github-actions[bot]
|
0ee476129a
|
Post-release preparation for codeql-cli-2.10.1
|
2022-07-14 14:38:49 +00:00 |
|
Erik Krogh Kristensen
|
85a652f3d1
|
remove a bunch of repeated words
|
2022-07-14 12:42:48 +02:00 |
|
github-actions[bot]
|
d1aa0d7dd3
|
Release preparation for version 2.10.1
|
2022-07-14 08:56:03 +00:00 |
|
thiggy1342
|
62a10e20b2
|
Merge branch 'main' into experimental-manually-check-request-verb
|
2022-07-13 20:28:09 -04:00 |
|
thiggy1342
|
8ca7d7d775
|
update change note
|
2022-07-14 00:22:38 +00:00 |
|
thiggy1342
|
9d277027a3
|
Merge branch 'main' into experimental-strong-params
|
2022-07-13 20:19:50 -04:00 |
|
thiggy1342
|
3dd61cadf4
|
formatting query
|
2022-07-14 00:19:36 +00:00 |
|
thiggy1342
|
ee79834cc8
|
formatting in qhelp
|
2022-07-14 00:15:39 +00:00 |
|
thiggy1342
|
ae634367c9
|
add qhelp file
|
2022-07-14 00:11:52 +00:00 |
|
thiggy1342
|
2cc703387b
|
use taint config for data flow
|
2022-07-14 00:11:52 +00:00 |
|
thiggy1342
|
f5301aa478
|
Merge branch 'main' into add-activerecord-annotate
|
2022-07-13 14:35:44 -04:00 |
|
Erik Krogh Kristensen
|
9e2e32f037
|
Merge pull request #9322 from erik-krogh/fixAutoBuild
QL/RB: fix the QL-for-QL and ruby autobuilders
|
2022-07-13 14:39:59 +02:00 |
|
Erik Krogh Kristensen
|
595875ff98
|
remove redundant not-equals check
|
2022-07-13 12:06:12 +02:00 |
|
Erik Krogh Kristensen
|
a4262f8d91
|
add some more references to the overly-large-range qhelp
|
2022-07-13 11:20:24 +02:00 |
|
Harry Maclean
|
1fa2144716
|
Ruby: Update test fixtures
|
2022-07-13 21:02:08 +12:00 |
|
Erik Krogh Kristensen
|
c4f44bb67f
|
sync files
|
2022-07-13 10:01:26 +02:00 |
|
Erik Krogh Kristensen
|
047b14e310
|
get the autobuilders to work after introducing test-cases
|
2022-07-13 09:50:55 +02:00 |
|
Erik Krogh Kristensen
|
eb0340dcb6
|
get excludes to work properly
|
2022-07-13 09:50:55 +02:00 |
|
Erik Krogh Kristensen
|
2850b35a04
|
update, and fix, the autobuilders by using the new --also-match option
|
2022-07-13 09:48:29 +02:00 |
|
Harry Maclean
|
49aab51893
|
Ruby: Make helper predicate private
|
2022-07-13 18:20:27 +12:00 |
|
Harry Maclean
|
ea95e2e1d0
|
Ruby: Use InclusionTests library in barrier guards
|
2022-07-13 18:20:27 +12:00 |
|
Harry Maclean
|
b9fc82a741
|
Ruby: Test both old and new-style barrier guards
|
2022-07-13 18:20:25 +12:00 |
|
Harry Maclean
|
4cfaa86d5d
|
Ruby: Update new-style barrier-guard
|
2022-07-13 18:20:14 +12:00 |
|
Harry Maclean
|
5f17d8370c
|
Ruby: Small change to isArrayExpr
|
2022-07-13 18:20:14 +12:00 |
|
Harry Maclean
|
63dcce9a31
|
Ruby: Refactor isArrayConstant
|
2022-07-13 18:20:14 +12:00 |
|
Harry Maclean
|
b5a3d3c488
|
Ruby: Extract isArrayConstant
This predicate might be useful elsewhere.
|
2022-07-13 18:20:14 +12:00 |
|
Harry Maclean
|
301914d80c
|
Ruby: Add an extra barrier guard test
|
2022-07-13 18:20:14 +12:00 |
|
Harry Maclean
|
706d1d2eee
|
Ruby: Make StringArrayInclusion more sensitive
We now recognise the following pattern as a barrier guard for `x`:
values = ["foo", "bar"]
if values.include? x
sink x
end
|
2022-07-13 18:20:12 +12:00 |
|
thiggy1342
|
7129002573
|
tweak tests more
|
2022-07-13 00:33:58 +00:00 |
|
thiggy1342
|
b3f1a513d1
|
Update tests
|
2022-07-13 00:25:43 +00:00 |
|
thiggy1342
|
9a0a9491da
|
Merge branch 'main' into add-activerecord-annotate
|
2022-07-12 20:13:56 -04:00 |
|
thiggy1342
|
2566ae9889
|
Merge branch 'main' into experimental-strong-params
|
2022-07-12 20:12:51 -04:00 |
|
thiggy1342
|
db5f63b208
|
add tests
|
2022-07-12 23:14:16 +00:00 |
|
thiggy1342
|
7facc63699
|
remove predicate
|
2022-07-12 22:59:48 +00:00 |
|
thiggy1342
|
74d6061082
|
Merge branch 'main' into experimental-manually-check-request-verb
|
2022-07-12 17:15:54 -04:00 |
|
Erik Krogh Kristensen
|
8e52fc97fc
|
changes based on review by Shack
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
220ff3cb2e
|
convert tabs to spaces in qhelp
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
aae3e2ddde
|
other changes based on Esbens review
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
ff25451699
|
rename query to overly-large-range, and rewrite the @description
|
2022-07-12 16:02:46 +02:00 |
|
Nick Rolfe
|
217c9a8aaf
|
Fix typo in changenote
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2022-07-12 08:50:58 +01:00 |
|
Nick Rolfe
|
a3628b06f1
|
Ruby: fix markup in changenote
|
2022-07-11 17:23:45 +01:00 |
|
Nick Rolfe
|
032aa56dc3
|
Ruby: add change note for system command execution sink bug
|
2022-07-11 17:00:07 +01:00 |
|
Nick Rolfe
|
6632dfaf88
|
Ruby: fix another SystemCommandExecution::isShellInterpreted implementation
|
2022-07-11 16:53:30 +01:00 |
|
thiggy1342
|
ad7c3e7217
|
Merge branch 'main' into experimental-manually-check-request-verb
|
2022-07-11 10:20:07 -04:00 |
|
Nick Rolfe
|
348ad95fc0
|
Ruby: fix defining every dataflow node as a command execution sink
|
2022-07-11 15:06:27 +01:00 |
|
thiggy1342
|
e8e8da1b31
|
fix lib test expect for ActionController
|
2022-07-08 19:01:01 +00:00 |
|
thiggy1342
|
5d3232c614
|
refactor to use data flow
|
2022-07-08 18:53:24 +00:00 |
|
thiggy1342
|
96e66c4a50
|
move tests
|
2022-07-08 18:39:04 +00:00 |
|
thiggy1342
|
0435105d16
|
Merge remote-tracking branch 'upstream/main' into experimental-strong-params
|
2022-07-08 18:36:09 +00:00 |
|
thiggy1342
|
6aab970a9e
|
refactor query to use cfg and dataflow
|
2022-07-08 18:32:54 +00:00 |
|