Erik Krogh Kristensen
|
3bea7df45d
|
add deprecated aliases in the old locations, and use the Query.qll pattern for js/polynomial-redos
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
13482fc97b
|
rename ReDoSUtil to NfaUtils, and rename the "performance" folder to "regexp"
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
6b0df9bdfb
|
refactor the concretize algorithm
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dbeae9aefb
|
make a parameterized module out of the RegexpMatching implementation
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
7fb3d81d2f
|
add further normalization of char classses
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3be4a86acd
|
make ReDoSPruning into a parameterized module
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dc06e9df02
|
move predicates that depend on isReDoSCandidate into a ReDoSPruning module
|
2022-06-23 14:36:24 +02:00 |
|
Anders Schack-Mulligen
|
4a317a25d3
|
Dataflow: Sync.
|
2022-06-23 14:34:52 +02:00 |
|
Asger F
|
d94010c244
|
Grammar: report -> reports
|
2022-06-23 14:17:52 +02:00 |
|
github-actions[bot]
|
a74051c658
|
Release preparation for version 2.10.0
|
2022-06-23 11:17:46 +00:00 |
|
Rasmus Wriedt Larsen
|
3248f7b423
|
Merge pull request #9649 from RasmusWL/certificate-modeling
Python/JS/Ruby: Ignore common words (like certain) as sensitive data source
|
2022-06-23 12:04:58 +02:00 |
|
thiggy1342
|
e838b83f5f
|
attempt to introduce dataflow tracking
|
2022-06-23 02:21:47 +00:00 |
|
Rasmus Wriedt Larsen
|
876ba71d9b
|
Python/JS/Ruby: Add change-note
|
2022-06-22 11:14:05 +02:00 |
|
Rasmus Wriedt Larsen
|
2ce4b7b9fc
|
SensitiveDataHeuristics: sync
|
2022-06-22 11:05:14 +02:00 |
|
Anders Schack-Mulligen
|
df6d68b215
|
Merge pull request #9618 from aschackmull/dataflow/deprecate-barrierguard-class
Dataflow: Deprecate BarrierGuard class
|
2022-06-22 10:44:08 +02:00 |
|
Michael Nebel
|
24ba5cc06e
|
Merge pull request #9025 from michaelnebel/csharp/generatedrefactor
C#: Provenance column in Models as Data CSV format.
|
2022-06-22 10:34:31 +02:00 |
|
thiggy1342
|
995f365568
|
just check string literal
|
2022-06-22 02:17:01 +00:00 |
|
thiggy1342
|
c767f241ad
|
narrow query scope
|
2022-06-22 02:12:23 +00:00 |
|
thiggy1342
|
f6c4b5c44b
|
Merge branch 'experimental-manually-check-request-verb' of https://github.com/thiggy1342/codeql into experimental-manually-check-request-verb
|
2022-06-21 21:27:39 +00:00 |
|
thiggy1342
|
990747cd22
|
Limit findings to just those called in Controllers
|
2022-06-21 21:27:18 +00:00 |
|
thiggy1342
|
53729f99c5
|
restrict findings to just controller classes
|
2022-06-21 20:28:29 +00:00 |
|
thiggy1342
|
83b720d730
|
first draft of weak params query
|
2022-06-21 19:28:53 +00:00 |
|
Brandon Stewart
|
a2e2dcdfd5
|
Make ActiveRecordInstanceMethodCall Public
|
2022-06-21 14:44:52 -04:00 |
|
Anders Schack-Mulligen
|
f8f9b7d3b4
|
Apply suggestions from code review
|
2022-06-21 14:11:36 +02:00 |
|
Asger F
|
a1af9c3d7d
|
Ruby: update predicate docs
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
d15b90e21a
|
Ruby: Add deprecation
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
9838e2e101
|
Ruby: Rename getAValueReachingRhs -> getAValueReachingSink
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
7c877c7861
|
Ruby: Rename getARhs -> asSink
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
2f8086bb57
|
Ruby: Rename getAUse -> getAValueReachableFromSource
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
573c5c5efe
|
Ruby: Rename getAnImmediateUse -> asSource
|
2022-06-21 12:44:16 +02:00 |
|
Asger F
|
f2403e2610
|
Ruby: port API graph doc comment
|
2022-06-21 12:44:16 +02:00 |
|
Edoardo Pirovano
|
70dbd92e25
|
Bump minor version of all regularly released packs
|
2022-06-21 11:22:58 +01:00 |
|
Edoardo Pirovano
|
ad02b85efa
|
Merge branch main into rc/3.6
|
2022-06-21 11:15:25 +01:00 |
|
Anders Schack-Mulligen
|
736372ffd6
|
Ruby: Remove test.
|
2022-06-21 11:18:36 +02:00 |
|
Anders Schack-Mulligen
|
a4796e1542
|
Add change notes.
|
2022-06-21 11:17:47 +02:00 |
|
thiggy1342
|
c5bf1b8aab
|
update test expectation
|
2022-06-20 17:27:33 +00:00 |
|
thiggy1342
|
973013ff9c
|
Merge branch 'main' into experimental-decompression-api
|
2022-06-20 11:37:38 -04:00 |
|
thiggy1342
|
7932d3e4ab
|
Update ruby/ql/test/query-tests/security/decompression-api/DecompressionApi.expected
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-06-20 11:05:56 -04:00 |
|
thiggy1342
|
db46a1d807
|
Update ruby/ql/src/experimental/decompression-api/DecompressionApi.ql
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-06-20 11:05:16 -04:00 |
|
Arthur Baars
|
c5d3df087d
|
Update tree-sitter-embeded-template
|
2022-06-20 17:04:27 +02:00 |
|
Michael Nebel
|
649757c27f
|
Java/Ruby: Sync files.
|
2022-06-20 16:20:01 +02:00 |
|
thiggy1342
|
633ddf46fb
|
fix comments
|
2022-06-20 13:53:56 +00:00 |
|
thiggy1342
|
b4c893d857
|
Update ruby/ql/test/query-tests/security/decompression-api/decompression_api.rb
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-06-20 09:50:12 -04:00 |
|
thiggy1342
|
9c9ac919b7
|
Update ruby/ql/src/experimental/decompression-api/DecompressionApi.ql
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-06-20 09:49:52 -04:00 |
|
thiggy1342
|
3949e04797
|
Update ruby/ql/src/experimental/decompression-api/DecompressionApi.ql
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-06-20 09:49:11 -04:00 |
|
thiggy1342
|
2f505c527b
|
Merge branch 'main' into experimental-decompression-api
|
2022-06-20 09:48:21 -04:00 |
|
Anders Schack-Mulligen
|
1b13790a36
|
Ruby: Deprecate and replace BarrierGuard class.
|
2022-06-20 15:46:38 +02:00 |
|
Rasmus Wriedt Larsen
|
ae44a941f9
|
Merge pull request #9421 from RasmusWL/inline-brackets
Inline Expectation Tests: Allow `tag[foo bar]`
|
2022-06-20 10:01:19 +02:00 |
|
Harry Maclean
|
e1dcc207b4
|
Ruby: Model methods in Rails::Generators::Actions
These methods are sinks for command injection.
|
2022-06-20 13:36:09 +12:00 |
|
Harry Maclean
|
20ff4c4299
|
Ruby: Model ActiveRecord::Relation#touch_all
|
2022-06-20 13:36:02 +12:00 |
|