intrigus
|
141f057f7b
|
Java: Remove duplicate code.
|
2021-02-25 21:29:26 +01:00 |
|
Tamás Vajk
|
505d04b13e
|
Merge pull request #5102 from luchua-bc/java/main-method-in-servlet
Java: CWE-489 Query to detect main() method in servlets
|
2021-02-25 16:05:06 +01:00 |
|
Anders Schack-Mulligen
|
f0d3841369
|
Merge pull request #5105 from JLLeitschuh/feat/JLL/depricated_bintray_usage
CWE-1104: Maven POM dependence upon Bintray/JCenter
|
2021-02-25 09:08:31 +01:00 |
|
luchua-bc
|
e34a203731
|
Refactor the check of a main method in a test program to improve maintainability
|
2021-02-24 17:15:08 +00:00 |
|
Anders Schack-Mulligen
|
add960bc4d
|
Merge pull request #4880 from luchua-bc/java/sensitive-query-with-get
Java: Sensitive GET Query
|
2021-02-24 11:08:47 +01:00 |
|
yo-h
|
1d654febfd
|
Merge pull request #5195 from aschackmull/java/cwe-548-test
Java: Add empty file to test.
|
2021-02-23 21:12:40 -05:00 |
|
luchua-bc
|
56e3b301e9
|
Resolve ambiguous method access
|
2021-02-23 15:18:07 +00:00 |
|
luchua-bc
|
45f9125bfa
|
Update test program
|
2021-02-23 14:41:44 +00:00 |
|
luchua-bc
|
9eb8ec7da5
|
Create a separate file for EJB check
|
2021-02-23 14:38:15 +00:00 |
|
Anders Schack-Mulligen
|
b1bed2731d
|
Merge pull request #5172 from smowton/smowton/feature/commons-strbuilder
Java: Add support for commons-lang's StrBuilder class
|
2021-02-23 14:39:11 +01:00 |
|
yo-h
|
6213c20bc3
|
Merge pull request #5136 from aschackmull/java/csv-models
Java: Add support for framework modelling through csv data.
|
2021-02-22 19:00:41 -05:00 |
|
Jonathan Leitschuh
|
ad99aa2d76
|
Fix typo in test output
|
2021-02-22 13:26:51 -05:00 |
|
luchua-bc
|
40df01d2cd
|
Update qldoc and method name
|
2021-02-22 14:15:41 +00:00 |
|
luchua-bc
|
dc799019d0
|
Add query for Struts and Spring actions
|
2021-02-20 03:36:21 +00:00 |
|
luchua-bc
|
3d9ac0d094
|
Add query for enterprise beans
|
2021-02-20 02:00:42 +00:00 |
|
Anders Schack-Mulligen
|
dae65f687a
|
Merge pull request #5150 from Marcono1234/marcono1234/conditional-expr-branch
Java: Add ConditionalExpr.getBranchExpr(boolean)
|
2021-02-19 10:12:43 +01:00 |
|
Chris Smowton
|
321df82851
|
Apply review feedback: comment style, bracketing, and use proper MISSING test annotations
|
2021-02-18 14:56:52 +00:00 |
|
Anders Schack-Mulligen
|
954e0b9496
|
Java: Add empty file to test.
|
2021-02-18 13:10:29 +01:00 |
|
Anders Schack-Mulligen
|
74d35f4f37
|
Java: Add support for value-preserving steps.
|
2021-02-18 11:26:15 +01:00 |
|
Anders Schack-Mulligen
|
04eeeda2c9
|
Java: Add documentation for the final column.
|
2021-02-18 11:23:49 +01:00 |
|
Anders Schack-Mulligen
|
6f583baa90
|
Java: More documentation and support for field writes.
|
2021-02-18 11:18:31 +01:00 |
|
luchua-bc
|
e916ce8b9b
|
Exclude test directories of typical build tools
|
2021-02-18 00:50:38 +00:00 |
|
luchua-bc
|
5e36eedcb6
|
Add check for test packages
|
2021-02-17 18:04:55 +00:00 |
|
Jonathan Leitschuh
|
c43765917f
|
Fix formatting of MavenPom.qll
|
2021-02-17 11:55:10 -05:00 |
|
Anders Schack-Mulligen
|
862c41632e
|
Java: Add empty file to test.
|
2021-02-17 13:23:18 +01:00 |
|
Chris Smowton
|
c700d004e0
|
Commons Lang/Text StrBuilder: propagate taint from constructors
|
2021-02-17 09:51:28 +00:00 |
|
Chris Smowton
|
c243e03133
|
Lang3 StrBuilder: fix typo and coding style
|
2021-02-17 09:50:56 +00:00 |
|
Chris Smowton
|
10112c50ab
|
Add support for StrBuilder and TextStringBuilder in commons-text
These are identical to the current deprecated StrBuilder in commons-lang3.
|
2021-02-17 09:36:28 +00:00 |
|
Chris Smowton
|
714611f803
|
Address review feedback
|
2021-02-17 09:36:21 +00:00 |
|
Chris Smowton
|
a63f18e49d
|
Add models for Commons-Lang's StrBuilder class. These exclude its fluent methods for the time being, which will be added in a forthcoming PR.
|
2021-02-17 09:36:20 +00:00 |
|
Jonathan Leitschuh
|
a8167c6c9c
|
Add docstring for DeclaredRepository.getUrl
|
2021-02-16 11:21:19 -05:00 |
|
Chris Smowton
|
a2eeffa9c0
|
Add support for Apache Commons Lang StringUtils
|
2021-02-16 14:48:39 +00:00 |
|
Chris Smowton
|
bf03c0f419
|
Port InlineExpectationsTest for the Java analysis
|
2021-02-16 14:48:39 +00:00 |
|
Anders Schack-Mulligen
|
6eafa9d396
|
Merge pull request #5133 from pwntester/fix_SnakeYaml
Remove sanitizing condition which does not prevent vulnerability.
|
2021-02-16 12:58:47 +01:00 |
|
luchua-bc
|
2f17943abc
|
Update qldoc
|
2021-02-15 16:58:09 +00:00 |
|
Jonathan Leitschuh
|
d82e8216ed
|
Merge branch 'main' into feat/JLL/depricated_bintray_usage
|
2021-02-15 10:48:28 -05:00 |
|
Jonathan Leitschuh
|
73fba3a3c0
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-02-15 10:01:03 -05:00 |
|
Anders Schack-Mulligen
|
b9a479dd31
|
Merge pull request #5134 from pwntester/ArrayUtils
Add support for Apache Commons Lang ArrayUtils
|
2021-02-15 13:50:01 +01:00 |
|
Alvaro Muñoz
|
00a0b12dad
|
update expected results
|
2021-02-15 11:23:40 +01:00 |
|
Alvaro Muñoz
|
812884341b
|
Merge branch 'ArrayUtils' of github.com:pwntester/codeql-1 into ArrayUtils
|
2021-02-15 10:59:49 +01:00 |
|
Alvaro Muñoz
|
504d119749
|
adjust max parameter number
|
2021-02-15 10:58:17 +01:00 |
|
Alvaro Muñoz
|
c7072aef16
|
update A.java test
|
2021-02-15 10:34:20 +01:00 |
|
Anders Schack-Mulligen
|
7e83a608a2
|
Merge pull request #4954 from aschackmull/java/member-hasqualifiedname
Java: Add Member.hasQualifiedName.
|
2021-02-15 10:02:13 +01:00 |
|
Anders Schack-Mulligen
|
161e756c4b
|
Merge pull request #5141 from github/yo-h/java-flow-check-fix
Java: prepare to enforce additional compiler checks in test code
|
2021-02-15 09:41:03 +01:00 |
|
yo-h
|
1d007b6e72
|
Java: delete two test cases as per code review
|
2021-02-14 21:42:58 -05:00 |
|
Marcono1234
|
7a6db061b5
|
Address review feedback
|
2021-02-12 20:15:10 +01:00 |
|
Chris Smowton
|
402f20c5e2
|
Merge pull request #5154 from smowton/smowton/admin/deprecate-old-maven-predicate-names
Java: Re-introduce deprecated versions of old Maven predicate names
|
2021-02-12 17:22:05 +00:00 |
|
Chris Smowton
|
80978c7c35
|
Merge pull request #5153 from smowton/smowton/admin/move-misplaced-experimental-query
Move misplaced experimental query into the conventional directory
|
2021-02-12 17:21:57 +00:00 |
|
Alvaro Muñoz
|
7d294361dc
|
Update java/ql/src/semmle/code/java/frameworks/apache/Lang.qll
Co-authored-by: Joe Farebrother <joefarebrother@github.com>
|
2021-02-12 15:40:44 +01:00 |
|
Alvaro Muñoz
|
6b80a42913
|
apply LSP formatter and add missing dot
|
2021-02-12 15:03:11 +01:00 |
|