Tom Hvitved
|
fe6efde449
|
Address review comments
|
2021-03-09 14:30:12 +01:00 |
|
Rasmus Lerchedahl Petersen
|
8b25806a2c
|
Python: Attempt to clarify help
|
2021-03-09 13:29:33 +01:00 |
|
Rasmus Lerchedahl Petersen
|
a16de26799
|
Python: add linebreak to qhelp file
hopefully this will generate better markdown
|
2021-03-09 13:27:44 +01:00 |
|
yoff
|
fd5ac13828
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.ql
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:23:44 +01:00 |
|
yoff
|
88784fbd31
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:23:35 +01:00 |
|
yoff
|
b6257edc9e
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:20:19 +01:00 |
|
yoff
|
d5b304ce75
|
Update python/change-notes/2021-02-23-port-insecure-default-protocol.md
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:19:48 +01:00 |
|
Taus
|
19b74e6e01
|
Merge pull request #5367 from tausbn/mergeback-rc/3.1-to-main
Merge rc/3.1 into main
|
2021-03-09 12:46:24 +01:00 |
|
Mathias Vorreiter Pedersen
|
19d08d7b40
|
Merge branch 'main' into rdmarsh/cpp/use-taint-configuration-dtt
|
2021-03-09 12:35:44 +01:00 |
|
Tamas Vajk
|
5480a31b68
|
Java: Remove MultipartFile.getSize/isEmpty from remote flow sources
|
2021-03-09 12:23:47 +01:00 |
|
Tamas Vajk
|
0d405c293a
|
Java: Convert PlayRequestGetMethod to CSV based flow source
|
2021-03-09 12:20:35 +01:00 |
|
Joe Farebrother
|
7a4ce83169
|
Merge pull request #5310 from joefarebrother/guava-io
Java: Add modelling for Guava IO utilities
|
2021-03-09 11:19:44 +00:00 |
|
Joe Farebrother
|
bd4a414abd
|
Remove CSV data from query
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-03-09 10:50:15 +00:00 |
|
Tamas Vajk
|
e0b1a86038
|
Java: Convert WebSocketMessageParameterSource to CSV based flow source
|
2021-03-09 11:49:59 +01:00 |
|
Tamas Vajk
|
193458eb3d
|
Java: Convert SpringRestTemplateResponseEntityMethod to CSV based flow source
|
2021-03-09 11:49:59 +01:00 |
|
Tamas Vajk
|
e0c51b510f
|
Java: Convert WebViewGetUrlMethod to CSV based flow source
|
2021-03-09 11:42:40 +01:00 |
|
Tamas Vajk
|
8ba820cae1
|
Java: Convert android XML get* methods to CSV based flow source
|
2021-03-09 11:42:13 +01:00 |
|
Tamas Vajk
|
09b0d824b4
|
Java: Convert org.apache.http.Http*.get* methods to CSV based flow source
|
2021-03-09 11:41:33 +01:00 |
|
Tamas Vajk
|
3c8ac5c789
|
Java: Convert Cookie.get* methods to CSV based flow source
|
2021-03-09 11:41:33 +01:00 |
|
Tamas Vajk
|
86cf143029
|
Java: Convert ServletRequestGetBodyMethod to CSV based flow source
|
2021-03-09 11:41:32 +01:00 |
|
Tamas Vajk
|
b05a9043b5
|
Java: Convert SpringWebRequestGetMethod to CSV based flow source
|
2021-03-09 11:41:32 +01:00 |
|
Tamas Vajk
|
09bcf878f7
|
Java: Convert HttpServletRequest.get* methods to CSV based flow source
|
2021-03-09 11:40:59 +01:00 |
|
Tamas Vajk
|
f2448cc921
|
Java: Convert SpringMultipartFileSource to CSV based flow source
|
2021-03-09 11:40:18 +01:00 |
|
Tamas Vajk
|
80b4d63d4b
|
Java: Convert SpringMultipartRequestSource to CSV based flow source
|
2021-03-09 11:39:47 +01:00 |
|
Tamas Vajk
|
06fdd64dab
|
Java: Remove already modelled BeanValidationSource
|
2021-03-09 11:35:42 +01:00 |
|
Tamas Vajk
|
3dfc236bbe
|
Java: Remove already modelled RemoteTaintedMethods
|
2021-03-09 11:35:42 +01:00 |
|
Erik Krogh Kristensen
|
caf1dbdc46
|
move TemplateObjectInjection out of experimental
|
2021-03-09 11:29:45 +01:00 |
|
Tamas Vajk
|
ba05bf3ae0
|
Fix code review findings
|
2021-03-09 11:17:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
d14b993aba
|
C++: Replace 'Argument -1 indirection' with 'This indirection'.
|
2021-03-09 10:22:21 +01:00 |
|
Jonas Jensen
|
2a9f7a966c
|
Merge pull request #5361 from MathiasVP/arguments-in-path-explanations
C++: Show arguments in path explanations
|
2021-03-09 09:35:03 +01:00 |
|
Tom Hvitved
|
d4e0c7efae
|
Merge pull request #5340 from hvitved/csharp/null-checks
C#: Use `is [not] null` throughout in the extractor
|
2021-03-09 09:30:54 +01:00 |
|
Tamas Vajk
|
0defad77dd
|
C#: Add tuple data flow in patterns
|
2021-03-09 09:14:24 +01:00 |
|
Tom Hvitved
|
80a7b52f38
|
C#: Convert data-flow test queries to path-problems
|
2021-03-09 09:14:24 +01:00 |
|
Tom Hvitved
|
0698bdd907
|
C#: Restrict tuple read/store steps to tuple deconstructions/constructions
|
2021-03-09 09:14:24 +01:00 |
|
Tamas Vajk
|
6d409a0050
|
Fix failing tests
|
2021-03-09 09:14:24 +01:00 |
|
Tamas Vajk
|
ccf68ffd16
|
Add change note for tuple data flow improvements
|
2021-03-09 09:14:24 +01:00 |
|
Tamas Vajk
|
fcc4758eb8
|
Remove old taint tracking for tuples
|
2021-03-09 09:14:24 +01:00 |
|
Tamas Vajk
|
d05a733109
|
Add more test cases
|
2021-03-09 09:14:23 +01:00 |
|
Tamas Vajk
|
b05199dccf
|
Tuple data flow: take cfg reachability into account
|
2021-03-09 09:14:23 +01:00 |
|
Tamas Vajk
|
0ca4bf4267
|
C#: WIP: Add tuple data flow
|
2021-03-09 09:14:23 +01:00 |
|
Tamas Vajk
|
4709442ef3
|
Extract tuple types from patterns and variable declarations
|
2021-03-09 09:14:23 +01:00 |
|
Tamas Vajk
|
1d70bfd011
|
Extract non-named tuple types
|
2021-03-09 09:06:35 +01:00 |
|
Tamas Vajk
|
7e1eee5fe2
|
Add tests that show tuple types
|
2021-03-09 09:06:35 +01:00 |
|
Taus Brock-Nannestad
|
3d0d280972
|
Merge remote-tracking branch 'upstream/rc/3.1' into mergeback-rc/3.1-to-main
|
2021-03-08 22:15:10 +01:00 |
|
Artem Smotrakov
|
a78f2115f2
|
Split SpringExporterUnsafeDeserialization.ql
|
2021-03-09 00:06:38 +03:00 |
|
Erik Krogh Kristensen
|
25ef3edb20
|
combine stages by introducing extended stages
|
2021-03-08 20:48:15 +01:00 |
|
Aditya Sharad
|
318ce47982
|
Actions: Fix comment that tags the Docs team
|
2021-03-08 09:17:19 -08:00 |
|
Mathias Vorreiter Pedersen
|
7207a17f6f
|
C++: Accept more tests.
|
2021-03-08 16:50:12 +01:00 |
|
Anders Schack-Mulligen
|
aeb13146d2
|
Merge pull request #5275 from Marcono1234/marcono1234/included-qhelp-files
Use `.inc.qhelp` extension for included help files
|
2021-03-08 16:26:32 +01:00 |
|
Chris Smowton
|
f9f143d62c
|
Merge pull request #5347 from Marcono1234/marcono1234/simplify-tests
Java: Simplify tests using InlineExpectationsTest
|
2021-03-08 14:47:28 +00:00 |
|