Jonathan Leitschuh
|
9299c7996d
|
Add information disclosure test fix suggestions
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
0a621c2801
|
Fix the formatting in TempDirLocalInformationDisclosureFromMethodCall
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
79db76dcf8
|
Fix test failures TempDirLocalInformationDisclosureFromSystemProperty
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
d5c9af31b2
|
Fixup documentation/code from PR feedback
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
f7a4aac525
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a4b5573f53
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a8d25b63ac
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Chris Smowton
|
e795823d97
|
Autoformat TempDirUtils.qll
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
7e514e9ef9
|
Add QLdoc and fix Compiler Errors in Tests
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
cb30385684
|
Update java/ql/src/Security/CWE/CWE-200/TempDirUtils.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
df716cbaa0
|
Revert changes to MethodAccessSystemGetProperty
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
66831989b7
|
Add QLdoc to TempDirUtils
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7e55c92eb4
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
c19f52cd04
|
Add release notes for "Temporary Directory Local information disclosure"
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f6067d28f9
|
Fix file names and formatting from PR feedback
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
41b5011b81
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7929faedc0
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f910fd4719
|
Remove path flow tracking in 'TempDirLocalInformationDisclosureFromMethodCall'
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
e4c017e888
|
Apply suggestions from code review
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
13fed0e9b6
|
Temp Dir Info Disclosure: Final pass and add documentation
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
bc12e994b0
|
Add java.nio.file.Files API checks
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
ecad7534ae
|
Add mkdirs check
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
cf0ed81575
|
Add TempDir taint tracking for Files.write
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
3a15678b1e
|
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-04 17:10:23 -05:00 |
|
Erik Krogh Kristensen
|
ab2d3a7ca0
|
Merge pull request #7828 from Naman-ntc/main
JS: Adding model for `.get` function of `Map` in Unvalidated Dynamic Method Call
|
2022-02-04 20:19:02 +01:00 |
|
Erik Krogh Kristensen
|
f00d723c49
|
Merge pull request #7843 from erik-krogh/CVE-2021-23484
JS: add file sources from `jszip` to `js/zip-slip`
|
2022-02-04 20:17:43 +01:00 |
|
BACK Yonah
|
21fdc53d62
|
C/C++: Using UnspecifiedType instead of Type
|
2022-02-04 19:12:15 +01:00 |
|
Nick Rolfe
|
9744cf2457
|
Ruby: apply suggested simplification from review
|
2022-02-04 17:14:47 +00:00 |
|
Nick Rolfe
|
aaff3226c9
|
Ruby: prefer ...isInt(x) over x = ...getInt()
|
2022-02-04 17:10:22 +00:00 |
|
BACK Yonah
|
b2ca25abef
|
Merge branch 'main' of https://github.com/github/codeql
|
2022-02-04 18:09:19 +01:00 |
|
BACK Yonah
|
f4a1d1d5e6
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:05:03 +01:00 |
|
Nick Rolfe
|
45962f1cad
|
Ruby: make this unique for each method
Even when summaries are shared in a single class.
|
2022-02-04 17:03:55 +00:00 |
|
BACK Yonah
|
34320cb57b
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:03:29 +01:00 |
|
Ian Wright
|
6c3daf49f9
|
Merge pull request #7785 from github/z80coder/impose-length-restriction
Restrict AST nodes according to string length
|
2022-02-04 16:35:04 +00:00 |
|
Nick Rolfe
|
7a9ddc28bf
|
Ruby: address some more feedback on array flow summaries
|
2022-02-04 16:33:27 +00:00 |
|
Henry Mercer
|
bb1e89d261
|
Merge pull request #7848 from github/henrymercer/js-ml-powered-codeowners
JS: Add codeowners for ML-powered queries
|
2022-02-04 16:08:56 +00:00 |
|
Michael Nebel
|
6ee30843bb
|
C#: Add lambda attributes test cases.
|
2022-02-04 16:54:49 +01:00 |
|
Henry Mercer
|
22ef35e13a
|
JS: Add codeowners for ML-powered queries
Create a new reviewers team @github/codeql-ml-powered-queries-reviewers
for reviewing ML-powered queries and the associated CodeQL libraries.
|
2022-02-04 15:49:44 +00:00 |
|
Ian Wright
|
be5e8dae05
|
Update javascript/ql/experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling/FunctionBodyFeatures.qll
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-02-04 15:41:50 +00:00 |
|
Michael Nebel
|
7b3ba3cb96
|
C#: Modify database schema to allow lambda expression to be attributable and extract the lambda expression attributes.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
f412d49ba4
|
C#: Add some examples lambdas with different kind of attributes and update existing testcases.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
bb3f9cea3a
|
C#: Update test cases(s) expected output.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
7520948ec4
|
C#: Add test case for finding lambdas with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
83a5ef4961
|
C#: Examples of lambda expressions with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
25019dbaa0
|
C#: Add support QL library support for lambda explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
eb8c226749
|
C#: Add support for explicit return types in the extractor.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
ae62704d3a
|
C#: Add table for explicit return type in lambda expressions.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
ccb727e3ca
|
C#: Test cases that shows that lambdas can be naturally (implicitly) typed and that the type is indistinguishable from the equivalent explicitly typed declaration.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
a67033034a
|
C#: Example of naturally typed lambda.
|
2022-02-04 16:34:57 +01:00 |
|
Ian Wright
|
e57a0e0e2f
|
Update javascript/ql/experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling/FunctionBodyFeatures.qll
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-02-04 15:21:56 +00:00 |
|