Maiky
|
820db43945
|
Add ERB Template Injection Sink
|
2023-04-13 17:21:31 +02:00 |
|
Michael Nebel
|
52bc43b22b
|
Merge pull request #12595 from michaelnebel/enhanceprovenance
Java/C# : Enhance provenance.
|
2023-04-13 14:27:53 +02:00 |
|
Alex Ford
|
8c46bfd051
|
Merge pull request #12816 from github/rc/3.9
Merge `rc/3.9` into `main`
|
2023-04-13 12:35:41 +01:00 |
|
Michael Nebel
|
1d82b09ec1
|
Sync files.
|
2023-04-13 09:21:05 +02:00 |
|
Asger F
|
69cb138912
|
Ruby: Tweak caching/inlining or API graph predicates
|
2023-04-12 15:56:58 +02:00 |
|
Chris Smowton
|
7eefa43f5a
|
Rename and document viableArgParamSpecific to make clear it is a temporary hook.
|
2023-04-12 14:33:46 +01:00 |
|
Asger F
|
7e23bf3938
|
Ruby: remove some redundant getASubclass() calls
|
2023-04-12 15:32:01 +02:00 |
|
Chris Smowton
|
4d8ca3d759
|
Add dataflow callback to filter out receiver argument flow to Golang interface dispatch candidates.
Other langauges stub the callback.
|
2023-04-12 14:19:06 +01:00 |
|
github-actions[bot]
|
ac426b1302
|
Post-release preparation for codeql-cli-2.12.6
|
2023-04-04 16:49:26 +00:00 |
|
Asger F
|
7c9100c782
|
Merge pull request #12730 from asgerf/rb/net-http
Ruby: Minor fix in NetHttpRequest
|
2023-04-04 09:44:11 +02:00 |
|
Asger F
|
c699afd07f
|
Ruby: instantiate NetHttpRequest even if body is not accessed
|
2023-03-31 12:56:09 +02:00 |
|
Asger F
|
008ffea94f
|
Merge pull request #12703 from asgerf/rb/api-graphs-trackdef
Ruby: do not depend on trackDefNode in isDef
|
2023-03-31 10:30:18 +02:00 |
|
github-actions[bot]
|
0a3218676c
|
Release preparation for version 2.12.6
|
2023-03-30 19:25:06 +00:00 |
|
github-actions[bot]
|
e87ce62f95
|
Post-release preparation for codeql-cli-2.12.5
|
2023-03-30 13:48:58 +00:00 |
|
Jeroen Ketema
|
0acca2ba76
|
Merge pull request #12687 from jketema/unit-2
Make imports of `codeql.util.Unit` private
|
2023-03-29 13:07:12 +02:00 |
|
Asger F
|
f8e76b5347
|
Ruby: do not depend on trackDefNode in isDef
|
2023-03-29 10:31:42 +02:00 |
|
Anders Schack-Mulligen
|
7c74fd07e9
|
Merge pull request #12684 from aschackmull/dataflow/remove-footgun
Dataflow: Remove accidentally exposed predicates.
|
2023-03-28 15:14:58 +02:00 |
|
Jeroen Ketema
|
3b8ad087eb
|
Make imports of codeql.util.Unit private
|
2023-03-28 14:14:13 +02:00 |
|
Anders Schack-Mulligen
|
47e7aa9566
|
Dataflow: Add change note.
|
2023-03-28 13:17:48 +02:00 |
|
Anders Schack-Mulligen
|
d406b051fc
|
Dataflow: Remove accidentally exposed predicates.
|
2023-03-28 10:04:21 +02:00 |
|
Asger F
|
32bab0b8b2
|
Merge pull request #12654 from asgerf/rb/always-resolve-toplevel-namespace
RB: always resolve toplevel namespaces to their locally qualified name
|
2023-03-28 09:54:59 +02:00 |
|
Tom Hvitved
|
f8c28bee6a
|
Ruby: Order synthetic children in PrintAST based on their index instead of location
|
2023-03-27 11:38:30 +02:00 |
|
Arthur Baars
|
4964f86df5
|
Merge pull request #12540 from aibaars/destructured-assign
Ruby: change evaluation order of destructured assignments
|
2023-03-27 11:30:44 +02:00 |
|
Jeroen Ketema
|
977f15f8a4
|
Merge pull request #12649 from jketema/unit
Replace all definitions of `Unit` by `import codeql.util.Unit`
|
2023-03-27 08:49:50 +02:00 |
|
Arthur Baars
|
3b12ddfdc2
|
Address comments
|
2023-03-24 16:58:53 +01:00 |
|
Arthur Baars
|
052bc95639
|
Ruby: add change note
|
2023-03-24 16:58:53 +01:00 |
|
Arthur Baars
|
9a8e138684
|
Ruby: also change evaluation order for scoped constants
|
2023-03-24 16:57:55 +01:00 |
|
Arthur Baars
|
8b90d021fa
|
Ruby: change evaluation order of destructured assignments
|
2023-03-24 16:57:25 +01:00 |
|
Anders Schack-Mulligen
|
6db8c8b19f
|
Merge pull request #12656 from aschackmull/dataflow/qldoc
Dataflow: Minor qldoc fix
|
2023-03-24 14:57:39 +01:00 |
|
Asger F
|
179d0b36cf
|
Ruby: make up qnames for top-level namespaces
|
2023-03-24 13:42:51 +01:00 |
|
Anders Schack-Mulligen
|
85511ba19d
|
Dataflow: Sync
|
2023-03-24 12:42:06 +01:00 |
|
Tom Hvitved
|
a5b7a0fe16
|
Merge pull request #12566 from hvitved/ruby/dataflow-assignments-in-paths
|
2023-03-24 12:31:59 +01:00 |
|
Jeroen Ketema
|
a87a9438c7
|
Replace all definitions of Unit by import codeql.util.Unit
|
2023-03-24 10:39:34 +01:00 |
|
Tom Hvitved
|
b816c79248
|
Ruby: Include all assignments in data flow paths
|
2023-03-24 10:09:30 +01:00 |
|
Anders Schack-Mulligen
|
9d88f01c82
|
Merge pull request #12645 from aschackmull/dataflow/renaming
Dataflow: Rename Make to Global and hasFlow to flow
|
2023-03-24 08:48:31 +01:00 |
|
Asger F
|
a59a404752
|
Ruby: redundant check is implied by isToplevel()
|
2023-03-23 14:28:09 +01:00 |
|
Anders Schack-Mulligen
|
d440bc2d0c
|
Dataflow: Sync.
|
2023-03-23 13:40:23 +01:00 |
|
Anders Schack-Mulligen
|
1c1aa7ecdd
|
Dataflow: Add change notes.
|
2023-03-23 13:17:36 +01:00 |
|
Anders Schack-Mulligen
|
d0b7ffda70
|
Python/Ruby/Swift: Rename references.
|
2023-03-23 13:06:19 +01:00 |
|
Anders Schack-Mulligen
|
2761aa73ca
|
Dataflow: Sync.
|
2023-03-23 13:06:19 +01:00 |
|
Kasper Svendsen
|
ce6be1f636
|
Dataflow: Instantiate stage 1 access paths with proper unit type
|
2023-03-23 08:32:16 +01:00 |
|
Anders Schack-Mulligen
|
b2d436ccc1
|
Merge pull request #12533 from aschackmull/java/misc-perf
Java/dataflow: Misc performance fixes
|
2023-03-22 08:39:43 +01:00 |
|
Anders Schack-Mulligen
|
0d6dd7d25a
|
DataFlow: Sync.
|
2023-03-21 14:27:25 +01:00 |
|
Tom Hvitved
|
5260d9815a
|
Merge pull request #12582 from hvitved/ruby/element-of-type-content-set
Ruby: Introduce `ContentSet::isElementOfType[OrUnknown]/1`
|
2023-03-21 13:41:15 +01:00 |
|
Asger F
|
6d665da4dc
|
Merge pull request #12570 from github/post-release-prep/codeql-cli-2.12.5
Post-release preparation for codeql-cli-2.12.5
|
2023-03-21 13:06:25 +01:00 |
|
Anders Schack-Mulligen
|
3876e4335f
|
Merge pull request #12420 from kaspersv/kaspersv/dataflow-remove-alias-preds
Dataflow: Remove revFlowAlias and revFlowApAlias predicates
|
2023-03-20 16:30:15 +01:00 |
|
Alex Ford
|
be163cfc38
|
Merge pull request #12311 from maikypedia/maikypedia/ruby-ssti
Ruby: Add Server Side Template Injection query
|
2023-03-20 15:26:27 +00:00 |
|
Kasper Svendsen
|
1d2f1b6ae6
|
Address comments
|
2023-03-20 13:34:14 +01:00 |
|
Kasper Svendsen
|
e0e3a1d621
|
Dataflow: remove revFlowApAlias trick
|
2023-03-20 13:04:13 +01:00 |
|
Alex Ford
|
4b1171ce64
|
Merge branch 'main' into maikypedia/ruby-ssti
|
2023-03-20 09:55:53 +00:00 |
|