github-actions[bot]
|
661e68dab5
|
Release preparation for version 2.16.4
|
2024-03-05 18:13:58 +00:00 |
|
Joe Farebrother
|
dcc6f83d3b
|
Merge pull request #15782 from joefarebrother/ruby-typhoeus
Ruby: Model `Typhoeus::Request.new`
|
2024-03-05 16:55:38 +00:00 |
|
Angela P Wen
|
967963a653
|
Revert "Release preparation for version 2.16.4"
|
2024-03-05 08:53:33 -08:00 |
|
Joe Farebrother
|
7027b7fe82
|
Apply review suggestions: Use getInstance and clarify predicate name/qldoc. Also fix changenote formatting.
|
2024-03-05 16:34:48 +00:00 |
|
Harry Maclean
|
148241183a
|
Ruby: update changenote
|
2024-03-05 10:20:25 +00:00 |
|
Harry Maclean
|
91cb2a37fd
|
Ruby: Model Process.exec
|
2024-03-05 10:19:22 +00:00 |
|
Tom Hvitved
|
bd7b2c4cc6
|
Update expected output
|
2024-03-05 10:44:13 +01:00 |
|
Harry Maclean
|
179aaa1342
|
Ruby: model Open4.popen4ext
|
2024-03-05 09:35:18 +00:00 |
|
Harry Maclean
|
87f3b43576
|
Ruby: remove deprecated private class
|
2024-03-05 08:28:16 +00:00 |
|
github-actions[bot]
|
a67218a027
|
Release preparation for version 2.16.4
|
2024-03-04 17:42:08 +00:00 |
|
Angela P Wen
|
2b2ea597ce
|
Fix formatting on changenotes
|
2024-03-04 16:42:38 +00:00 |
|
Joe Farebrother
|
31687afd5d
|
Fix performance
|
2024-03-04 09:47:12 +00:00 |
|
Joe Farebrother
|
5a1c0f60e6
|
Fix qldoc typo
|
2024-03-01 15:12:16 +00:00 |
|
Peter Stöckli
|
4adc373dfe
|
Ruby: more test cases for code injection via method
|
2024-03-01 16:01:07 +01:00 |
|
Joe Farebrother
|
4b1626c83a
|
Add change note
|
2024-03-01 14:59:24 +00:00 |
|
Peter Stöckli
|
3418ec8a81
|
Ruby: Update method code injection sinks change note
Co-authored-by: Harry Maclean <hmac@github.com>
|
2024-03-01 15:54:58 +01:00 |
|
Joe Farebrother
|
65b30c1dff
|
Add tests and qldoc
|
2024-03-01 14:46:55 +00:00 |
|
Joe Farebrother
|
a08b292099
|
Add models for Typhoeus::Request
|
2024-03-01 14:23:24 +00:00 |
|
Peter Stöckli
|
e43c368222
|
Ruby: change note for methode code injection sinks
|
2024-03-01 15:20:32 +01:00 |
|
Peter Stöckli
|
a693c6d9b4
|
Ruby: sinks for code injection via calls to method
|
2024-03-01 14:42:22 +01:00 |
|
Joe Farebrother
|
abdae2c437
|
Apply reveiw suggestion - update change note
Co-authored-by: Harry Maclean <hmac@github.com>
|
2024-03-01 09:57:28 +00:00 |
|
Joe Farebrother
|
bf2174ffce
|
Add change note
|
2024-03-01 09:57:28 +00:00 |
|
Joe Farebrother
|
0b7b7ea1b8
|
Add test cases and improve controller model
|
2024-03-01 09:57:24 +00:00 |
|
Joe Farebrother
|
ef0a1d2873
|
Implement models for translation methods
|
2024-03-01 09:52:53 +00:00 |
|
Tom Hvitved
|
914a605a87
|
Ruby: Rework hidden synthetic data-flow nodes
|
2024-02-27 15:33:58 +01:00 |
|
Tom Hvitved
|
994d990f37
|
Ruby: Add another data flow test
|
2024-02-27 15:33:58 +01:00 |
|
Joe Farebrother
|
3ab6f222d0
|
Merge pull request #15718 from joefarebrother/ruby-arel-sqlliteral
Ruby: Model Arel::Nodes::SqlLiteral.new
|
2024-02-27 12:43:47 +00:00 |
|
Harry Maclean
|
d0e7fbc871
|
Ruby: Add changenote
|
2024-02-27 09:47:51 +00:00 |
|
Tom Hvitved
|
bbeee8f38d
|
Merge pull request #15717 from hvitved/csharp/view-cfg
Shared `View CFG` implementation
|
2024-02-27 09:13:18 +01:00 |
|
Joe Farebrother
|
cb733dcf85
|
Simplify model defenition
|
2024-02-26 14:59:03 +00:00 |
|
Cornelius Riemenschneider
|
4bb725cbf5
|
Merge pull request #15656 from github/criemen/ruby-bazel
Ruby: Start building the language pack using bazel.
|
2024-02-26 15:52:28 +01:00 |
|
Harry Maclean
|
8212f5de1b
|
Ruby: Update test
|
2024-02-26 13:10:27 +00:00 |
|
Harry Maclean
|
b86643fab2
|
Ruby: doc fixes
|
2024-02-26 12:57:21 +00:00 |
|
Harry Maclean
|
8a670fe9a2
|
Ruby: formatting
|
2024-02-26 12:26:04 +00:00 |
|
amammad
|
32f5667bb6
|
revert YAML.qll and yaml sinks to previous PR, make a separate experimental query only for yaml
|
2024-02-26 12:12:03 +00:00 |
|
amammad
|
c582ea626d
|
update expected test file
|
2024-02-26 12:10:04 +00:00 |
|
amammad
|
1c1a6f13df
|
fix QLDoc style
|
2024-02-26 12:05:35 +00:00 |
|
amammad
|
9c5c8c8362
|
fix test file
|
2024-02-26 12:05:35 +00:00 |
|
amammad
|
464e2e4291
|
fix qldoc and test files
|
2024-02-26 12:04:52 +00:00 |
|
amammad
|
18fa91bde4
|
add transform method that is an alias for to_ruby
|
2024-02-26 11:59:41 +00:00 |
|
amammad
|
a75a004942
|
add more additional steps, change parse* sinks to reciever of them
|
2024-02-26 11:59:41 +00:00 |
|
amammad
|
474a4f8abd
|
thanks @asgerf for informing me that Successor wants to be deprecated and thank him that providing the solution
|
2024-02-26 11:59:41 +00:00 |
|
amammad
|
1410574f76
|
make seperate steps for YAML.parse* and use getAsuccessor*() to reach final to_ruby method call, All parts have Rewritten with API graphs exclusively
|
2024-02-26 11:59:35 +00:00 |
|
Harry Maclean
|
f7b8e8af41
|
Ruby: Include request forgery sinks from MaD
|
2024-02-26 11:34:11 +00:00 |
|
Harry Maclean
|
8bed3fbed4
|
Ruby: Add basic model for Terrapin library
|
2024-02-26 11:32:41 +00:00 |
|
Harry Maclean
|
9d13a1ff51
|
Ruby: Add model for Process.spawn
|
2024-02-26 11:26:38 +00:00 |
|
Harry Maclean
|
d1847566b6
|
Ruby: Ql4QL fix
|
2024-02-26 11:26:38 +00:00 |
|
Harry Maclean
|
beef9965cc
|
Ruby: Model Open4 library
Also remove duplicate modeling of Process.spawn.
|
2024-02-26 11:26:38 +00:00 |
|
Harry Maclean
|
a03c06802e
|
Ruby: Add some more command injection sinks
|
2024-02-26 11:26:38 +00:00 |
|
Cornelius Riemenschneider
|
1657b314c1
|
Re-pin ruby extractor deps.
|
2024-02-26 11:21:23 +00:00 |
|