressions with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
25019dbaa0
|
C#: Add support QL library support for lambda explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
eb8c226749
|
C#: Add support for explicit return types in the extractor.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
ae62704d3a
|
C#: Add table for explicit return type in lambda expressions.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
ccb727e3ca
|
C#: Test cases that shows that lambdas can be naturally (implicitly) typed and that the type is indistinguishable from the equivalent explicitly typed declaration.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
a67033034a
|
C#: Example of naturally typed lambda.
|
2022-02-04 16:34:57 +01:00 |
|