Rasmus Lerchedahl Petersen
|
144df9a39e
|
python: remove explicit dataflow steps
|
2023-05-26 13:24:22 +02:00 |
|
Rasmus Lerchedahl Petersen
|
8d4f9447b1
|
python: remove explicit steps
copy, pop, get, popitem
|
2023-05-26 13:22:54 +02:00 |
|
Michael Nebel
|
915042a881
|
Minor cleanup and sync files.
|
2023-05-26 12:25:00 +02:00 |
|
Michael Nebel
|
811eee1f0d
|
Python: Re-factor getComponent.
|
2023-05-26 12:24:59 +02:00 |
|
Asger F
|
75fd20b3b8
|
Python: add meta-query for calls to summarized callables
|
2023-05-26 11:40:58 +02:00 |
|
erik-krogh
|
9f5bf8fb22
|
also fix the first code-block
|
2023-05-25 13:56:29 +02:00 |
|
erik-krogh
|
765076bcba
|
fix whitespace in the samples in ReDoS.qhelp
|
2023-05-25 13:28:39 +02:00 |
|
github-actions[bot]
|
d2e192020b
|
Post-release preparation for codeql-cli-2.13.3
|
2023-05-24 11:26:12 +00:00 |
|
Tom Hvitved
|
1788c54bd8
|
Python: Avoid calling TypeTracker::step in call graph construction
|
2023-05-24 11:11:54 +02:00 |
|
Tom Hvitved
|
deee314370
|
Python/Ruby: Optimize join-order in TypeTracker::[small]step
|
2023-05-24 11:11:07 +02:00 |
|
Arthur Baars
|
e33f3a6668
|
Merge pull request #13154 from aibaars/sync-dbscheme-py
JS/Ruby/QL/Python: sync dbscheme fragments
|
2023-05-23 19:14:29 +02:00 |
|
Rasmus Wriedt Larsen
|
5c77edecf7
|
Merge pull request #12991 from Sim4n6/python-UBV
[Python] Add Unicode Bypass Validation query tests and help
|
2023-05-23 12:21:55 +02:00 |
|
github-actions[bot]
|
7aa23cf11d
|
Release preparation for version 2.13.3
|
2023-05-22 20:47:00 +00:00 |
|
Arthur Baars
|
5e279f2898
|
Python: add upgrade/downgrade scripts
|
2023-05-22 19:37:58 +02:00 |
|
Arthur Baars
|
ef3005ea9e
|
Python: sync shared dbscheme fragments
|
2023-05-22 19:37:58 +02:00 |
|
Rasmus Wriedt Larsen
|
c1b90c8f05
|
Python: Apply suggested change
|
2023-05-22 11:58:32 +02:00 |
|
Rasmus Wriedt Larsen
|
a057365b7e
|
Python: Accept .expected changes
|
2023-05-22 11:54:50 +02:00 |
|
Rasmus Wriedt Larsen
|
44d806507d
|
Merge branch 'main' into python-UBV
|
2023-05-22 11:53:56 +02:00 |
|
erik-krogh
|
710b309142
|
apply suggestions from doc review
|
2023-05-21 22:18:48 +02:00 |
|
erik-krogh
|
10bf17c33e
|
Merge branch 'main' into polyQhelp
|
2023-05-21 22:17:06 +02:00 |
|
Sim4n6
|
be3f59afab
|
Replaced StringMethod() with a restrained String method calls
|
2023-05-20 12:17:33 +01:00 |
|
Sim4n6
|
d939f192d5
|
Deleted the UBV query change note.
|
2023-05-20 11:46:18 +01:00 |
|
Sim4n6
|
21e99d52c7
|
Fix a redundant import
|
2023-05-20 10:23:04 +01:00 |
|
Sim4n6
|
b8969707c5
|
Delete the vulnerability flow image from the QHelp file.
|
2023-05-20 10:21:38 +01:00 |
|
Sim4n6
|
16ce024429
|
Update python/ql/src/experimental/Security/CWE-176/UnicodeBypassValidation.qhelp
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-05-20 10:13:23 +01:00 |
|
Sim4n6
|
8462b14b54
|
Update python/ql/src/experimental/Security/CWE-176/UnicodeBypassValidation.qhelp
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-05-20 10:12:55 +01:00 |
|
Sim4n6
|
2a8645c447
|
Fix 'Singleton set literal' warning
|
2023-05-20 10:11:26 +01:00 |
|
Sim4n6
|
58be109a70
|
Moved UnicodeBypassValidation Customizations & Query.qll to src/experimental
|
2023-05-20 10:08:56 +01:00 |
|
erik-krogh
|
480e71fd69
|
avoid contractions
|
2023-05-17 08:42:45 +02:00 |
|
Rasmus Lerchedahl Petersen
|
5d68473d12
|
python: elide nodes without location from basic
|
2023-05-16 14:38:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
5b4f98d6c4
|
python: Add summaries for container constructors
Also:
- turn on flow summaries for taint
- do not restrict node type
(as now we need summary nodes)
|
2023-05-16 14:38:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
145eaf3947
|
python: remove steps for container constructors
|
2023-05-16 10:35:10 +02:00 |
|
erik-krogh
|
83ca1495e0
|
trim the whitespace in the poly-redos examples
|
2023-05-15 16:47:24 +02:00 |
|
erik-krogh
|
d989359656
|
add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-15 16:47:02 +02:00 |
|
Tom Hvitved
|
9dede31c0d
|
Merge pull request #13077 from hvitved/ruby/track-regexp-improvements
Ruby: Improvements to `RegExpTracking`
|
2023-05-15 16:02:00 +02:00 |
|
Rasmus Lerchedahl Petersen
|
81adf5aad4
|
python: remember to adjust annotation
|
2023-05-12 14:28:41 +02:00 |
|
Rasmus Lerchedahl Petersen
|
1b848bb510
|
python: fix tests
|
2023-05-12 13:51:50 +02:00 |
|
yoff
|
3adaa21571
|
Merge branch 'main' into python/test-container-steps
|
2023-05-12 13:19:53 +02:00 |
|
yoff
|
72c6919f4e
|
Merge pull request #13095 from yoff/python/interpret-summary-content
Python: Interpret summary content
|
2023-05-12 13:09:14 +02:00 |
|
yoff
|
6a5fc3c1b1
|
Update python/ql/test/experimental/dataflow/tainttracking/defaultAdditionalTaintStep/test_collections.py
|
2023-05-12 13:06:08 +02:00 |
|
yoff
|
62b60f490c
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-05-12 12:54:17 +02:00 |
|
Rasmus Wriedt Larsen
|
62f0c64a03
|
Merge pull request #12552 from erik-krogh/py-type-trackers
Py: refactor regex tracking to type-trackers
|
2023-05-11 16:18:34 +02:00 |
|
Rasmus Lerchedahl Petersen
|
0a9515dbcd
|
python: add tests for built-in collections
- constructors: list, tuple, set, dict
- methods:
- general: copy, pop
- list: append
- set: add
- dict: keys, values, items, get, popitem
- functions: sorted, reversed, iter, next
|
2023-05-10 18:10:05 +02:00 |
|
yoff
|
9bd3957bc8
|
Merge branch 'main' into python/interpret-summary-content
|
2023-05-10 11:41:50 +02:00 |
|
yoff
|
9cc7cdef4c
|
Merge branch 'main' into python/update-taint-debug
|
2023-05-10 10:26:19 +02:00 |
|
Tom Hvitved
|
211a1e188c
|
Sync files
|
2023-05-10 09:36:00 +02:00 |
|
yoff
|
25899c15c9
|
Merge pull request #13098 from hvitved/python/update-consistency-expected
Python: Update expected test output
|
2023-05-10 08:58:27 +02:00 |
|
Tom Hvitved
|
4d84f92e8c
|
Python: Update expected test output
|
2023-05-10 08:15:15 +02:00 |
|
Rasmus Lerchedahl Petersen
|
064877140e
|
Python: interpret remaining content
|
2023-05-09 21:40:01 +02:00 |
|
Rasmus Lerchedahl Petersen
|
c1110666b5
|
Python: remaining content-based summary components
|
2023-05-09 21:40:01 +02:00 |
|