Arthur Baars
|
682bf6d3a7
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-19 14:16:05 +01:00 |
|
yoff
|
d4eb2b964c
|
Merge pull request #11699 from erik-krogh/shareHost
Dynamic: Share more regexp code
|
2022-12-19 13:29:53 +01:00 |
|
Arthur Baars
|
23f595bea1
|
JavaScript: use shared AlertSuppression.qll
|
2022-12-19 12:25:17 +01:00 |
|
erik-krogh
|
442749bb7f
|
JS: add heuristic variants of queries that use RemoteFlowSource
|
2022-12-19 12:01:22 +01:00 |
|
Jean Helie
|
31f7702a04
|
Merge pull request #11726 from github/jhelie/fix-endpoint-large-scale-script
ATM: fix script updating endpoint large scale test data
|
2022-12-19 10:55:30 +01:00 |
|
erik-krogh
|
35e8d6afd4
|
move getACommonTld into a utility module without parameters
|
2022-12-18 17:23:45 +01:00 |
|
erik-krogh
|
26c5480ee6
|
share {js,rb}/regex/missing-regexp-anchor
|
2022-12-18 17:23:41 +01:00 |
|
turbo
|
1e5426fca2
|
Create security-experimental suite helper and all language suite implementations
|
2022-12-18 15:44:08 +01:00 |
|
erik-krogh
|
355499ea52
|
move getACommonTld to the shared pack
|
2022-12-17 17:26:18 +01:00 |
|
erik-krogh
|
f67d0bc8c0
|
put the shared HostnameRegexp code in the shared regex pack
|
2022-12-17 17:26:18 +01:00 |
|
Henry Mercer
|
30451ee950
|
Merge pull request #11681 from github/henrymercer/mergeback-3.8
Merge `rc/3.8` back to `main`
|
2022-12-16 17:43:12 +00:00 |
|
Jean Helie
|
938a7e828c
|
update tests
|
2022-12-16 15:31:43 +01:00 |
|
Jean Helie
|
cd0220b248
|
update autogenerated data for endpoint_large_scale
|
2022-12-16 14:03:01 +01:00 |
|
Jean Helie
|
904a4bd48b
|
fix script updating endpoint_large_scale test data
|
2022-12-16 14:03:00 +01:00 |
|
Erik Krogh Kristensen
|
1500fa5f67
|
Merge pull request #10663 from pwntester/restify_improvements
Javascript: Improve Restify support and add new Spife support
|
2022-12-15 11:08:22 +01:00 |
|
Erik Krogh Kristensen
|
55558120d9
|
add explicit this
|
2022-12-14 20:59:28 +01:00 |
|
Alvaro Muñoz
|
f46a8faf00
|
port RouteSetup API-based implementation to DataFlow one
|
2022-12-14 17:37:32 +01:00 |
|
turbo
|
4ec401a3f6
|
Tag all security queries in supported languages' experimental directories with an experimental tag
|
2022-12-14 17:15:50 +01:00 |
|
Asger F
|
a92acf5218
|
Merge pull request #11689 from asgerf/js/missing-csrf-qhelp
JS: Update MissingCsrfMiddleware after 'csurf' deprecation
|
2022-12-14 15:50:32 +01:00 |
|
Alvaro Muñoz
|
818c2da1aa
|
fix Spife tests (without heuristics)
|
2022-12-14 15:42:27 +01:00 |
|
Alvaro Muñoz
|
4cf7299d79
|
restore Spife.qll to working status
|
2022-12-14 15:41:53 +01:00 |
|
Alvaro Muñoz
|
14faff4477
|
fix restify tests
|
2022-12-14 15:38:35 +01:00 |
|
Alvaro Muñoz
|
e1f05e960d
|
Merge branch 'restify_improvements' of https://github.com/pwntester/codeql into restify_improvements
|
2022-12-14 13:11:13 +01:00 |
|
Alvaro Muñoz
|
a71fc930a6
|
add tests
|
2022-12-14 13:11:02 +01:00 |
|
Asger F
|
b63c658e3b
|
JS: recognize tiny-csrf
|
2022-12-14 12:30:15 +01:00 |
|
Asger F
|
162419138d
|
JS: Replace csurf -> lusca.csrf from example and qhelp
|
2022-12-14 12:30:15 +01:00 |
|
Henry Mercer
|
6023a1225c
|
Merge pull request #11673 from github/codeql-ci/atm/release-0.4.4
JS: Bump version numbers of ML-powered packs after 0.4.4 release
|
2022-12-14 10:27:00 +00:00 |
|
Alvaro Muñoz
|
701676eea1
|
Update javascript/ql/lib/semmle/javascript/frameworks/Spife.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-14 10:18:47 +01:00 |
|
Erik Krogh Kristensen
|
8a89849476
|
Merge pull request #11660 from erik-krogh/dynamic-useInstanceOf
Py/JS/RB: Use instanceof in more places
|
2022-12-13 21:50:13 +01:00 |
|
Henry Mercer
|
a3933fbf4f
|
Bump minor versions of packs we regularly release
|
2022-12-13 18:59:24 +00:00 |
|
Henry Mercer
|
7167f078be
|
Merge branch 'main' into henrymercer/mergeback-3.8
|
2022-12-13 18:40:53 +00:00 |
|
Henry Mercer
|
423374a7b8
|
Merge branch 'main' into codeql-ci/atm/release-0.4.4
|
2022-12-13 14:26:21 +00:00 |
|
github-actions[bot]
|
745823ca60
|
JS: Bump version of ML-powered library and query packs to 0.4.5
|
2022-12-13 13:32:52 +00:00 |
|
github-actions[bot]
|
ea13925a92
|
JS: Bump patch version of ML-powered library and query packs
|
2022-12-13 13:28:09 +00:00 |
|
Asger F
|
6b15839221
|
JS: Add tests for the examples used in the docs
|
2022-12-13 11:33:12 +01:00 |
|
Asger F
|
ba1364a4cb
|
JS: Add sinks mentioned in doc
Note that 'sql-injection' was already added
|
2022-12-13 11:33:12 +01:00 |
|
Alvaro Muñoz
|
270a4355df
|
format Restify.qll
|
2022-12-13 11:22:24 +01:00 |
|
Alvaro Muñoz
|
4ba3190d29
|
Replace API::Node with DataFlow::Node for Spife's RouteSetup
|
2022-12-13 11:10:04 +01:00 |
|
erik-krogh
|
b3a9c1ca06
|
Py/JS/RB: Use instanceof in more places
|
2022-12-12 16:06:57 +01:00 |
|
Alvaro Muñoz
|
469d7f52dc
|
Use fluent API instead of hasPropertyWrite
|
2022-12-12 10:46:50 +01:00 |
|
Alvaro Muñoz
|
1410d2838e
|
Update javascript/ql/lib/semmle/javascript/frameworks/Spife.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-12 09:54:02 +01:00 |
|
github-actions[bot]
|
343b7b1c8b
|
Post-release preparation for codeql-cli-2.11.6
|
2022-12-11 18:15:04 +00:00 |
|
github-actions[bot]
|
0b2fb4f70a
|
Release preparation for version 2.11.6
|
2022-12-10 15:49:35 +00:00 |
|
Asger F
|
387a673c10
|
Merge pull request #11567 from asgerf/js/data-extensions2
JS: Move MaD models to data extensions
|
2022-12-09 10:09:24 +01:00 |
|
Henry Mercer
|
280bb6864f
|
Merge pull request #11604 from github/codeql-ci/atm/release-0.4.3
JS: Bump version numbers of ML-powered packs after 0.4.3 release
|
2022-12-08 13:04:16 +00:00 |
|
Chris Smowton
|
49bc524fd0
|
Merge remote-tracking branch 'origin/rc/3.8' into smowton/admin/merge-rc38-into-main
|
2022-12-08 11:12:30 +00:00 |
|
Henry Mercer
|
78f15755d7
|
Merge branch 'main' into codeql-ci/atm/release-0.4.3
|
2022-12-07 20:49:26 +00:00 |
|
github-actions[bot]
|
d577eeeea8
|
JS: Bump version of ML-powered library and query packs to 0.4.4
|
2022-12-07 20:05:30 +00:00 |
|
github-actions[bot]
|
9702ea02fb
|
JS: Bump patch version of ML-powered library and query packs
|
2022-12-07 20:01:33 +00:00 |
|
Alvaro Muñoz
|
38b2f537d4
|
Use ReplyCall.super syntax instead of this.(ReplyCall)
|
2022-12-07 16:39:07 +01:00 |
|