Anders Schack-Mulligen
|
8485b6f0b3
|
Merge pull request #6691 from bmuskalla/moreStringMethods
Java: Support String#getChars and #translateEscapes
|
2021-09-15 10:14:54 +02:00 |
|
Anders Schack-Mulligen
|
e71173d953
|
Merge pull request #6591 from bmuskalla/inlineFlowTest
Java: Simplify setup for flow tests using `InlineExpectationsTest`
|
2021-09-14 10:31:29 +02:00 |
|
Benjamin Muskalla
|
199e015a06
|
Support missing String methods
|
2021-09-14 10:22:22 +02:00 |
|
Benjamin Muskalla
|
24d740b2da
|
Merge branch 'main' into inlineFlowTest
|
2021-09-13 17:15:37 +02:00 |
|
Benjamin Muskalla
|
bf5a46f6d8
|
Simplify inline tests
|
2021-09-13 17:08:02 +02:00 |
|
Anders Schack-Mulligen
|
ab862276fc
|
Java: Fix tests.
|
2021-09-13 16:04:11 +02:00 |
|
Anders Schack-Mulligen
|
89a6cdc711
|
Java: Add support for callback-based library models.
|
2021-09-13 14:49:28 +02:00 |
|
Benjamin Muskalla
|
9d5e48430e
|
Merge branch 'main' into charSeqSubSeq
|
2021-09-09 16:04:36 +02:00 |
|
Benjamin Muskalla
|
3bc70f0ce6
|
Convert containerflow to inline flow test
|
2021-09-07 16:46:59 +02:00 |
|
Benjamin Muskalla
|
7a0fc6ae61
|
Migrate jaxson to inline test
|
2021-09-07 16:46:59 +02:00 |
|
Benjamin Muskalla
|
24d43689b2
|
Simplify test setup
|
2021-09-07 16:46:58 +02:00 |
|
Benjamin Muskalla
|
8830f1531f
|
Convert some tests to use InlineFlowTest
|
2021-09-07 16:46:58 +02:00 |
|
Benjamin Muskalla
|
acb055400d
|
Extract inline flow test
|
2021-09-07 16:46:57 +02:00 |
|
Benjamin Muskalla
|
d1a1f57e77
|
Convert taint-format test into inline test
|
2021-09-07 16:46:56 +02:00 |
|
Anders Schack-Mulligen
|
f6541811d2
|
Dataflow: Update more tests.
|
2021-09-07 13:02:20 +02:00 |
|
Benjamin Muskalla
|
7ddf7ff211
|
Track taint from concatenated string
|
2021-09-01 15:41:16 +02:00 |
|
Benjamin Muskalla
|
3928ffd30d
|
Support CharSequence#subSequence
|
2021-09-01 15:41:15 +02:00 |
|
Benjamin Muskalla
|
b7e608abc9
|
Model string builder APIs
|
2021-09-01 15:41:14 +02:00 |
|
Anders Schack-Mulligen
|
7fb1e1578e
|
Merge pull request #5894 from atorralba/atorralba/promote-ognl-injection
Java: Promote OGNL Injection query from experimental
|
2021-08-03 15:31:40 +02:00 |
|
Benjamin Muskalla
|
8ce841493c
|
Avoid taint for valueOf(Object)
|
2021-08-03 14:46:55 +02:00 |
|
Tony Torralba
|
a33e0bce9d
|
Fix tests affected by Jackson stubs changes
|
2021-08-03 13:15:45 +02:00 |
|
Tony Torralba
|
9b384d84cc
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 14:06:45 +02:00 |
|
Tony Torralba
|
351a24558d
|
Add tests for JacksonSerializability
Upgraded jackson stubs to 2.12
|
2021-08-02 14:03:30 +02:00 |
|
Benjamin Muskalla
|
b7b74b51a3
|
Track taint for String.valueOf(..)
|
2021-07-29 09:14:03 +02:00 |
|
Sauyon Lee
|
fd02dcdf2e
|
Java: Add models for collection constructors
|
2021-07-22 07:23:26 -07:00 |
|
Sauyon Lee
|
60db9e1851
|
Rename springframework-5.2.3 to 5.3.8
|
2021-06-28 08:26:39 -07:00 |
|
Anders Schack-Mulligen
|
95ad8b55fe
|
Merge pull request #6107 from aschackmull/dataflow/implicit-reads
Dataflow: Add support for implicit reads
|
2021-06-24 15:38:35 +02:00 |
|
Chris Smowton
|
74feaf2893
|
Adapt to static methods and nested types returning unbound declaring types
Previously these returned raw declaring types instead
|
2021-06-23 16:03:18 +01:00 |
|
Anders Schack-Mulligen
|
38fc8a750c
|
Java: Improve test and fix a few missing cases.
|
2021-06-22 11:16:02 +02:00 |
|
Anders Schack-Mulligen
|
c06e152e90
|
Java: Remove outdated test.
|
2021-06-21 16:08:59 +02:00 |
|
Owen Mansel-Chan
|
d1fe62d4d5
|
(Minor) Update comments to match ExternalFlow docs
|
2021-06-10 10:43:38 +01:00 |
|
Anders Schack-Mulligen
|
dbe352f3ff
|
Java: Remove deprecated tests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
901996f9fd
|
Java: Add collection flow test.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
43d1b0ab27
|
Java: Update qltests.
|
2021-06-01 11:47:52 +02:00 |
|
Sebastian Bauersfeld
|
28f597440f
|
Add method invocations of Spring's SavedRequest as a remote sources.
|
2021-05-20 20:00:14 +07:00 |
|
Jonathan Leitschuh
|
5a68ac88ef
|
Cleanup Jackson logic after code review
|
2021-05-11 10:48:22 -04:00 |
|
Jonathan Leitschuh
|
bacc3ef5b3
|
[Java] Jackson add support for 2 step deserialization taint flow
|
2021-05-11 10:36:47 -04:00 |
|
Jonathan Leitschuh
|
d0638db6e7
|
[Java] Add data flow through Iterator deserializers for Jackson
|
2021-05-11 10:36:47 -04:00 |
|
Jonathan Leitschuh
|
56b1f15dda
|
[Java] Add taint tracking through Jackson deserialization
|
2021-05-11 10:36:47 -04:00 |
|
yo-h
|
cb524b6c19
|
Merge pull request #5611 from github/yo-h/java16
Java: adjust test `options` for JDK 16 upgrade
|
2021-04-19 15:12:23 -04:00 |
|
Anders Schack-Mulligen
|
579c955892
|
Java: Adjust some tests.
|
2021-04-19 14:06:27 +02:00 |
|
Tom Hvitved
|
fd8f745468
|
Java: Adopt shared flow summary library and refactor data-flow nodes.
|
2021-04-09 16:57:03 +02:00 |
|
yo-h
|
cc63563a88
|
Merge remote-tracking branch 'upstream-public/main' into yo-h/java16
|
2021-04-06 13:16:02 -04:00 |
|
yo-h
|
0200aedc2e
|
Java 16: adjust test options
|
2021-03-21 12:55:25 -04:00 |
|
Anders Schack-Mulligen
|
d1f30d9164
|
Java: Autoformat.
|
2021-03-15 15:28:04 +01:00 |
|
Anders Schack-Mulligen
|
662e17ff85
|
Java: Bugfix dispatch to lambda in call context.
|
2021-03-15 15:09:03 +01:00 |
|
Chris Smowton
|
6cf15f49bb
|
Replace hasTaintFlow=y with hasTaintFlow everywhere
|
2021-03-08 11:57:35 +00:00 |
|
Marcono1234
|
b7353f0bb0
|
Java: Simplify tests using InlineExpectationsTest
|
2021-03-08 11:49:52 +00:00 |
|
Anders Schack-Mulligen
|
cf4f55d9ab
|
Merge pull request #5223 from smowton/smowton/feature/backward-dataflow-for-modelled-fluent-methods
Java: Add backward dataflow edges through modelled function invocations
|
2021-03-05 15:11:43 +01:00 |
|
Chris Smowton
|
012058a866
|
Apply review suggestions: use ArgumentNode.argumentOf, and change more uses of ValuePreservingCallable -> ValuePreservingMethod
|
2021-03-05 13:34:13 +00:00 |
|