Brandon Stewart
|
c7b4133fbe
|
Merge branch 'main' into patch-1
|
2022-06-28 09:46:46 -04:00 |
|
Brandon Stewart
|
33d1aae92a
|
Update ruby/ql/lib/codeql/ruby/frameworks/ActiveRecord.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2022-06-28 08:51:01 -04:00 |
|
Brandon Stewart
|
1dc26a0ca3
|
Update ruby/ql/lib/codeql/ruby/frameworks/ActiveRecord.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2022-06-28 08:50:54 -04:00 |
|
Arthur Baars
|
6e836c7eb8
|
Merge pull request #9706 from aibaars/update-tree-sitter-ruby-2
Ruby: update tree-sitter-ruby
|
2022-06-28 14:14:15 +02:00 |
|
Erik Krogh Kristensen
|
a343ceaf8b
|
add suspicious-regexp-range query
|
2022-06-28 09:49:27 +02:00 |
|
Asger F
|
cc57cb8af5
|
Merge branch 'main' into post-release-prep/codeql-cli-2.10.0
|
2022-06-27 20:37:25 +02:00 |
|
Brandon Stewart
|
99ae1b3f0d
|
Merge branch 'main' into patch-1
|
2022-06-27 10:12:26 -04:00 |
|
Brandon Stewart
|
52290fd4ae
|
run codeql query format
|
2022-06-27 10:01:40 -04:00 |
|
Arthur Baars
|
051b865230
|
Ruby: update tree-sitter-ruby
|
2022-06-27 13:03:04 +02:00 |
|
Nick Rolfe
|
280c959dc8
|
Merge branch 'main' into nickrolfe/pathname
|
2022-06-27 11:11:17 +01:00 |
|
Asger F
|
09476d1c13
|
Ruby: fix deprecation warning
|
2022-06-27 10:01:37 +02:00 |
|
Harry Maclean
|
101111bd2f
|
Merge pull request #9574 from hmac/hmac/action-cable-logger
Ruby: More Rails modeling
|
2022-06-27 19:56:54 +12:00 |
|
Asger F
|
d6fd43fe12
|
Merge pull request #9364 from asgerf/ruby/api-graph-api
Ruby: API graph renaming an documentation
|
2022-06-27 08:54:24 +02:00 |
|
Brandon Stewart
|
29e73e1a04
|
Update ActiveRecord.qll
|
2022-06-24 15:35:36 -04:00 |
|
Brandon Stewart
|
463c096d4c
|
Update ActiveRecord.qll
|
2022-06-24 15:33:02 -04:00 |
|
Brandon Stewart
|
2047954013
|
Merge branch 'main' into patch-1
|
2022-06-24 15:30:11 -04:00 |
|
Brandon Stewart
|
ff9a7244c2
|
Update ActiveRecord.qll
|
2022-06-24 15:28:09 -04:00 |
|
Nick Rolfe
|
c1515db09c
|
Ruby: modeling of some file-related concepts for the Pathname class
|
2022-06-24 14:14:07 +01:00 |
|
Nick Rolfe
|
03d0f66247
|
Ruby: add flow summaries for Pathname class
|
2022-06-24 14:14:06 +01:00 |
|
Erik Krogh Kristensen
|
9bc12ed8fd
|
sync review changes to other languages
|
2022-06-24 13:12:15 +02:00 |
|
Erik Krogh Kristensen
|
28ac47689f
|
changes based on reviews
|
2022-06-24 13:11:46 +02:00 |
|
github-actions[bot]
|
d506f448ef
|
Post-release preparation for codeql-cli-2.10.0
|
2022-06-24 07:36:33 +00:00 |
|
thiggy1342
|
6ea1aad5fc
|
more style fixes
|
2022-06-23 22:57:51 -04:00 |
|
thiggy1342
|
ce2edd4b28
|
style tweaks
|
2022-06-24 02:46:48 +00:00 |
|
thiggy1342
|
ca074e2275
|
add qhelp file
|
2022-06-24 02:19:06 +00:00 |
|
thiggy1342
|
cf36333082
|
forgot to finish this test
|
2022-06-24 02:18:48 +00:00 |
|
thiggy1342
|
45dd38df6e
|
polish up dataflow query
|
2022-06-24 01:50:20 +00:00 |
|
Brandon Stewart
|
caeef68bde
|
Update ActiveRecord.qll
|
2022-06-23 12:31:05 -04:00 |
|
Brandon Stewart
|
173bea2579
|
Update ActiveRecord.qll
|
2022-06-23 12:18:26 -04:00 |
|
Brandon Stewart
|
fa622f551a
|
Update ruby/ql/lib/codeql/ruby/frameworks/ActiveRecord.qll
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2022-06-23 12:16:50 -04:00 |
|
Anders Schack-Mulligen
|
dc517a758e
|
Autoformat
|
2022-06-23 14:44:40 +02:00 |
|
Erik Krogh Kristensen
|
724721c5c8
|
fix typo
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
22871138c6
|
simplify the recursion between TTrace and isReachableFromStartTuple
similar to the fix made by Shack in `ExponentialBackTracking.qll`
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
be37763125
|
improve performance of process() by pruning accept states early
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
bf20b7dfc5
|
add change note for the ReDoS renamings
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
14204be2f9
|
add missing qldoc
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3bea7df45d
|
add deprecated aliases in the old locations, and use the Query.qll pattern for js/polynomial-redos
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
13482fc97b
|
rename ReDoSUtil to NfaUtils, and rename the "performance" folder to "regexp"
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
6b0df9bdfb
|
refactor the concretize algorithm
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dbeae9aefb
|
make a parameterized module out of the RegexpMatching implementation
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
7fb3d81d2f
|
add further normalization of char classses
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3be4a86acd
|
make ReDoSPruning into a parameterized module
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dc06e9df02
|
move predicates that depend on isReDoSCandidate into a ReDoSPruning module
|
2022-06-23 14:36:24 +02:00 |
|
Anders Schack-Mulligen
|
4a317a25d3
|
Dataflow: Sync.
|
2022-06-23 14:34:52 +02:00 |
|
Asger F
|
d94010c244
|
Grammar: report -> reports
|
2022-06-23 14:17:52 +02:00 |
|
github-actions[bot]
|
a74051c658
|
Release preparation for version 2.10.0
|
2022-06-23 11:17:46 +00:00 |
|
Rasmus Wriedt Larsen
|
3248f7b423
|
Merge pull request #9649 from RasmusWL/certificate-modeling
Python/JS/Ruby: Ignore common words (like certain) as sensitive data source
|
2022-06-23 12:04:58 +02:00 |
|
thiggy1342
|
e838b83f5f
|
attempt to introduce dataflow tracking
|
2022-06-23 02:21:47 +00:00 |
|
Rasmus Wriedt Larsen
|
876ba71d9b
|
Python/JS/Ruby: Add change-note
|
2022-06-22 11:14:05 +02:00 |
|
Rasmus Wriedt Larsen
|
2ce4b7b9fc
|
SensitiveDataHeuristics: sync
|
2022-06-22 11:05:14 +02:00 |
|