Nora Dimitrijević
|
bc0b383595
|
[DIFF-INFORMED] Java: MaybeBrokenCryptoAlgorithm
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-327/MaybeBrokenCryptoAlgorithm.ql#L25
|
2025-07-17 19:02:00 +02:00 |
|
Nora Dimitrijević
|
b688df9dec
|
[DIFF-INFORMED] Java: LogInjection
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-117/LogInjection.ql#L20
|
2025-07-17 19:01:58 +02:00 |
|
Nora Dimitrijević
|
2d734056b1
|
[DIFF-INFORMED] Java: InsecureLdapAuth
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-522/InsecureLdapAuth.ql#L21
|
2025-07-17 19:01:56 +02:00 |
|
Nora Dimitrijević
|
74b37e71a0
|
[DIFF-INFORMED] Java: InsecureCookie
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-614/InsecureCookie.ql#L21
|
2025-07-17 19:01:52 +02:00 |
|
Nora Dimitrijević
|
19e5c3d805
|
[DIFF-INFORMED] Java: ImproperValidationOfArray…
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-129/ImproperValidationOfArrayIndexCodeSpecified.ql#L48
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-129/ImproperValidationOfArrayConstructionCodeSpecified.ql#L28
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-129/ImproperValidationOfArrayConstruction.ql#L26
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-129/ImproperValidationOfArrayIndex.ql#L24
|
2025-07-17 19:01:50 +02:00 |
|
Nora Dimitrijević
|
919fea53f0
|
[DIFF-INFORMED] Java: ExternallyControlledFormatString
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-134/ExternallyControlledFormatString.ql#L24
|
2025-07-17 19:01:34 +02:00 |
|
Nora Dimitrijević
|
1c6ecf1216
|
[DIFF-INFORMED] Java: UntrustedDataToExternalAPI
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-020/UntrustedDataToExternalAPI.ql#L20
|
2025-07-17 18:59:15 +02:00 |
|
Nora Dimitrijević
|
0cf1195678
|
[DIFF-INFORMED] Java: ConditionalBypass
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-807/ConditionalBypass.ql#L26
|
2025-07-17 18:59:14 +02:00 |
|
Nora Dimitrijević
|
0bcdb421ed
|
[DIFF-INFORMED] Java: ArithmeticUncontrolled
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-190/ArithmeticUncontrolled.ql#L36
|
2025-07-17 18:59:11 +02:00 |
|
Nora Dimitrijević
|
54546f6e99
|
[DIFF-INFORMED] Java: ArithmeticTainted
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-190/ArithmeticTainted.ql#L35
|
2025-07-17 18:59:09 +02:00 |
|
Nora Dimitrijević
|
8353fdd041
|
[DIFF-INFORMED] Java: (Android)SensitiveCommunication
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/java/ql/src/Security/CWE/CWE-927/SensitiveCommunication.ql#L20
|
2025-07-17 18:59:06 +02:00 |
|
Nora Dimitrijević
|
b33058c967
|
[TEST] Java: SensitiveCommunication: convert to qlref
|
2025-07-17 18:59:05 +02:00 |
|
Nora Dimitrijević
|
44bb5e7220
|
[TEST] Java: ConditionalBypass: convert to qlref
|
2025-07-17 18:59:03 +02:00 |
|
Nora Dimitrijević
|
6134518d60
|
[TEST] Java: SensitiveLogInfo: convert to qlref
|
2025-07-17 18:59:01 +02:00 |
|
Nora Dimitrijević
|
94386f0550
|
[TEST] Java: TrustBoundaryViolations: convert test to qlref
|
2025-07-17 18:58:59 +02:00 |
|
Nora Dimitrijević
|
49e03b4dfd
|
[TEST] Java: UnsafeCertTrust: convert test to qlref
|
2025-07-17 18:58:56 +02:00 |
|
Nora Dimitrijević
|
7aced48443
|
[TEST] Java: LogInjection: convert test to qlref
|
2025-07-17 18:58:54 +02:00 |
|
Nora Dimitrijević
|
5c2cf79785
|
[TEST] Java: CWE-020/ExternalAPI: new test based on qhelp
|
2025-07-17 18:58:52 +02:00 |
|
Geoffrey White
|
c2ddf25f11
|
Merge branch 'main' into constcrypto
|
2025-07-17 16:13:58 +01:00 |
|
Anders Schack-Mulligen
|
996de78a66
|
Java: Prune PathGraph for CsrfUnprotectedRequestType.ql
|
2025-07-17 15:06:38 +02:00 |
|
Anders Schack-Mulligen
|
1485d7072d
|
Merge pull request #19885 from aschackmull/java/annotated-exit-cfg
Java: Add AnnotatedExitNodes to the CFG.
|
2025-07-17 15:02:24 +02:00 |
|
Nora Dimitrijević
|
4342b2b799
|
[DIFF-INFORMED] Swift: UnsafeWebViewFetch
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/swift/ql/src/queries/Security/CWE-079/UnsafeWebViewFetch.ql#L24
|
2025-07-17 14:59:09 +02:00 |
|
Nora Dimitrijević
|
b1e723991e
|
[DIFF-INFORMED] Swift: InsecureTLS
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/swift/ql/src/queries/Security/CWE-757/InsecureTLS.ql#L18
|
2025-07-17 14:59:07 +02:00 |
|
Nora Dimitrijević
|
6dea73b081
|
[DIFF-INFORMED] Swift: CleartextStoragePreferences
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/swift/ql/src/queries/Security/CWE-312/CleartextStoragePreferences.ql#L32
|
2025-07-17 14:59:05 +02:00 |
|
Nora Dimitrijević
|
cd3fa64ee3
|
[DIFF-INFORMED] Swift: CleartextStorageDatabase
https://github.com/d10c/codeql/blob/d10c/diff-informed-phase-3/swift/ql/src/queries/Security/CWE-311/CleartextStorageDatabase.ql#L33
|
2025-07-17 14:59:03 +02:00 |
|
Michael Nebel
|
2f29459cda
|
Merge pull request #19931 from michaelnebel/ql4ql/qualitytagcheck
Ql4ql: Quality query tagging.
|
2025-07-17 14:53:14 +02:00 |
|
Idriss Riouak
|
36ebe99f2f
|
Merge pull request #19707 from microsoft/lwsimpkins/fix-qhelp-upstream
fix qhelp files
|
2025-07-17 14:51:01 +02:00 |
|
Owen Mansel-Chan
|
af977e9ac7
|
Merge pull request #20067 from owen-mc/java/unsafe-deserialization-mad-sinks
Java: allow the definition of `java/unsafe-deserialization` sinks using data extensions
|
2025-07-17 13:42:31 +01:00 |
|
Kasper Svendsen
|
a807db52ad
|
Merge pull request #19872 from github/kaspersv/overlay-java-enable
Overlay: Enable overlay compilation for Java
|
2025-07-17 14:38:17 +02:00 |
|
Jeroen Ketema
|
acc66c7b58
|
Merge pull request #19984 from jketema/jketema/sec-shared
Make a proper shared library out of the concept related libraries
|
2025-07-17 13:25:33 +02:00 |
|
Owen Mansel-Chan
|
6629bd8279
|
No need to deprecate classes when module is deprecated
|
2025-07-17 11:52:31 +01:00 |
|
Owen Mansel-Chan
|
b361f76643
|
Delete unused private class
|
2025-07-17 11:36:06 +01:00 |
|
Anders Schack-Mulligen
|
448cc82ef9
|
Kotlin: Accept more test changes.
|
2025-07-17 11:21:27 +02:00 |
|
Anders Schack-Mulligen
|
54775e0958
|
Java: Adjust Paths.qll
|
2025-07-17 11:21:26 +02:00 |
|
Anders Schack-Mulligen
|
e7a6259bd7
|
Java: Accept test changes.
|
2025-07-17 11:21:26 +02:00 |
|
Anders Schack-Mulligen
|
fbe79e8a52
|
Java: Add AnnotatedExitNodes to the CFG.
|
2025-07-17 11:21:26 +02:00 |
|
Joe Farebrother
|
680e31dc48
|
Modernize raise-not-implemented
|
2025-07-17 10:02:00 +01:00 |
|
Owen Mansel-Chan
|
53e1939b60
|
Merge pull request #20053 from owen-mc/go/fix-dataflowconsistency
Go: Fix compilation of DataFlowImplConsistency.qll
|
2025-07-17 09:22:12 +01:00 |
|
Michael Nebel
|
01738c2e42
|
Merge pull request #19940 from michaelnebel/csharp/fixmodels
C#: Improve some existing manual models.
|
2025-07-17 07:58:14 +02:00 |
|
Jeroen Ketema
|
eabe651edf
|
Merge pull request #20069 from jketema/spaceship-ir
C++: Support the spaceship operator in the IR
|
2025-07-16 21:45:39 +02:00 |
|
Jeroen Ketema
|
29a6af4efd
|
C++: Fix instruction class name
|
2025-07-16 18:11:17 +02:00 |
|
Jeroen Ketema
|
f319381f27
|
C++: Support the spaceship operator in the IR
|
2025-07-16 17:53:55 +02:00 |
|
Jeroen Ketema
|
9b8302f983
|
Merge pull request #20068 from jketema/spaceship-test
C++: Add test that shows that IR generation for `<=>` is broken
|
2025-07-16 16:50:25 +02:00 |
|
Owen Mansel-Chan
|
805e31fdb9
|
Update test expectations
|
2025-07-16 15:25:45 +01:00 |
|
Jeroen Ketema
|
807ab986f4
|
C++: Update more exoected test results
|
2025-07-16 16:19:40 +02:00 |
|
Mathias Vorreiter Pedersen
|
a9fb49a2c3
|
Merge pull request #20066 from MathiasVP/dont-summarize-function-pointer-calls
C++: Don't wrap calls through function pointers in `FunctionWithWrappers`
|
2025-07-16 14:57:14 +01:00 |
|
Jeroen Ketema
|
2709bf0615
|
C++: Add test that shows that IR generation for <=> is broken
|
2025-07-16 15:54:18 +02:00 |
|
Owen Mansel-Chan
|
7d4a70cc1d
|
Add change notes
|
2025-07-16 14:44:24 +01:00 |
|
Owen Mansel-Chan
|
ad60aff860
|
Update which sink kinds are shared between languages
|
2025-07-16 14:42:12 +01:00 |
|
Owen Mansel-Chan
|
fdd1e3fefe
|
Use MaD models for unsafe deserialization sinks when possible
Many of the unsafe deserialization sinks have to stay defined in QL
because they have custom logic that cannot be expressed in MaD models.
|
2025-07-16 14:42:07 +01:00 |
|