Tom Hvitved
|
1237e566d0
|
C#: Fix typo
|
2021-01-04 12:59:45 +01:00 |
|
Tom Hvitved
|
c1f822c83f
|
C#: Port SSA performance improvements from Java
|
2021-01-04 10:18:17 +01:00 |
|
Tom Hvitved
|
591f90f98e
|
C#: Add change note
|
2020-12-21 10:26:49 +01:00 |
|
Tom Hvitved
|
b5a1e039a4
|
C#: Merge queries FormatInvalid.ql, FormatMissingArgument.ql, and FormatUnusedArgument.ql
|
2020-12-21 10:13:56 +01:00 |
|
Tom Hvitved
|
8d6c69bf74
|
C#: Move Expr::hasValue() to DotNet::Expr
|
2020-12-21 09:46:45 +01:00 |
|
John Lugton
|
059d6b0e0f
|
Fix warning in ServiceStack.qll
|
2020-12-18 08:34:06 -08:00 |
|
John Lugton
|
563dc62c33
|
Improve qldoc for ServiceStack.qll
|
2020-12-18 08:23:27 -08:00 |
|
Tom Hvitved
|
d53faa86dc
|
C#: Restrict FormatInvalid.ql and UncontrolledFormatString.ql to calls with insertions
|
2020-12-18 10:53:11 +01:00 |
|
Tamas Vajk
|
8e8c3a9ded
|
Add change note
|
2020-12-18 09:15:33 +01:00 |
|
Tamas Vajk
|
6fd1f0049d
|
Add DB upgrade folder
|
2020-12-18 09:10:55 +01:00 |
|
John Lugton
|
3f1f83f667
|
remove experimental
|
2020-12-17 16:24:52 -08:00 |
|
John Lugton
|
6d5f9035e6
|
Minor fixes to XSS:
Only want returns in request methods
Also care about non-string 1st args to HttpResult e.g. streams
|
2020-12-17 16:17:26 -08:00 |
|
John Lugton
|
7d47bffd53
|
Tidy up ServiceStack.qll
Use fully qualified names for classes
Make util predicate private
Make naming more consistent with rest of ql libs
|
2020-12-17 16:17:26 -08:00 |
|
Chelsea Boling
|
d4acccb13c
|
Update sink
|
2020-12-17 16:17:26 -08:00 |
|
Chelsea Boling
|
0a7e4b6840
|
Update sink based on feedback
|
2020-12-17 16:17:26 -08:00 |
|
Chelsea Boling
|
4e0f3a30ee
|
Update sink based on feedback
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
ba46eaa143
|
Refactor sink
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
3c493511e9
|
Update file
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
12e8107492
|
Add example
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
5c7dedffb3
|
Update sinks
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
71a08c3237
|
Update servicestack lib
|
2020-12-17 16:17:25 -08:00 |
|
John Lugton
|
d408ae7e10
|
Split ServiceStack into modules and incorporate into main lib
|
2020-12-17 16:17:25 -08:00 |
|
John Lugton
|
386eb2d56b
|
move ServiceStack out of microsoft
|
2020-12-17 16:17:25 -08:00 |
|
Chelsea Boling
|
cae6f91729
|
Create ServiceStack.qll
|
2020-12-17 16:17:24 -08:00 |
|
Chelsea Boling
|
dbe0170249
|
Add files via upload
|
2020-12-17 16:17:24 -08:00 |
|
Chelsea Boling
|
188dbde2d6
|
Create SQLInjection.ql
|
2020-12-17 16:17:24 -08:00 |
|
Tamas Vajk
|
8eeab8fdd0
|
Add new stats file
|
2020-12-17 21:22:58 +01:00 |
|
Tamas Vajk
|
f3a0d1d138
|
Add test to list all custom modifiers extracted from IL
|
2020-12-17 15:43:41 +01:00 |
|
Tamas Vajk
|
7662b55ecc
|
C#: Extract init only accessors and custom modifiers
|
2020-12-17 15:43:41 +01:00 |
|
Tom Hvitved
|
7a132149a2
|
C#: Add change note
|
2020-12-17 15:39:01 +01:00 |
|
Tom Hvitved
|
fe559c190e
|
C#: Recognize format methods without insertion parameters
|
2020-12-17 15:39:01 +01:00 |
|
Tamas Vajk
|
57c163f314
|
C#: Add test for CIL setter extraction
|
2020-12-17 15:23:33 +01:00 |
|
Tamás Vajk
|
45893ab084
|
Merge pull request #4775 from tamasvajk/feature/cil-attribute-decoding2
C#: Improve CIL attribute decoding
|
2020-12-17 15:20:44 +01:00 |
|
Tamas Vajk
|
f12befdcd0
|
Add extra test for collection initialization
|
2020-12-17 13:49:02 +01:00 |
|
Tamas Vajk
|
1bc65a68df
|
Address PR review comments
|
2020-12-16 16:12:11 +01:00 |
|
Robert Marsh
|
5d2a553059
|
C++/C#: autoformat
|
2020-12-15 17:16:31 -08:00 |
|
Robert Marsh
|
fd14eb4c8c
|
C++: remove unreachable IR operands in late stages
|
2020-12-15 11:45:40 -08:00 |
|
Tamas Vajk
|
8fd409898a
|
Add new stats file
|
2020-12-15 18:34:47 +01:00 |
|
Tamas Vajk
|
3cf967458f
|
Fix failing test
|
2020-12-15 14:28:51 +01:00 |
|
Tamas Vajk
|
adba961634
|
Add DB upgrade folder
|
2020-12-15 13:10:53 +01:00 |
|
Tamas Vajk
|
6cf3ca49e4
|
C#: Extract 'ImplicitObjectCreationExpressionSyntax'
|
2020-12-15 13:10:53 +01:00 |
|
Tom Hvitved
|
8c235323e7
|
Merge pull request #4796 from hvitved/csharp/cfg/simplify
C#: Various simplifications to CFG logic
|
2020-12-15 13:07:13 +01:00 |
|
Tamás Vajk
|
e391356893
|
Merge pull request #4630 from tamasvajk/feature/csharp9-init-prop
C#: Add support for init only accessors
|
2020-12-15 11:12:32 +01:00 |
|
Tamas Vajk
|
74c88e6bac
|
Add DB stats
|
2020-12-14 17:16:29 +01:00 |
|
Tom Hvitved
|
bb637f666c
|
C#: Introduce CfgScope class and generalize ControlFlowTree to include callables
|
2020-12-14 10:38:39 +01:00 |
|
Tom Hvitved
|
a92404a6cd
|
C#: Add LabeledStmtTree for goto CFG edges
|
2020-12-14 09:58:54 +01:00 |
|
Tom Hvitved
|
06d42dac3e
|
C#: Use set literals in Splitting.qll
|
2020-12-14 09:58:54 +01:00 |
|
Tom Hvitved
|
0b2233155c
|
C#: Simplify CFG logic for finally blocks
|
2020-12-14 09:58:53 +01:00 |
|
Tom Hvitved
|
249eea9d2b
|
Merge pull request #4780 from hvitved/csharp/cfg/nested-finally
C#: Add missing CFG edges for nested `finally` blocks
|
2020-12-14 09:57:36 +01:00 |
|
Robert Marsh
|
96e913031d
|
C#: share IR Operand IPA type between stages
|
2020-12-11 16:11:00 -08:00 |
|