Nick Rolfe
|
f18492e39b
|
Merge pull request #7443 from github/nickrolfe/behavior
QL4QL: catch behaviour/behavior in ql/non-us-spelling
|
2021-12-20 13:23:53 +00:00 |
|
Tom Hvitved
|
ed006d7283
|
Merge pull request #7231 from hvitved/csharp/dataflow/consistency-queries
C#: Enable data-flow consistency queries
|
2021-12-20 08:46:19 +01:00 |
|
Nick Rolfe
|
28912c508f
|
Fix non-US spelling of 'behavior'
|
2021-12-17 15:29:31 +00:00 |
|
Tom Hvitved
|
e4d9f5f29e
|
Fix QL doc
|
2021-12-17 13:14:11 +01:00 |
|
Tom Hvitved
|
ab2e0fdb18
|
Data flow: Sync files
|
2021-12-17 13:13:36 +01:00 |
|
Tony Torralba
|
6f2d91a8ad
|
Sinks for CloseableThreadContext
|
2021-12-17 09:17:04 +01:00 |
|
Tony Torralba
|
7d6cba77a0
|
Add tests
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
2e0ca6ce2b
|
Add stubs
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
7d70b77141
|
Add new sinks and taint steps
|
2021-12-16 13:43:58 +01:00 |
|
Tony Torralba
|
c1e4c05aa2
|
Update change note to new format
|
2021-12-15 13:08:34 +01:00 |
|
Tony Torralba
|
e2022f467c
|
Update java/ql/lib/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
a3b25f0eb5
|
Don't consider subtypes of fields
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
47002a3bd7
|
Fix test
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
1426c5b406
|
Consider parameterized types
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
7ce9b04941
|
Add change note
|
2021-12-15 13:00:15 +01:00 |
|
Tony Torralba
|
5e80044f11
|
Preserve taint on field-read-steps on entrypoint types
|
2021-12-15 13:00:15 +01:00 |
|
Tony Torralba
|
68a0efaf0c
|
Formatting
|
2021-12-14 14:53:38 +01:00 |
|
Bas van Schaik
|
d85ed9ea7a
|
Clarify Log4jJndiInjection.ql query help
|
2021-12-14 12:32:36 +00:00 |
|
Chris Smowton
|
85ff57bae6
|
Merge pull request #7354 from atorralba/atorralba/log4j-rce-experimental-query
Java: Experimental query for Log4j JNDI Injection
|
2021-12-14 11:32:13 +00:00 |
|
Tony Torralba
|
aee617f911
|
Autoformat
|
2021-12-14 08:40:30 +01:00 |
|
Tony Torralba
|
1b761b3d12
|
Apply suggestions from code review
|
2021-12-13 20:38:06 +01:00 |
|
Tony Torralba
|
ff2f5a5f91
|
Apply suggestions from code review
Co-authored-by: Bas van Schaik <5082246+sj@users.noreply.github.com>
|
2021-12-13 19:44:38 +01:00 |
|
Tony Torralba
|
d2dc19900f
|
Apply suggestions from code review
Co-authored-by: Bas van Schaik <5082246+sj@users.noreply.github.com>
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-12-13 19:39:52 +01:00 |
|
Andrew Eisenberg
|
0669ef505e
|
Fix semver for upgrades references
Ensure the version range is flexible enough to handle
future version changes.
|
2021-12-13 09:03:33 -08:00 |
|
Andrew Eisenberg
|
66c1629974
|
Merge pull request #7285 from github/post-release-prep-2.7.3-ddd4ccbb
Post-release preparation 2.7.3
|
2021-12-10 09:59:45 -08:00 |
|
Tony Torralba
|
43a10457dd
|
[Java] Query for Log4j JNDI Injection
|
2021-12-10 17:37:43 +01:00 |
|
github-actions[bot]
|
7e5bfa5aa0
|
Add changed framework coverage reports
|
2021-12-10 00:09:34 +00:00 |
|
Chris Smowton
|
753d886b0d
|
Merge pull request #6319 from haby0/java/MyBatisSqlInjection
[Java] CWE-089 MyBatis Mapper Sql Injection
|
2021-12-09 19:57:18 +00:00 |
|
Chris Smowton
|
75f3ebf051
|
Fix OTHER XML tag
|
2021-12-09 17:55:03 +00:00 |
|
Chris Smowton
|
9f69c75c50
|
Fix XML tag
|
2021-12-09 17:44:49 +00:00 |
|
Chris Smowton
|
2cd70b96cd
|
Fix doctype
|
2021-12-09 17:44:08 +00:00 |
|
Chris Smowton
|
470256da85
|
Copyedit
|
2021-12-09 15:10:07 +00:00 |
|
Chris Smowton
|
d0a19fffee
|
Copyedit
|
2021-12-09 14:58:29 +00:00 |
|
Tony Torralba
|
38250b0821
|
Remove unnecessary implicit read step
|
2021-12-09 15:18:38 +01:00 |
|
Tony Torralba
|
522a4bb9fa
|
Propagate extras through build methods
|
2021-12-09 14:56:52 +01:00 |
|
Tony Torralba
|
c0c40cc05b
|
Remove synthetic fields
|
2021-12-09 13:34:41 +01:00 |
|
Tony Torralba
|
3a3c7fc59e
|
Fix stub
|
2021-12-09 13:34:41 +01:00 |
|
Tony Torralba
|
f209ff4f76
|
Use synthetic fields to improve taint precision
|
2021-12-09 13:34:39 +01:00 |
|
Tony Torralba
|
b7f7c5ba20
|
Change format of fluent models to make review easier
|
2021-12-09 13:33:19 +01:00 |
|
Tony Torralba
|
f63ffb0630
|
Add models for Notification builders
|
2021-12-09 13:33:17 +01:00 |
|
haby0
|
8bcbf8e30f
|
rename isMybatisCollectionTypeSqlInjection
|
2021-12-09 09:16:33 +08:00 |
|
haby0
|
a18aad8536
|
Fix one
|
2021-12-08 21:03:17 +08:00 |
|
Anders Schack-Mulligen
|
38d0bb4a60
|
Merge pull request #7260 from hvitved/dataflow/argument-parameter-matching
Data flow: Introduce `ParameterPosition` and `ArgumentPosition`
|
2021-12-08 12:49:08 +01:00 |
|
haby0
|
1d321c692b
|
Refactor isMybatisXmlOrAnnotationSqlInjection
|
2021-12-08 18:59:55 +08:00 |
|
Tom Hvitved
|
283173ad02
|
Address review comments
|
2021-12-08 11:26:44 +01:00 |
|
Tom Hvitved
|
490872173a
|
Data flow: Sync files
|
2021-12-07 20:29:18 +01:00 |
|
Anders Schack-Mulligen
|
6c739b67fa
|
Merge pull request #7318 from RasmusWL/java-cwe-328
Java: Tag queries with CWE-328
|
2021-12-07 11:39:48 +01:00 |
|
Erik Krogh Kristensen
|
3c59aa319e
|
Merge pull request #7245 from erik-krogh/explicit-this-all-the-places
All langs: apply the explicit-this patch to all remaining code
|
2021-12-07 10:40:26 +01:00 |
|
Rasmus Wriedt Larsen
|
ff9ed0d4fb
|
Java: Tag queries with CWE-328
CWE-328: Use of Weak Hash, see https://cwe.mitre.org/data/definitions/328.html
Since weak hash functions (md5/sha1) are considered for the
`java/weak-cryptographic-algorithm` query. See
caeeebf572/java/ql/lib/semmle/code/java/security/Encryption.qll (L148)
To keep things consistent between `java/weak-cryptographic-algorithm`
and `java/potentially-weak-cryptographic-algorithm`, I also added the
tag to the latter.
|
2021-12-06 13:59:00 +01:00 |
|
github-actions[bot]
|
c46ede02e6
|
Add changed framework coverage reports
|
2021-12-06 00:09:47 +00:00 |
|