ihsinme
|
e1c1f80f28
|
Rename cpp/ql/test/experimental/query-tests/Security/CWE/CWE-200/semmle/tests/ExposureSensitiveInformationUnauthorizedActor.qlref to cpp/ql/test/experimental/query-tests/Security/CWE/CWE-200/test1/ExposureSensitiveInformationUnauthorizedActor.qlref
|
2022-03-03 19:58:16 +03:00 |
|
ihsinme
|
b32be69e0a
|
Update DangerousUseOfTransformationAfterOperation.expected
|
2022-03-03 19:55:30 +03:00 |
|
Arthur Baars
|
b79d08523c
|
Merge pull request #8293 from aibaars/regex-pattern-source
Ruby: parse more string literals as regular expressions
|
2022-03-03 17:35:40 +01:00 |
|
Arthur Baars
|
22b0697371
|
Update ruby/ql/lib/codeql/ruby/security/performance/ParseRegExp.qll
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2022-03-03 17:13:19 +01:00 |
|
tombolton
|
bd9e845aea
|
update column names and remove encoding value
|
2022-03-03 15:59:10 +00:00 |
|
tombolton
|
f1f1526237
|
add query-sink mapping query
|
2022-03-03 15:20:06 +00:00 |
|
Mathias Vorreiter Pedersen
|
bf10456bf5
|
C++: Add a path explanation to the 'cpp/using-expired-stack-address' query.
|
2022-03-03 13:55:00 +00:00 |
|
Mathias Vorreiter Pedersen
|
9df923a7c8
|
C++: Catch more true positives by stepping into calls in the 'cpp/using-expired-stack-address' query.
|
2022-03-03 13:53:09 +00:00 |
|
Tom Hvitved
|
0c2551079a
|
C#: Add change note about recursive codeql test run extraction
|
2022-03-03 14:32:55 +01:00 |
|
Tom Hvitved
|
9d6d479fba
|
Add missing QL doc
|
2022-03-03 14:17:41 +01:00 |
|
Tom Hvitved
|
ba6ff88d05
|
Sync files
|
2022-03-03 12:30:50 +01:00 |
|
Tom Hvitved
|
b23ab8089a
|
Ruby: Clear call contexts after jump steps in type tracking
|
2022-03-03 12:29:47 +01:00 |
|
Jeroen Ketema
|
f80372b837
|
C++: Update the DB scheme stats file
|
2022-03-03 09:02:37 +01:00 |
|
Jeroen Ketema
|
3fc2f2f3dc
|
Merge pull request #8309 from jketema/taint-join-order
C++: Fix join order in the IR dataflow library
|
2022-03-03 09:00:42 +01:00 |
|
Jeroen Ketema
|
2fd950caad
|
C++: Fix join order in the IR dataflow library
Not having this fixed caused problems when updating the database
scheme stats file.
|
2022-03-03 07:42:52 +01:00 |
|
Harry Maclean
|
4a43731b83
|
Ruby: Use SimpleSummarizedCallable
This simplifies some String flow summaries.
|
2022-03-03 10:49:44 +13:00 |
|
Robert Marsh
|
9fb94d85b4
|
C++: performance tweaks for InsufficientKeySize
|
2022-03-02 15:59:42 -05:00 |
|
Arthur Baars
|
692fc4cb02
|
Update ruby/ql/lib/change-notes/2022-02-28-regex-string-literals.md
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2022-03-02 21:13:23 +01:00 |
|
Rasmus Lerchedahl Petersen
|
6946ae931a
|
python: missed a spot..
|
2022-03-02 17:12:48 +01:00 |
|
Michael Nebel
|
b39f383d45
|
Merge pull request #8230 from michaelnebel/csharp/autobuilder-buildless
C#: Buildless extractor option.
|
2022-03-02 15:53:02 +01:00 |
|
Michael Nebel
|
938902dc89
|
C#: Include example fragment in the release note on, how to invoke the extractor with the optional parameter.
|
2022-03-02 14:28:25 +01:00 |
|
Michael Nebel
|
fc89888c74
|
C#: Add pattern that only accepts 'true' and 'false' as the buildless option.
|
2022-03-02 14:28:21 +01:00 |
|
Michael Nebel
|
c5ddf6110f
|
C#: Address review comments (change description to use true/false instead of yes/no).
|
2022-03-02 14:27:45 +01:00 |
|
Michael Nebel
|
8d9999a8c4
|
C#: Change note describing the buildless extractor option.
|
2022-03-02 14:25:11 +01:00 |
|
Michael Nebel
|
3859b62554
|
C#: Autobuilder should use standalone in case buildless options is provided.
|
2022-03-02 14:25:11 +01:00 |
|
Michael Nebel
|
c973693bee
|
C#: Introduce buildless extractor option.
|
2022-03-02 14:25:06 +01:00 |
|
Michael Nebel
|
fff42501fc
|
Merge pull request #8167 from michaelnebel/csharp/extractor-option-compress
C# Extractor Option for specifying compression.
|
2022-03-02 14:22:52 +01:00 |
|
Michael Nebel
|
23fbfbc3b7
|
C#: Performance optimization of the GVN implementation.
|
2022-03-02 13:48:33 +01:00 |
|
Michael Nebel
|
a0a2cde6fa
|
C#: Update relase note to include example fragment on, how to invoke the extractor with the optional parameter.
|
2022-03-02 13:17:20 +01:00 |
|
Rasmus Lerchedahl Petersen
|
143e9ee954
|
Merge branch 'main' of github.com:github/codeql into python/promote-xpath-injection
|
2022-03-02 13:14:08 +01:00 |
|
Rasmus Lerchedahl Petersen
|
ee45e79948
|
python: Create XML modulein Concepts
to prepare for XXE and other XML related modelling
|
2022-03-02 13:10:23 +01:00 |
|
Rasmus Lerchedahl Petersen
|
80be767a7a
|
python: implement stdlib xpath support
|
2022-03-02 12:59:34 +01:00 |
|
Rasmus Lerchedahl Petersen
|
06e0f140c5
|
python: add tests for stdlib xpath
|
2022-03-02 12:58:37 +01:00 |
|
Mathias Vorreiter Pedersen
|
3681a1b736
|
Merge pull request #7933 from geoffw0/cwe497
C++: Improve cpp/system-data-exposure
|
2022-03-02 10:18:01 +00:00 |
|
Mathias Vorreiter Pedersen
|
71cd507f89
|
Merge pull request #8298 from MathiasVP/filter-bad-conversions-in-cpp-gvn
C++: Fix `GVN` performance on more invalid IR
|
2022-03-02 10:14:19 +00:00 |
|
Michael Nebel
|
53b2eac8c5
|
C#: Remove (symmetric) duplicates from the test output.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
38f04e5585
|
C#: Flatten the the Gvn type.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
6b4dea780f
|
C#: Introduce caching of the Gvn related types and the toGvn predicate.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
796a18043b
|
C#: Add testcase for GVN printing.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
7e25b141ca
|
C#: Add test cases for finding structurally equivalent control flow elements.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
52952e98bf
|
C#: Example source code with structurally same expressions and statements.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
4499551ca4
|
C#: Add a verbatim copy of the structural comparison for internal use only.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
16270cf57f
|
C#: Add configuration class to allow defining a candidate pairs of control flow predicates, where we want to look for structural equality.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
87cb92a434
|
C#: Add predicates for restricting the Gvn type and the relation between control flow elements and global value numbers.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
8bd12b23e2
|
C#: Add type(s) for representing global value numbers.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
cc5d56547c
|
C#: Add type Global value number kinds for control flow elements.
|
2022-03-02 09:44:51 +01:00 |
|
Michael Nebel
|
8179e247bf
|
C#: Delete the existing structural comparison implementation.
|
2022-03-02 09:44:51 +01:00 |
|
ihsinme
|
9e76260f1d
|
Update DangerousUseOfTransformationAfterOperation.ql
|
2022-03-02 10:38:57 +03:00 |
|
ihsinme
|
f5267ba8c6
|
Update DangerousUseOfTransformationAfterOperation.qhelp
|
2022-03-02 10:24:40 +03:00 |
|
Harry Maclean
|
37dac186a8
|
Ruby: String.try_convert isn't value-preserving
`String.try_convert` can convert arbitrary objects to strings, which
obviously isn't value-preserving.
|
2022-03-02 13:31:59 +13:00 |
|