copilot-swe-agent[bot]
81aed363a8
Initial plan
2026-07-15 17:19:04 +00:00
Jeroen Ketema
64df10409a
Merge pull request #22191 from jketema/jketema/swift-6.3.3
...
Swift: Update to Swift 6.3.3
2026-07-15 14:09:47 +02:00
Jeroen Ketema
a701922dbd
Swift: Update to Swift 6.3.3
2026-07-15 13:28:15 +02:00
Jeroen Ketema
303f81ee14
Merge pull request #22194 from github/jketema/kotlin-2.4.10
...
Kotlin: Support Kotlin 2.4.10
2026-07-15 11:46:21 +02:00
Michael Nebel
2c161e6b8f
Merge pull request #22180 from michaelnebel/csharp/rawurl
...
C#: Remove the RawUrl sanitizer.
2026-07-15 11:38:28 +02:00
Jeroen Ketema
574ef4d1ac
Kotlin: Support Kotlin 2.4.10
2026-07-15 10:17:58 +02:00
Owen Mansel-Chan
05734dcc38
Merge pull request #22175 from owen-mc/java/fix-path-sanitizer
...
Java: Fix `File.getName()` path sanitizer
2026-07-14 13:12:56 +01:00
Jeroen Ketema
8b477059fe
Merge pull request #22178 from jketema/jketema/go-recv
...
Go: Track whether a type parameter type was declared as part of a receiver
2026-07-14 10:49:52 +02:00
Jeroen Ketema
09da46d8bd
Go: Address review comments
2026-07-14 10:23:43 +02:00
Owen Mansel-Chan
2d0095826b
Address review comment
2026-07-13 19:40:31 +01:00
Michael Nebel
42843f155e
Merge pull request #22159 from aschackmull/java/join-order-effnonvirt
...
Java: Improve join order.
2026-07-13 16:45:54 +02:00
Jeroen Ketema
2656b5d87d
Merge pull request #22179 from jketema/jketema.new-free
...
C++: Update the CWE tag of `cpp/new-free-mismatch`
2026-07-13 16:25:58 +02:00
Michael Nebel
ae06b778e5
C#: Add change-note.
2026-07-13 15:29:18 +02:00
Michael Nebel
03e44f548f
C#: Update test and expected output.
2026-07-13 15:19:04 +02:00
Michael Nebel
a8885aeebd
C#: Remove the HttpRequest.RawUrl barrier model.
2026-07-13 15:18:38 +02:00
Jeroen Ketema
b3c16b48c2
Merge pull request #21516 from github/dependabot/bazel/nlohmann_json-3.12.0.bcr.1
...
Bump nlohmann_json from 3.11.3 to 3.12.0.bcr.1
2026-07-13 14:25:20 +02:00
Jeroen Ketema
5caa29a465
Merge branch 'main' into dependabot/bazel/nlohmann_json-3.12.0.bcr.1
2026-07-13 13:40:25 +02:00
Jeroen Ketema
e0f0987b81
Go: Make isFromReceiver and actual predicate
2026-07-13 13:24:23 +02:00
Jeroen Ketema
fe0d1af079
Merge pull request #22177 from github/workflow/go-version-update
...
Go: Update to 1.26.5
2026-07-13 13:21:01 +02:00
Jeroen Ketema
9efcc49af7
C++: Update the CWE tag of cpp/new-free-mismatch
2026-07-13 13:06:15 +02:00
Jeroen Ketema
9c1f5c9be2
Go: Fix dowgrade script formatting
2026-07-13 12:47:17 +02:00
Jeroen Ketema
e17508ca51
Go: Expose new TypeParamType column and use in test
2026-07-13 12:41:47 +02:00
Jeroen Ketema
37454ab5f6
Go: Add upgrade and downgrade scripts
2026-07-13 12:35:29 +02:00
Jeroen Ketema
032636cf34
Go: Track whether a type parameter was defined as part of a receiver
2026-07-13 12:35:27 +02:00
Jeroen Ketema
6017cbc6cb
Merge pull request #22176 from jketema/jketema/go-dead
...
Go: Remove dead extractor code
2026-07-13 12:33:00 +02:00
github-actions[bot]
0584ca09dc
Go: Update to 1.26.5
2026-07-13 04:12:46 +00:00
Jeroen Ketema
559f9f3850
Go: Remove dead isAlias
2026-07-13 00:38:58 +02:00
Jeroen Ketema
63ff22abd6
Go: Remove dead ObjectsOverride
2026-07-13 00:08:51 +02:00
Owen Mansel-Chan
a142121038
Merge pull request #22157 from github/dependabot/go_modules/go/extractor/extractor-dependencies-ac3bf41f8e
...
Bump golang.org/x/tools from 0.47.0 to 0.48.0 in /go/extractor in the extractor-dependencies group
2026-07-11 22:28:05 +01:00
Owen Mansel-Chan
6057b4b6e9
Fix path sanitizer
2026-07-11 07:28:14 +01:00
Owen Mansel-Chan
22fca39735
Merge pull request #22156 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2026-07-11 01:14:26 +01:00
Owen Mansel-Chan
dee6386459
Merge pull request #22126 from owen-mc/js/convert-qlref-inline-expectations
...
JS: Convert qlref tests to inline expectations
2026-07-11 00:24:20 +01:00
Owen Mansel-Chan
9fc65df23d
Merge pull request #22150 from owen-mc/go/remove-incorrect-sanitizer
...
Go: Fix incorrect path injection sanitizer `FilePath.Rel`
2026-07-10 15:25:17 +01:00
Anders Schack-Mulligen
33261f441e
Java: Improve join order.
...
Before:
```
[2026-07-10 15:15:58] Evaluated non-recursive predicate ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod.getAnAccess/0#dispred#efac59ed@090459qt in 4303ms (size: 186002).
Evaluated relational algebra for predicate ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod.getAnAccess/0#dispred#efac59ed@090459qt with tuple counts:
790592 ~0% {2} r1 = JOIN `Expr::MethodCall.getMethod/0#dispred#41989dc9_10#join_rhs` WITH `Member::Method.getSourceDeclaration/0#dispred#93e6cdf8` ON FIRST 1 OUTPUT Rhs.1, Lhs.1
539755681 ~2% {2} | JOIN WITH `Member::SrcMethod.getAPossibleImplementationOfSrcMethod/0#dispred#4f4317e6#bf` ON FIRST 1 OUTPUT Rhs.1, Lhs.1
186002 ~2% {2} | JOIN WITH ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod#86c19e07 ON FIRST 1 OUTPUT Lhs.0, Lhs.1
return r1
```
After:
```
[2026-07-10 15:29:39] Evaluated non-recursive predicate ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod.getAnAccess/0#dispred#efac59ed@32fb2e61 in 10ms (size: 186002).
Evaluated relational algebra for predicate ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod.getAnAccess/0#dispred#efac59ed@32fb2e61 with tuple counts:
122765 ~0% {2} r1 = SCAN ControlFlowGraph::NonReturningCalls::EffectivelyNonVirtualMethod#86c19e07 OUTPUT In.0, In.0
122766 ~0% {2} | JOIN WITH `Member::SrcMethod.getAPossibleImplementationOfSrcMethod/0#dispred#4f4317e6_10#join_rhs` ON FIRST 1 OUTPUT Rhs.1, Lhs.1
126911 ~0% {2} | JOIN WITH `Member::Method.getSourceDeclaration/0#dispred#93e6cdf8_10#join_rhs` ON FIRST 1 OUTPUT Rhs.1, Lhs.1
186002 ~2% {2} | JOIN WITH `Expr::MethodCall.getMethod/0#dispred#41989dc9_10#join_rhs` ON FIRST 1 OUTPUT Lhs.1, Rhs.1
return r1
```
2026-07-10 15:32:44 +02:00
Taus
247e54ba8d
Merge pull request #22112 from github/tausbn/yeast-reify-output-schema-as-ast-types
2026-07-10 12:11:41 +02:00
dependabot[bot]
985a79a45e
Bump golang.org/x/tools
...
Bumps the extractor-dependencies group in /go/extractor with 1 update: [golang.org/x/tools](https://github.com/golang/tools ).
Updates `golang.org/x/tools` from 0.47.0 to 0.48.0
- [Release notes](https://github.com/golang/tools/releases )
- [Commits](https://github.com/golang/tools/compare/v0.47.0...v0.48.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/tools
dependency-version: 0.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: extractor-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-10 03:03:43 +00:00
github-actions[bot]
8ff671f99d
Add changed framework coverage reports
2026-07-10 00:44:25 +00:00
Jeroen Ketema
161c8c4d30
Merge pull request #22149 from jketema/jketema/cwe-114-tag
...
C++/C#: Specify additional CWE tags for queries that specify CWE 114
2026-07-09 18:02:21 +02:00
Owen Mansel-Chan
233c3ce30d
Fix incorrect sanitizers
2026-07-09 16:47:49 +01:00
Jeroen Ketema
72efb6a058
C++: Add CWE 73 and CWE 78 tags to cpp/uncontrolled-process-operation
...
User controlled data here either leads to the loading of an uncontrolled
library (CWE 73) or the execution of an uncontrolled command (CWE 78).
2026-07-09 17:11:58 +02:00
Jeroen Ketema
66fea698a2
C#: Add CWE-73 tag to cs/assembly-path-injection
...
Use of CWE-114 is discoraged, and CWE-73 seems appropriate as the assembly
path is user controlled here.
2026-07-09 17:10:13 +02:00
Jeroen Ketema
2ae79d0f1e
C#: Remove misplaced change note
...
After almost 4 years it does not seem to be relevant anymore to propagate this
to the change log.
2026-07-09 17:09:07 +02:00
Florin Coada
747aa452cd
Merge pull request #22147 from github/codeql-spark-run-29025431896
...
Update changelog documentation site for codeql-cli-2.26.0
2026-07-09 15:43:31 +01:00
Taus
9e99a3c968
Merge branch 'main' into tausbn/yeast-reify-output-schema-as-ast-types
2026-07-09 16:30:06 +02:00
Taus
989154a105
Merge pull request #22136 from github/tausbn/yeast-translate-with-context
...
yeast: Add context scoping mechanism
2026-07-09 16:29:54 +02:00
github-actions[bot]
36d0ceb292
update codeql documentation
2026-07-09 14:29:47 +00:00
Taus
d609680083
yeast: Fix escaping bug in yeast-macros
...
Happily, it turned out that there was already a library function for
handling this case.
2026-07-09 11:48:50 +00:00
Taus
11afcce8b3
yeast: Fix bug in matching (_)
...
Turns out, `(_)` would match both named and unnamed nodes, as we never
checked the value of the `match_unnamed` field. This is the real reason
why the final catch-all rule we removed in the last commit was
superfluous -- unnamed nodes were being caught by the penultimate rule
instead (and mapped to `unsupported_node`).
Having fixed the bug, we now (correctly) get errors due to unmatched
unnamed nodes in the input. To fix this, we change the catch-all rule to
match unnamed nodes as well. This restores the previous behaviour
exactly.
At some point, we should find a better way to handle unnamed nodes, as
it seems wasteful to map these to `unsupported_node` (since we in
practice only use them for their string content). Perhaps we should not
attempt to translate unnamed nodes at all?
2026-07-09 11:48:50 +00:00
Taus
ee04938ded
yeast: Require type annotations on root-level Rust interpolations
...
In order to facilitate static type checking of rules (and to make it
easier for human readers as well), rust blocks at the root level (i.e.
rules of the form `... => { ... }`) must now have a type annotation in
front.
All other forms are unaffected: if the right hand side of a rule is a
tree, we can read the type of the root node directly. For interpolations
that happen inside of such a tree, we can recover the type by looking at
what field we're interpolating into, and consulting the output schema.
All existing uses have been updated to have the appropriate type
annotations, though these are of course not checked yet (and so could be
wrong).
Finally, this commit also removes the final catch-all rule `_ @node =>
{node}`. Because of the preceding rule that matches `(_) @node`, this
rule would only ever match unnamed nodes, and I think in practice it did
not match at all (at least not in our current set of tests).
To give it a proper type we would have to add some notion of an "any"
type, which I would like to avoid. If it _does_ turn out to be needed,
we can easily add it back (ideally with a test-case that shows why it's
still needed).
2026-07-09 11:48:50 +00:00
Taus
ea36f2d7f8
yeast: add rules! macro
...
This macro allows the easy addition of multiple rules at the same time.
In addition, it also accepts an input and output schema, which
eventually will be used to check the validity of the rewrite rules.
2026-07-09 11:39:30 +00:00