Anders Schack-Mulligen
|
53e6ddfeb6
|
Merge pull request #6001 from atorralba/atorralba/promote-mvel-injection
Java: Promote MVEL injection query from experimental
|
2021-08-02 14:40:26 +02:00 |
|
Tony Torralba
|
9b384d84cc
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 14:06:45 +02:00 |
|
Anders Schack-Mulligen
|
3b676d432f
|
Merge pull request #5900 from artem-smotrakov/unsafe-jackson-deserialization
Java: Unsafe deserialization with Jackson
|
2021-08-02 12:45:30 +02:00 |
|
Artem Smotrakov
|
622c7ee957
|
Added a change note for new steps for ByteBuffer and InputStream
|
2021-08-01 09:47:05 +02:00 |
|
Joe Farebrother
|
227818adb4
|
Add change note
|
2021-07-29 16:41:33 +01:00 |
|
Tony Torralba
|
bdf0f582a4
|
QLDoc improvements from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-07-29 16:34:21 +02:00 |
|
Tony Torralba
|
3248f458a5
|
Update java/change-notes/2021-06-14-groovy-code-injection-query.md
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2021-07-28 10:45:03 +02:00 |
|
Sauyon Lee
|
fd02dcdf2e
|
Java: Add models for collection constructors
|
2021-07-22 07:23:26 -07:00 |
|
Tony Torralba
|
4622d8590b
|
Fix change note
|
2021-07-20 17:50:58 +02:00 |
|
Tony Torralba
|
99e66cffa2
|
Merge branch 'main' into atorralba/promote-unsafe-android-webview-fetch
|
2021-07-20 17:30:56 +02:00 |
|
Tony Torralba
|
ed0db7c7b4
|
Fix release note
|
2021-07-20 17:24:24 +02:00 |
|
Tony Torralba
|
7a898a04f3
|
Fix release note
|
2021-07-20 17:23:47 +02:00 |
|
Tony Torralba
|
b6904a7992
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-07-20 17:17:17 +02:00 |
|
Tony Torralba
|
430d9f1834
|
Merge branch 'main' into atorralba/promote-missing-jwt-signature-check
|
2021-07-20 16:20:35 +02:00 |
|
Tony Torralba
|
42b6b26c10
|
Decouple JndiInjection.qll to reuse the taint tracking configuration
|
2021-07-20 15:38:34 +02:00 |
|
Tony Torralba
|
b8ea833a61
|
Merge branch 'main' into atorralba/promote-jndi-injection
|
2021-07-20 15:01:26 +02:00 |
|
Chris Smowton
|
8051a7cd83
|
Add change note
|
2021-07-19 18:11:05 +01:00 |
|
Tony Torralba
|
5ca8b380e9
|
Merge branch 'main' into atorralba/promote-mvel-injection
|
2021-07-19 13:45:10 +02:00 |
|
Tony Torralba
|
b08f417a1e
|
Merge branch 'main' into atorralba/promote-groovy-injection
|
2021-07-19 12:44:03 +02:00 |
|
Anders Schack-Mulligen
|
d1f21a854a
|
Merge pull request #6042 from joefarebrother/spring-http
[Java] Model spring `http` package
|
2021-07-19 11:24:41 +02:00 |
|
Anders Schack-Mulligen
|
c32a75a1b3
|
Merge pull request #6183 from smowton/smowton/feature/javax-json-models
Add models of the jakarta/javax.json package
|
2021-07-19 11:19:21 +02:00 |
|
Chris Smowton
|
1bbac748fe
|
Add change note
|
2021-07-15 14:58:25 +01:00 |
|
Joe Farebrother
|
51045a83c2
|
Add change note
|
2021-07-15 10:33:33 +01:00 |
|
Chris Smowton
|
f2b232f276
|
Add change note
|
2021-07-14 17:39:58 +01:00 |
|
Sauyon Lee
|
671243c15d
|
Add change note
|
2021-07-14 05:05:17 -07:00 |
|
Sauyon Lee
|
b807757863
|
Model Spring web.multipart
|
2021-07-13 10:29:01 -07:00 |
|
Artem Smotrakov
|
e9731cd212
|
Minor improvements for Jackson in UnsafeDeserialization.qll
|
2021-07-09 10:24:15 +02:00 |
|
Artem Smotrakov
|
704cc77bb5
|
Added a change note for Jackson
|
2021-07-09 10:24:14 +02:00 |
|
Chris Smowton
|
d022c57903
|
Add change note
|
2021-07-02 10:02:28 +01:00 |
|
Chris Smowton
|
8b7db8a8cc
|
Merge pull request #5408 from p0wn4j/urlclassloader-webclient-ssrf-sinks
Java: Add URLClassLoader, WebClient SSRF sinks
|
2021-07-01 16:14:22 +01:00 |
|
Chris Smowton
|
44e8dd9ec5
|
Add change note
|
2021-07-01 13:36:00 +01:00 |
|
Anders Schack-Mulligen
|
cda5c22f6e
|
Merge pull request #5590 from github/sauyon/java-spring-errors
Add models for Spring validation.Errors
|
2021-07-01 14:29:49 +02:00 |
|
Chris Smowton
|
52471b292a
|
Add change note
|
2021-06-30 12:04:21 +01:00 |
|
Tony Torralba
|
0bb9e464b2
|
Merge branch 'main' into atorralba/spring-beans
|
2021-06-30 12:55:10 +02:00 |
|
Chris Smowton
|
ba5dc3cdbc
|
Add models of the javax.json package
|
2021-06-29 15:21:01 +01:00 |
|
Sauyon Lee
|
534ab86900
|
Add models for Spring validation.Errors
|
2021-06-29 05:51:21 -07:00 |
|
Sauyon Lee
|
c4e9b1fd8e
|
Model Spring util
|
2021-06-28 08:26:37 -07:00 |
|
Tony Torralba
|
8112d723e0
|
Merge branch 'main' into atorralba/spring-beans
|
2021-06-28 17:02:31 +02:00 |
|
Owen Mansel-Chan
|
e2803800dc
|
Add change note
|
2021-06-25 12:55:09 +01:00 |
|
Anders Schack-Mulligen
|
95ad8b55fe
|
Merge pull request #6107 from aschackmull/dataflow/implicit-reads
Dataflow: Add support for implicit reads
|
2021-06-24 15:38:35 +02:00 |
|
Anders Schack-Mulligen
|
01fc3e6559
|
C++/C#/Java/Python: Add change notes.
|
2021-06-24 14:29:34 +02:00 |
|
Anders Schack-Mulligen
|
1e511c0a9e
|
Merge pull request #6137 from smowton/smowton/feature/java-util-optional
Java: Model java.util.Optional
|
2021-06-24 13:21:36 +02:00 |
|
Chris Smowton
|
4c777eb04a
|
Add change note
|
2021-06-23 18:54:27 +01:00 |
|
Chris Smowton
|
9c91d1a965
|
Add change note
|
2021-06-23 16:09:29 +01:00 |
|
Anders Schack-Mulligen
|
7eb6da3888
|
Merge pull request #5772 from smowton/smowton/feature/apache-tuple-flow
Add models for Apache Commons Lang's tuple types
|
2021-06-18 11:25:07 +02:00 |
|
Tony Torralba
|
0c71393171
|
Merge branch 'main' into atorralba/promote-unsafe-android-webview-fetch
|
2021-06-17 14:54:25 +02:00 |
|
Chris Smowton
|
5cf0243dd0
|
Add change note
|
2021-06-17 12:34:40 +01:00 |
|
Chris Smowton
|
09f27554d0
|
Note incidental extra models in change note
|
2021-06-17 11:43:33 +01:00 |
|
Chris Smowton
|
8d70e3d22e
|
Fix casing of change note
|
2021-06-17 11:41:05 +01:00 |
|
Chris Smowton
|
fb2989c16b
|
Copyedit comments and function names
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-06-17 11:41:04 +01:00 |
|