Chris Smowton
|
9016997b51
|
Golang: fix flow from a map value via a range statement
|
2024-02-14 14:56:24 +00:00 |
|
Tony Torralba
|
16284fdd20
|
Discard sources that are obvious dummy values
|
2024-02-14 12:21:52 +01:00 |
|
Tony Torralba
|
a76de495e0
|
Simplify sanitizers
Use DataFlow::returnedWithError instead
|
2024-02-14 12:21:51 +01:00 |
|
Tony Torralba
|
3fb422ca25
|
Split Jwt.qll into framework libraries, which makes more sense
|
2024-02-14 12:21:38 +01:00 |
|
Tony Torralba
|
8afaa231ee
|
Update go/ql/lib/semmle/go/security/Jwt.qll
|
2024-02-14 12:15:20 +01:00 |
|
Tony Torralba
|
84d1d72497
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2024-02-14 12:15:19 +01:00 |
|
Tony Torralba
|
ba1faea630
|
Go: Promote go/hardcoded-key from experimental
|
2024-02-14 12:15:14 +01:00 |
|
Michael B. Gale
|
205847df64
|
Go: Add DummyFile class
|
2024-02-13 17:49:31 +00:00 |
|
Michael B. Gale
|
c6f4495ada
|
Go: Exclude dummy files from File
|
2024-02-13 17:46:41 +00:00 |
|
erik-krogh
|
8be7eadace
|
delete outdated deprecations
|
2024-01-22 09:11:35 +01:00 |
|
Tony Torralba
|
8d6aa281b9
|
Update go/ql/lib/semmle/go/frameworks/AwsLambda.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2024-01-19 10:48:34 +01:00 |
|
Tony Torralba
|
9a0fb39382
|
Model StartWithContext
Co-authored-by: Chris Smowton <smowton@github.com>
|
2024-01-19 09:25:35 +01:00 |
|
Tony Torralba
|
d3a9a5ec3f
|
Update go/ql/lib/semmle/go/frameworks/AwsLambda.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2024-01-19 09:22:46 +01:00 |
|
Tony Torralba
|
1d7dbec719
|
Go: Add flow sources for AWS Lambda function handlers
|
2024-01-18 15:17:21 +01:00 |
|
Owen Mansel-Chan
|
057ee85cd0
|
Merge pull request #14123 from am0o0/amammad-go-fastHttp
Go: fasthttp
|
2024-01-14 20:12:31 +00:00 |
|
Tony Torralba
|
12c5b46a0a
|
Reduce FPs
* Restrict allowed types in the flow step
* Discard more non-crypto-related TLS APIs
|
2024-01-11 16:20:46 +01:00 |
|
Tony Torralba
|
05b487e3a6
|
Go: Recognize unsafe candidate selection in go/insecure-randomness
|
2024-01-11 11:58:12 +01:00 |
|
Tony Torralba
|
5e8c63c3aa
|
Use arg position instead of arg as class field to reduce number of instances
|
2024-01-10 14:12:29 +01:00 |
|
Tony Torralba
|
78c0cdfa2c
|
Apply suggestions from code review
co-authored-by: Owen Mansel-Chan <owen-mc@github.com>
|
2024-01-10 13:33:41 +01:00 |
|
Tony Torralba
|
80526e509e
|
Go: Adds sources and sinks to go/clear-text-logging
|
2024-01-10 13:33:41 +01:00 |
|
Tony Torralba
|
ca0a1dc7ae
|
Merge pull request #15267 from atorralba/atorralba/go/fmt-appenderorsprinter-mad
Go: Migrate AppenderOrSprinter model to models-as-data
|
2024-01-10 13:31:19 +01:00 |
|
Tony Torralba
|
dc911c3f28
|
Apply suggestions from code review
co-authored-by: Owen Mansel-Chan <owen-mc@github.com>
|
2024-01-10 11:53:53 +01:00 |
|
Tony Torralba
|
da4049e25c
|
Go: Migrate AppenderOrSprinter model to models-as-data
|
2024-01-09 16:35:47 +01:00 |
|
Tom Hvitved
|
f90201eb56
|
Data flow: Remove column from mayBenefitFromCallContext
|
2024-01-09 11:34:43 +01:00 |
|
Owen Mansel-Chan
|
6f9242b1cb
|
Merge pull request #15162 from owen-mc/go/stratify-cfg-succ
Go: Stratify `CFG::succ` to avoid recursion
|
2024-01-04 14:11:25 +00:00 |
|
Owen Mansel-Chan
|
e2e91ebe1c
|
Fix capitalization in predicate name
This was introduced by a copy-paste error
|
2024-01-04 07:08:37 +00:00 |
|
Owen Mansel-Chan
|
dfd25f705d
|
Add pragma[nomagic] to top-level succ0 and remove cached
|
2024-01-04 07:06:55 +00:00 |
|
Owen Mansel-Chan
|
90f07d2116
|
Add pragma[nomagic] to member 'succ0'
|
2024-01-03 16:54:58 +00:00 |
|
Owen Mansel-Chan
|
14cffc3170
|
Merge pull request #15128 from owen-mc/go/fix-fp-incorrect-integer-conversion-signedness
Go: fix FP in incorrect integer conversion query relating to strict comparisons with MaxInt and MaxUint
|
2024-01-03 14:57:34 +00:00 |
|
Owen Mansel-Chan
|
bb44141390
|
Add QLDoc for succ0
|
2024-01-03 14:55:56 +00:00 |
|
Owen Mansel-Chan
|
032574f3d1
|
Make succ0 private
|
2024-01-03 14:55:42 +00:00 |
|
Owen Mansel-Chan
|
6ecf6ea3ac
|
Rename succSimple to succ0
|
2024-01-03 14:51:57 +00:00 |
|
Chad Bentz
|
730f6ed5b0
|
Merge branch 'main' into go-xxe-libxml2
|
2023-12-22 11:57:43 -05:00 |
|
Chad Bentz
|
4c46be1ed0
|
Use 3 arg overload on Method for hasQualifiedName for Package/Name/Type
|
2023-12-21 00:23:01 +00:00 |
|
Owen Mansel-Chan
|
9697d76c2d
|
Stratify CFG::succ to avoid recursion
The first level doesn't deal with defer statements properly.
The second level usees the first level to deal with them properly.
|
2023-12-19 21:33:13 +00:00 |
|
Owen Mansel-Chan
|
e45e92eaa7
|
Fix MaxIntOrMaxUint.isBoundFor
It was wrong for strictnessOffset = 1 before.
|
2023-12-17 06:16:33 +00:00 |
|
amammad
|
d84333dad8
|
added *ReadBody* Methods as UntrustedFlowSource
|
2023-12-14 15:31:09 +01:00 |
|
Anders Schack-Mulligen
|
a1068ce2f9
|
Dataflow: deprecate references
|
2023-12-14 15:05:33 +01:00 |
|
Tom Hvitved
|
c8b4a215bc
|
Merge pull request #14573 from hvitved/flow-summary-impl-param
Move `FlowSummaryImpl.qll` to `dataflow` pack
|
2023-12-14 12:24:15 +01:00 |
|
Tom Hvitved
|
098afb935b
|
Address more review comments
|
2023-12-14 09:48:45 +01:00 |
|
Owen Mansel-Chan
|
5675df842e
|
Merge pull request #15054 from owen-mc/go/find-more-callees-for-captured-variables
Go: Also follow jump steps when looking for a callee source
|
2023-12-12 15:49:15 +00:00 |
|
Chad Bentz
|
2d33f86d41
|
Initial Push
- Sample test (test not compiling)
- Stubs not generating
|
2023-12-12 15:00:00 +00:00 |
|
amammad
|
cc5416406f
|
added more sinks related to io.Writer of BodyWriter
|
2023-12-10 22:06:27 +01:00 |
|
amammad
|
b6aaff2e64
|
use SimpleGlobal with source and sink to find BodyWriter successors globally
|
2023-12-10 15:45:42 +01:00 |
|
Tom Hvitved
|
35c654aa76
|
Go: Use FlowSummaryImpl from dataflow pack
|
2023-12-10 11:25:44 +01:00 |
|
Owen Mansel-Chan
|
40b3598fd0
|
Also follow jump steps when looking for a callee source
This is needed because capturing a variable is a jump step
and we want to find a callee source for captured functions.
|
2023-12-08 18:44:14 +00:00 |
|
amammad
|
a3fbc3c20c
|
fix ResponseBody Class issues
|
2023-12-07 19:36:27 +01:00 |
|
amammad
|
dbf01a9284
|
fix an issue in ResponseBody, change isHTMLEscape to isHtmlEscape
|
2023-12-07 08:52:55 +01:00 |
|
amammad
|
20a3211d06
|
move sanitizers from sharedxss::sanitizer to EscapeFunction::Range, added proper inline tests
|
2023-12-06 16:19:34 +01:00 |
|
amammad
|
3e0ed0090f
|
added BodyWriter Sink, added proper content-type header in tests to comply new changed xss strategy
|
2023-12-06 16:00:36 +01:00 |
|