Erik Krogh Kristensen
|
e962a7c77c
|
Update python/ql/src/semmle/python/RegexTreeView.qll
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2021-08-16 11:24:05 +02:00 |
|
Rasmus Lerchedahl Petersen
|
6be78d442c
|
Python: fix compilation
|
2021-08-16 10:35:33 +02:00 |
|
Fosstars
|
fbac5891b8
|
Fixed a typo in qldoc
|
2021-08-14 21:28:30 +02:00 |
|
Marcono1234
|
48872b4588
|
Java: Improve Callable.getStringSignature() documentation
|
2021-08-14 19:58:55 +02:00 |
|
Fosstars
|
e2dc9753ac
|
Covered copyOfRange() and clone() in ArrayUpdate
|
2021-08-14 13:25:46 +02:00 |
|
Fosstars
|
d218813320
|
Updated qldoc for ArrayUpdate
|
2021-08-14 13:09:14 +02:00 |
|
Fosstars
|
11992404ec
|
Be precise when checking for Cipher.ENCRYPT_MODE
|
2021-08-14 12:18:02 +02:00 |
|
Fosstars
|
4e69081c22
|
Support multi-dimensional arrays
|
2021-08-13 20:52:27 +02:00 |
|
Sarita Iyer
|
57ff8e7138
|
Merge pull request #6473 from github/sarita-iyer/codeql-packs-vscode
Added article for working with codeQL packs in VS Code
|
2021-08-12 16:08:00 -04:00 |
|
Sarita Iyer
|
a373ac8332
|
Update period at end of quote
|
2021-08-12 15:42:23 -04:00 |
|
Sarita Iyer
|
eb2ef23d56
|
Apply suggestions from code review
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
Co-authored-by: Andrew Eisenberg <aeisenberg@github.com>
|
2021-08-12 14:57:13 -04:00 |
|
Sauyon Lee
|
814004e63d
|
Add tests for html escape functions
|
2021-08-12 11:20:49 -07:00 |
|
Sauyon Lee
|
ed1d855025
|
Java: Remove redundant models from Spring web.util and fix typo
|
2021-08-12 11:20:49 -07:00 |
|
Sauyon Lee
|
9c1d5a70e3
|
Java: Add test for XSS sanitizer
|
2021-08-12 11:20:49 -07:00 |
|
Sauyon Lee
|
9a5c0f6c73
|
Java: Add HTML escapes as XSS sanitizers
Co-Authored-By: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-08-12 11:20:49 -07:00 |
|
Sauyon Lee
|
eb980e2a40
|
Add change note
|
2021-08-12 11:20:49 -07:00 |
|
Sauyon Lee
|
d86dffbb5d
|
Add tests for Spring web.util
|
2021-08-12 11:20:48 -07:00 |
|
Sauyon Lee
|
fd0ea15719
|
Add stubs for Spring web.util tests
|
2021-08-12 11:20:48 -07:00 |
|
Sauyon Lee
|
25649a61c4
|
Java: Add models for the Spring web.util package
|
2021-08-12 11:20:48 -07:00 |
|
Sarita Iyer
|
d1190dc5f2
|
Switch from object to element, and clarify package cache functionality
|
2021-08-12 10:41:20 -04:00 |
|
Owen Mansel-Chan
|
1c2476c6a1
|
Add explanatory comments
|
2021-08-12 14:51:49 +01:00 |
|
Owen Mansel-Chan
|
fe477ff989
|
Fix more models based on review comments
|
2021-08-12 14:51:37 +01:00 |
|
Rasmus Lerchedahl Petersen
|
2df846ee4b
|
Merge branch 'python-regex-parsing-consistency-checks' of github.com:yoff/codeql into python-regex-parsing-consistency-checks
|
2021-08-12 13:34:11 +02:00 |
|
Rasmus Lerchedahl Petersen
|
54e65ce765
|
Python: Add consistency tests
for all the projects that went out of disk as a result of ReDoS
|
2021-08-12 13:33:44 +02:00 |
|
Shati Patel
|
1707fb8821
|
Merge pull request #6475 from github/correct-link-syntax
Fix markup in `metadata-for-codeql-queries.rst`
|
2021-08-12 09:36:18 +01:00 |
|
yoff
|
61bbddeb0c
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2021-08-12 09:39:04 +02:00 |
|
Asger Feldthaus
|
a6c389698e
|
JS: Fix DomBasedXssQuery.qll
|
2021-08-12 09:31:24 +02:00 |
|
Asger Feldthaus
|
fd027451b1
|
JS: Fix StoresXss example query
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
020d65befc
|
Fix StoredXssTypeTracking example query
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
cb0075f15a
|
JS: Remove use of deprecated API
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
3a6da34454
|
JS: Add missing QLdoc
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
71930f93f1
|
JS: Fix cleartext logging
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
abb819ed88
|
JS: Fix insecure randomness
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
5638a33199
|
JS: Remove obsolete module prefix
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
f6da030572
|
JS: Migrate to *Query.qll convention
|
2021-08-12 09:30:18 +02:00 |
|
CodeQL CI
|
8fe2a43fd9
|
Merge pull request #6433 from asgerf/js/tainted-url-suffix
Approved by erik-krogh
|
2021-08-12 00:28:46 -07:00 |
|
James Fletcher
|
3bd918972e
|
fix markup
|
2021-08-12 08:16:20 +01:00 |
|
yo-h
|
bd3a24d568
|
Java: add org.json package to known frameworks
|
2021-08-11 20:03:32 -04:00 |
|
Sarita Iyer
|
186e011a4b
|
Added codeql packs info for use in VS code
|
2021-08-11 15:47:27 -04:00 |
|
Alexandre Boulgakov
|
00466e4bb0
|
Merge pull request #6464 from sashabu/sashabu/auto
C++: Expose trailing return type presence.
|
2021-08-11 18:43:39 +01:00 |
|
Chris Smowton
|
7a2704373f
|
Merge pull request #5943 from joefarebrother/java-stub
[Java] Add stubbing script
|
2021-08-11 16:11:53 +01:00 |
|
Alexandre Boulgakov
|
490498899b
|
C++: Expose trailing return type presence.
|
2021-08-11 16:04:07 +01:00 |
|
Geoffrey White
|
3f72a1abea
|
Merge pull request #6471 from MathiasVP/fix-fp-in-incorrect-allocation-error-handling
C++: Fix false-positive in 'cpp/incorrect-allocation-error-handling'
|
2021-08-11 15:56:55 +01:00 |
|
CodeQL CI
|
c8ded7ebf6
|
Merge pull request #6459 from erik-krogh/oreq
Approved by asgerf
|
2021-08-11 07:40:13 -07:00 |
|
Mathias Vorreiter Pedersen
|
8d594dbf08
|
Update cpp/ql/test/query-tests/Security/CWE/CWE-570/test.cpp
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-08-11 16:18:18 +02:00 |
|
Benjamin Muskalla
|
8aba0b04bc
|
Add QLDoc for all shared libraries
|
2021-08-11 16:07:24 +02:00 |
|
Mathias Vorreiter Pedersen
|
0d1884d7a6
|
C++: Fix FP and accept test changes.
|
2021-08-11 15:38:57 +02:00 |
|
Mathias Vorreiter Pedersen
|
c2b1da0010
|
C++: Add FP testcase with an 'new' that has a 'std::nothrow&' parameter, but not a 'noexcept' specifier. This case was previously not reported because of the 'noexcept' specifier, and apparently the 'std::nothrow' case was broken all along.
|
2021-08-11 15:38:03 +02:00 |
|
Benjamin Muskalla
|
26ffe6c03d
|
Add tests for telemetry queries
|
2021-08-11 15:32:09 +02:00 |
|
Benjamin Muskalla
|
6287e6d8e9
|
Filter unused API callsites
|
2021-08-11 15:31:56 +02:00 |
|