Esben Sparre Andreasen
|
6b8fd49fba
|
JS: add change notes for two new queries
|
2018-10-10 12:17:46 +02:00 |
|
Max Schaefer
|
8d8148d58e
|
Merge pull request #294 from asger-semmle/canonical-this-source
JS: Canonicalize 'this' in the data-flow graph
|
2018-10-10 08:10:53 +01:00 |
|
yh-semmle
|
fa3b9a6997
|
Java: add change note for java/unreachable-catch-clause
|
2018-10-09 21:31:19 -04:00 |
|
Jonas Jensen
|
4b59c0cb80
|
Merge branch 'master' into hresult-boolean-qhelp
|
2018-10-09 14:56:58 +02:00 |
|
Asger F
|
9fb73f41c9
|
JS: rename ReactComponent::getAThisAccess -> getAThisNode
|
2018-10-09 08:54:44 +01:00 |
|
Asger F
|
e551ff3818
|
JS: add change note
|
2018-10-09 08:54:14 +01:00 |
|
Jonas Jensen
|
0e25649a5b
|
Merge pull request #289 from geoffw0/change-notes
CPP: Additional change notes.
|
2018-10-09 09:53:44 +02:00 |
|
Geoffrey White
|
03fd1ce83d
|
CPP: Remove external/microsoft tag.
|
2018-10-08 15:30:43 +01:00 |
|
Asger F
|
d2af4ab94a
|
Merge pull request #227 from xiemaisi/js/taint-kinds
JavaScript: Add support for state-based taint tracking.
|
2018-10-08 15:09:12 +01:00 |
|
Geoffrey White
|
4fb6611dbe
|
CPP: Change note for #264.
|
2018-10-08 12:19:45 +01:00 |
|
Geoffrey White
|
f706d2a96c
|
CPP: Change notes.
|
2018-10-08 12:19:45 +01:00 |
|
Geoffrey White
|
998b28b359
|
CPP: Change note.
|
2018-10-05 16:52:06 +01:00 |
|
Nick Rolfe
|
ae9b492b33
|
Merge pull request #277 from jbj/missing-return-high
C++: Make cpp/missing-return visible on LGTM again
|
2018-10-04 09:45:34 +01:00 |
|
semmle-qlci
|
bea86e52fb
|
Merge pull request #275 from xiemaisi/js/workaround-for-nested-imports
Approved by asger-semmle
|
2018-10-04 08:25:52 +01:00 |
|
Max Schaefer
|
335adee69c
|
JavaScript: Add change note.
|
2018-10-03 16:03:12 +01:00 |
|
Jonas Jensen
|
9c0ba51873
|
C++: Make cpp/missing-return visible on LGTM again
|
2018-10-03 15:02:15 +02:00 |
|
Max Schaefer
|
220fcb59bd
|
JavaScript: Add change note.
|
2018-10-03 13:08:31 +01:00 |
|
semmle-qlci
|
e9adc63d91
|
Merge pull request #260 from xiemaisi/js/confusing-precedence
Approved by esben-semmle, mc-semmle
|
2018-10-03 09:07:18 +01:00 |
|
Jonas Jensen
|
4ad4b19911
|
Merge pull request #189 from geoffw0/wrongtypedef
CPP: Permit more typedefs in WrongTypeFormatArguments.ql
|
2018-10-03 09:40:06 +02:00 |
|
Robert Marsh
|
7c2bcf6fa6
|
C++/Doc: change note for PR #269
|
2018-10-02 14:25:08 -07:00 |
|
Max Schaefer
|
425d2bfba7
|
Merge pull request #266 from esben-semmle/js/improve-dead-store-of-local
JS: support noop parentheses in js/useless-assignment-to-local
|
2018-10-02 16:19:56 +01:00 |
|
Max Schaefer
|
768368498f
|
JavaScript: Introduce new query UnclearOperatorPrecedence.
|
2018-10-02 08:46:51 +01:00 |
|
Max Schaefer
|
a63b7fc215
|
JavaScript: Introduce new library predicate for computing whitespace around binary operators.
|
2018-10-02 08:46:11 +01:00 |
|
semmle-qlci
|
829a5cc451
|
Merge pull request #259 from asger-semmle/open-redirect-expr
Approved by xiemaisi
|
2018-10-02 08:32:48 +01:00 |
|
Esben Sparre Andreasen
|
595fe217dd
|
JS: support noop parentheses in js/useless-assignment-to-local
The syntatic recognizer `isNullOrUndef` did not handle expressions
that were wrapped in parentheses.
This eliminates some results here:
https://lgtm.com/projects/g/vuejs/vue/alerts?mode=tree&ruleFocus=7900088
|
2018-10-02 09:31:32 +02:00 |
|
Jonas Jensen
|
54cd173da8
|
C++: Changelog entries for two new queries
|
2018-10-01 13:41:44 +02:00 |
|
Asger F
|
9f07b1011d
|
JS: bugfix in server-side redirect query
|
2018-10-01 12:34:13 +01:00 |
|
Asger F
|
8d3ac39b65
|
JS: change note
|
2018-09-27 10:21:57 +01:00 |
|
semmle-qlci
|
a93939b827
|
Merge pull request #230 from esben-semmle/js/ad-hoc-whitelisting
Approved by xiemaisi
|
2018-09-26 14:14:25 +01:00 |
|
Esben Sparre Andreasen
|
7c006d4530
|
Merge pull request #222 from xiemaisi/js/identity-replacement
JavaScript: Add new query flagging identity replacements.
|
2018-09-26 09:25:19 +02:00 |
|
Esben Sparre Andreasen
|
097a2811e1
|
JS: change notes for AdHocWhitelistCheckSanitizer
|
2018-09-26 09:20:40 +02:00 |
|
Max Schaefer
|
1ab11109f9
|
JavaScript: Add new query flagging identity replacements.
|
2018-09-25 11:27:11 +01:00 |
|
Geoffrey White
|
d975c09012
|
CPP: Change note.
|
2018-09-24 17:25:34 +01:00 |
|
semmle-qlci
|
7f56be6fe2
|
Merge pull request #216 from asger-semmle/lusca-csrf
Approved by esben-semmle
|
2018-09-24 11:34:24 +01:00 |
|
Dave Bartolomeo
|
26abf5d4a2
|
Force LF for basically everything.
|
2018-09-23 16:24:31 -07:00 |
|
Geoffrey White
|
492d79ea53
|
CPP: Change note.
|
2018-09-21 21:13:37 +01:00 |
|
Asger F
|
4797924bea
|
JS: review comments
|
2018-09-21 14:46:21 +01:00 |
|
Asger F
|
d2a04d32be
|
JS: add change note
|
2018-09-21 13:20:02 +01:00 |
|
Esben Sparre Andreasen
|
2cedc81774
|
JS: polish js/enabling-electron-renderer-node-integration meta info
|
2018-09-19 13:45:42 +02:00 |
|
semmle-qlci
|
89f2dbf8db
|
Merge pull request #195 from esben-semmle/js/reflected-xss-through-filenames
Approved by asger-semmle
|
2018-09-19 12:42:22 +01:00 |
|
Jonas Jensen
|
86fe0ce42e
|
Merge pull request #107 from rdmarsh2/rdmarsh/cpp/HashCons
C++: HashCons library
|
2018-09-18 11:45:26 +02:00 |
|
Esben Sparre Andreasen
|
bb48421d77
|
JS: address doc review comments
|
2018-09-17 11:08:35 +02:00 |
|
Esben Sparre Andreasen
|
5781b518bc
|
JS: change notes for js/stored-xss
|
2018-09-14 15:30:44 +02:00 |
|
Asger F
|
a3562aa4a7
|
Merge pull request #193 from esben-semmle/js/reduce-precision-of-remote-property-injection
JS: lower @precision of js/remote-property-injection
|
2018-09-14 11:14:13 +01:00 |
|
semmle-qlci
|
abbadf24f0
|
Merge pull request #192 from esben-semmle/js/additional-array-taint-steps
Approved by asger-semmle
|
2018-09-14 10:02:36 +01:00 |
|
Esben Sparre Andreasen
|
81aeda69e1
|
JS: lower @precision of js/remote-property-injection
|
2018-09-14 07:37:47 +02:00 |
|
Esben Sparre Andreasen
|
cb2bd9e0ae
|
JS: change notes for additional array taint steps
|
2018-09-13 21:36:53 +02:00 |
|
Robert Marsh
|
1a14b13703
|
C++: migrate change note
|
2018-09-13 09:53:41 -07:00 |
|
Esben Sparre Andreasen
|
52013f3071
|
JS: change notes for improved js/unbound-event-handler-receiver
|
2018-09-13 08:43:01 +02:00 |
|
Esben Sparre Andreasen
|
b9d825b379
|
JS: better matching of String.prototype.search in js/regex-injection
|
2018-09-05 08:35:00 +02:00 |
|