Alex Ford
|
04d3d04317
|
Ruby: configsig rb/regex/badly-anchored-regexp
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
77f3a70376
|
Ruby: renames for rb/xpath-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
42cd58695d
|
Ruby: configsig rb/url-redirection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f79796a644
|
Ruby: configsig rb/shell-command-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f03f670312
|
Ruby: configsig rb/html-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
8ad6c72ba2
|
Ruby: configsig rb/unsafe-deserialization
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
461bc0d359
|
Ruby: configsig rb/unsafe-code-construction
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
3e23a6e021
|
Ruby: configsig rb/server-side-template-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
0a73ebdbee
|
Ruby: configsig rb/tainted-format-string
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f5e433940f
|
Ruby: renames for rb/stored-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
030aae5693
|
Ruby: configsig rb/stack-trace-exposure
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
bf1cb33be3
|
Ruby: configsig rb/sql-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ba8ff0710d
|
Ruby: configsig rb/request-forgery
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
df9173502e
|
Ruby: configsig rb/sensitive-get-query
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
593d9a48d4
|
Ruby: configsig rb/reflected-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ad2bbfb265
|
Ruby: configsig rb/path-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
867e47bcdd
|
Ruby: renames for rb/log-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
eb34bbbfd2
|
Ruby: renames for rb/ldap-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
d46eceb5f4
|
Ruby: configsig rb/kernel-open
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
a8ad0d8ff5
|
Ruby: renames for rb/insecure-download
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
c973fc1274
|
Ruby: configsig rb/http-to-file-access
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
2536f1a0cd
|
Ruby: configsig rb/user-controlled-bypass
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
377570f361
|
Ruby: configsig rb/command-line-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
b1a49ddb0d
|
Ruby: configsig rb/code-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
6fa267a820
|
Ruby: configsig rb/clear-text-storage-sensitive-data
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
2a2f21d3a9
|
Ruby: configsig rb/clear-text-logging-sensitive-data
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
ce35d6921f
|
Ruby: configsig rb/hardcoded-data-interpreted-as-code
|
2023-08-31 16:20:18 +01:00 |
|
Tom Hvitved
|
89e9d25f02
|
Ruby: Hide desugared assignments from data flow path graph
|
2023-08-31 14:04:57 +02:00 |
|
Tom Hvitved
|
50db6916c8
|
Ruby: Get rid of unused EmptinessSuccessor
|
2023-08-31 13:17:05 +02:00 |
|
Tom Hvitved
|
c4b626a416
|
Ruby: Use data flow consistency checks from shared pack
|
2023-08-30 15:29:41 +02:00 |
|
Dave Bartolomeo
|
3343b78015
|
Merge pull request #14074 from github/post-release-prep/codeql-cli-2.14.3
Post-release preparation for codeql-cli-2.14.3
|
2023-08-28 13:34:10 -04:00 |
|
github-actions[bot]
|
3eba77421a
|
Post-release preparation for codeql-cli-2.14.3
|
2023-08-28 15:53:49 +00:00 |
|
Alex Ford
|
9957e2683b
|
Merge pull request #13313 from maikypedia/maikypedia/ldap-improper-auth
Ruby: Add Improper LDAP Authentication query (CWE-287)
|
2023-08-25 20:52:34 +01:00 |
|
Maiky
|
17565cde75
|
Add JWT Security Queries
|
2023-08-25 21:28:53 +02:00 |
|
Alex Ford
|
ae635c609f
|
Ruby: autoformat
|
2023-08-25 17:11:07 +01:00 |
|
Maiky
|
ffd618d6cc
|
Revert "Add "" and nil as sources"
This reverts commit 664c1eba72.
|
2023-08-25 15:23:55 +02:00 |
|
Harry Maclean
|
d18ca3f5d7
|
Ruby: Fix bug in excon model
If a codebase included a definition for `Excon.new`, we matched
connection nodes to unrelated request nodes.
|
2023-08-23 12:55:36 +01:00 |
|
Harry Maclean
|
fb4b774c0d
|
Merge pull request #13967 from hmac/remove-splat-all
Ruby: Remove isSplatAll
|
2023-08-23 09:40:06 +01:00 |
|
Maiky
|
664c1eba72
|
Add "" and nil as sources
|
2023-08-22 18:10:33 +02:00 |
|
Maiky
|
f301e46175
|
Remove isEmptyPassword predicate
|
2023-08-22 12:23:32 +02:00 |
|
Tom Hvitved
|
5192d7c137
|
Merge pull request #13997 from hvitved/ruby/type-tracking-splats
Ruby: Include more (hash) splat flow in type tracking
|
2023-08-22 11:33:39 +02:00 |
|
Tom Hvitved
|
3f54ecbcc2
|
Update ruby/ql/lib/codeql/ruby/typetracking/TypeTrackerSpecific.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2023-08-22 11:18:12 +02:00 |
|
Michael Nebel
|
ce6fd8ac5f
|
Merge pull request #13432 from michaelnebel/updateissupported
Java/C#: Update telemetry queries to report callables with sink/source neutrals as being supported.
|
2023-08-22 08:39:38 +02:00 |
|
Jeroen Ketema
|
2d0f73d7c2
|
Merge pull request #13881 from jketema/shared-taint-tracking
Introduce shared taint tracking library
|
2023-08-21 12:45:49 +02:00 |
|
Michael Nebel
|
106ba11e10
|
Address review comments.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
d66fe08661
|
Add QLDoc for the getKind predicate.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
4c06fbdc65
|
Ruby: Sync files and make manual changes.
|
2023-08-21 09:59:01 +02:00 |
|
github-actions[bot]
|
098dfb4242
|
Release preparation for version 2.14.3
|
2023-08-18 14:48:15 +00:00 |
|
Tom Hvitved
|
deaa37d9d3
|
Ruby: Include more (hash)splat flow in type tracking
|
2023-08-18 14:07:12 +02:00 |
|
Harry Maclean
|
0bbda992fb
|
Ruby: Remove isSplatAll arg/parameter position
This is equivalent to isSplat(0).
|
2023-08-18 12:09:04 +01:00 |
|