Erik Krogh Kristensen
|
9585481d0b
|
add support for static initializer blocks in TypeScript
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
59f15eb4eb
|
add tests for TypeScript 4.4 types
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
02a0eed8ee
|
add basic support for TypeScript 4.4
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
3b6c8c5191
|
Merge branch 'main' into clipBoard
|
2021-09-14 20:21:37 +02:00 |
|
CodeQL CI
|
136d04390d
|
Merge pull request #6695 from erik-krogh/js-add-cwes
Approved by esbena
|
2021-09-14 11:19:35 -07:00 |
|
Geoffrey White
|
8fd848701e
|
C++: Fix test failure.
|
2021-09-14 16:38:11 +01:00 |
|
Chris Smowton
|
e5b84fb795
|
Use InlineFlowTest
|
2021-09-14 16:37:07 +01:00 |
|
Chris Smowton
|
5d737934c3
|
Don't inherit models from a final class
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2021-09-14 16:37:07 +01:00 |
|
Chris Smowton
|
367a53dd71
|
Add models for android.net.Uri[.Builder]
|
2021-09-14 16:37:07 +01:00 |
|
Chris Smowton
|
ca87768a93
|
Merge pull request #6692 from bmuskalla/testGeneratorFlowTest
Java: Test generator uses `InlineFlowTest`
|
2021-09-14 15:44:24 +01:00 |
|
Mathias Vorreiter Pedersen
|
44dca68463
|
Merge branch 'main' into promote-sql-pqxx
|
2021-09-14 15:29:37 +01:00 |
|
Chris Smowton
|
406466de9a
|
Simplify specifiesContentType predicate
|
2021-09-14 15:24:46 +01:00 |
|
Mathias Vorreiter Pedersen
|
adbeba291b
|
Merge pull request #6687 from MathiasVP/fix-fp-in-av-rule-114
C++: Exclude uninstantiated templates from AV Rule 114.
|
2021-09-14 15:24:18 +01:00 |
|
Chris Smowton
|
6cff0d0376
|
Merge pull request #6393 from luchua-bc/java/xss-jsf
Java: CWE-079 Query to detect XSS with JavaServer Faces (JSF)
|
2021-09-14 15:15:56 +01:00 |
|
Anders Fugmann
|
bc22e0d9aa
|
C++: Update comments on memberMayBeVarSize
|
2021-09-14 16:04:39 +02:00 |
|
Tony Torralba
|
4e93330cb9
|
Improved tests
Note that a FN test case was added
|
2021-09-14 15:51:08 +02:00 |
|
Benjamin Muskalla
|
abd770a027
|
Avoid empty template in test generator
|
2021-09-14 15:32:12 +02:00 |
|
Chris Smowton
|
a1ad1ddc10
|
Deprecated and replace uses of old name ServletWriterSource
|
2021-09-14 14:21:29 +01:00 |
|
Rasmus Lerchedahl Petersen
|
d37c14880f
|
Python: Copy performance fix
|
2021-09-14 15:15:50 +02:00 |
|
Erik Krogh Kristensen
|
b936a04826
|
add some fitting CWEs to existing queries
|
2021-09-14 14:59:24 +02:00 |
|
Ethan Palm
|
c62a21e04f
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-09-14 08:55:46 -04:00 |
|
Erik Krogh Kristensen
|
6d12c4aab1
|
use the correct cwe tags
|
2021-09-14 14:42:23 +02:00 |
|
Anders Schack-Mulligen
|
26eafcb55a
|
Merge pull request #6456 from smowton/smowton/admin/flexjson-unsafe-deserialization
Java: add unsafe-deserialization support for Flexjson
|
2021-09-14 14:33:22 +02:00 |
|
Tony Torralba
|
0640b41f00
|
Adjust tests
|
2021-09-14 13:44:53 +02:00 |
|
Rasmus Wriedt Larsen
|
8b7fad8595
|
Merge pull request #6283 from tausbn/python-fix-exceptstmt-gettype
Python: Fix `ExceptStmt::getType`
|
2021-09-14 13:40:33 +02:00 |
|
Rasmus Wriedt Larsen
|
49f5f1e2c2
|
Merge pull request #6336 from tausbn/python-make-annotated-assignment-a-definitionnode
Python: Two fixes regarding annotated assignments
|
2021-09-14 13:37:53 +02:00 |
|
Chris Smowton
|
6af5c5fc86
|
Add change note
|
2021-09-14 12:36:38 +01:00 |
|
Chris Smowton
|
26dbf058c8
|
Add reverse import from ExternalFlow.qll
|
2021-09-14 12:35:33 +01:00 |
|
Chris Smowton
|
fcc0f1d5a7
|
Expand test to exercise all sinks
|
2021-09-14 12:27:33 +01:00 |
|
Chris Smowton
|
e439b7d7f8
|
Remove resource-related sources
These access application-owned resources AFAICT
|
2021-09-14 12:24:27 +01:00 |
|
Tony Torralba
|
b740cf9664
|
Add change note
|
2021-09-14 13:16:47 +02:00 |
|
Tony Torralba
|
097927226b
|
Improved heuristics to increase precision
|
2021-09-14 13:16:47 +02:00 |
|
Tony Torralba
|
f8d1e2ac11
|
Refactor tests to use InlineExpectationsTest
|
2021-09-14 13:16:45 +02:00 |
|
Tony Torralba
|
1f7990d6bb
|
Refactor to use ConditionalBypassQuery.qll
|
2021-09-14 13:16:09 +02:00 |
|
Tony Torralba
|
a484e9fb06
|
Use RemoteFlowSource instead of UserInput
|
2021-09-14 13:16:09 +02:00 |
|
Tom Hvitved
|
b69033f4ff
|
C++: Upgrade script
|
2021-09-14 13:14:04 +02:00 |
|
Tom Hvitved
|
6c32b92929
|
C++: Drop redundant columns from files and folders relations
|
2021-09-14 13:14:04 +02:00 |
|
Tom Hvitved
|
98a12cef26
|
Merge pull request #6690 from hvitved/js/files-folders-drop-columns
JavaScript: Drop redundant columns from `files` and `folders` relations
|
2021-09-14 13:13:37 +02:00 |
|
Chris Smowton
|
104873e8ee
|
Autoformat
|
2021-09-14 12:07:59 +01:00 |
|
Chris Smowton
|
6811441459
|
Factor JSF source definitions
|
2021-09-14 12:07:48 +01:00 |
|
Chris Smowton
|
b7fc068cee
|
Move JSFRenderer.qll to lib
|
2021-09-14 11:49:01 +01:00 |
|
Chris Smowton
|
023c533745
|
Combine Servlet and JSF vulnerable writer flow-tracking
JSP and Servlet already shared this logic; might as well add JSF into the same mechanism.
|
2021-09-14 11:48:34 +01:00 |
|
Chris Smowton
|
cb8096f636
|
Remove JSF XSS Example
Per previous commit, no need for a top-level JSF example
|
2021-09-14 11:47:37 +01:00 |
|
Chris Smowton
|
cca9ad06b4
|
Remove JSF example
I don't think we need this: there are lots of possible XSS vectors; we don't need to enumerate every one in the qhelp file.
|
2021-09-14 11:47:36 +01:00 |
|
Chris Smowton
|
76e4077b56
|
Delete unused classes
|
2021-09-14 11:47:35 +01:00 |
|
luchua-bc
|
24addd5c10
|
Query to detect XSS with JavaServer Faces (JSF)
|
2021-09-14 11:47:32 +01:00 |
|
Chris Smowton
|
e92b9cbe99
|
Improve getAProducesExpr documentation
|
2021-09-14 11:16:45 +01:00 |
|
Benjamin Muskalla
|
f9918cc63c
|
Test generator uses InlineFlowTest
|
2021-09-14 11:58:56 +02:00 |
|
Anders Schack-Mulligen
|
e71173d953
|
Merge pull request #6591 from bmuskalla/inlineFlowTest
Java: Simplify setup for flow tests using `InlineExpectationsTest`
|
2021-09-14 10:31:29 +02:00 |
|
Tom Hvitved
|
57b5b2af2e
|
JavaScript: DB upgrade script
|
2021-09-14 10:25:53 +02:00 |
|