Jeroen Ketema
|
0f5b70a802
|
C++: Add upgrade and downgrade scripts
|
2025-01-07 11:30:22 +01:00 |
|
Jeroen Ketema
|
2d7256862a
|
C++: Update dbscheme stats file
|
2025-01-07 11:28:32 +01:00 |
|
Jeroen Ketema
|
3812ee463d
|
C++: Add change note
|
2025-01-07 11:26:20 +01:00 |
|
Jeroen Ketema
|
a2d66ee155
|
C++: Extend the dbscheme with concept templates
|
2025-01-07 11:26:16 +01:00 |
|
Asger F
|
abea019751
|
Merge pull request #18412 from asgerf/jss/perf-fixes
JS: Fix a few perf issues
|
2025-01-07 11:20:57 +01:00 |
|
Asger F
|
f17cc5af15
|
JS: Move all hidden node definitions into DataFlowPrivate
|
2025-01-07 10:44:09 +01:00 |
|
Asger F
|
47cc3c09f5
|
JS: Deprecate an import
|
2025-01-07 10:43:40 +01:00 |
|
Tamás Vajk
|
e67f4be699
|
Merge pull request #18407 from tamasvajk/fix/razor-relative-path
C#: Change source generated razor file paths to be relative to csproj
|
2025-01-07 08:35:56 +01:00 |
|
dependabot[bot]
|
d7eaf9012f
|
Bump golang.org/x/tools
Bumps the extractor-dependencies group in /go/extractor with 1 update: [golang.org/x/tools](https://github.com/golang/tools).
Updates `golang.org/x/tools` from 0.28.0 to 0.29.0
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](https://github.com/golang/tools/compare/v0.28.0...v0.29.0)
---
updated-dependencies:
- dependency-name: golang.org/x/tools
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: extractor-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2025-01-07 03:20:27 +00:00 |
|
Chris Smowton
|
dd0012edcb
|
ASCII
|
2025-01-06 23:28:02 +01:00 |
|
Chris Smowton
|
03c6529961
|
Spelling
|
2025-01-06 22:46:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
7a9d341cb7
|
Merge pull request #18416 from MathiasVP/more-robust-param-name-matching-arrays
C++: Also resolve typedefs nested inside `ArrayType`s
|
2025-01-06 18:34:29 +00:00 |
|
Dave Bartolomeo
|
5d0c55ec33
|
Merge pull request #18419 from github/release-prep/2.20.1
Release preparation for version 2.20.1
|
2025-01-06 13:27:00 -05:00 |
|
Dave Bartolomeo
|
8a2398aaf0
|
Update python/ql/lib/CHANGELOG.md
|
2025-01-06 13:26:09 -05:00 |
|
github-actions[bot]
|
a121c5a5d0
|
Release preparation for version 2.20.1
|
2025-01-06 18:20:22 +00:00 |
|
aegilops
|
4530118681
|
Comment out hardcoded definition of sink
|
2025-01-06 17:33:31 +00:00 |
|
aegilops
|
820fe6cd04
|
Formatting
|
2025-01-06 16:59:04 +00:00 |
|
Cornelius Riemenschneider
|
0c2e05717f
|
Merge pull request #18417 from github/redsun82/cpp-analysis
Swift: fix CodeQL analysis workflow
|
2025-01-06 17:53:21 +01:00 |
|
aegilops
|
564df365cb
|
Merge branch 'main' of https://github.com/github/codeql into angular-sources-sinks
|
2025-01-06 16:53:02 +00:00 |
|
aegilops
|
322c731ac3
|
Attempt at AttributeDefinition to generalise Angular Renderer2 support
|
2025-01-06 16:52:38 +00:00 |
|
aegilops
|
6fb201372b
|
Update changelog note to remove new source
|
2025-01-06 16:51:59 +00:00 |
|
aegilops
|
e414b8c5be
|
Remove @Input() decorated members as remote sources, in favour of a later Threat Model
|
2025-01-06 16:51:35 +00:00 |
|
Paolo Tranquilli
|
370af8ac18
|
Swift: fix CodeQL analysis workflow
|
2025-01-06 17:12:37 +01:00 |
|
aegilops
|
8dac00aa83
|
Change from getParameter() to getArgument()
|
2025-01-06 15:43:47 +00:00 |
|
Mathias Vorreiter Pedersen
|
d935e9fb0f
|
C++: Also resolve typedefs nested inside arrays.
|
2025-01-06 14:50:37 +00:00 |
|
Mathias Vorreiter Pedersen
|
fdc305298d
|
C++: Add testcase with missing MaD support for resolving typedefs inside arrays.
|
2025-01-06 14:46:55 +00:00 |
|
Chris Smowton
|
d0eab598b1
|
Change note
|
2025-01-06 14:44:12 +00:00 |
|
Chris Smowton
|
5c2df36786
|
Exclude classes with a writeReplace method from serializability checks
|
2025-01-06 14:42:44 +00:00 |
|
Mathias Vorreiter Pedersen
|
493e75728c
|
Merge pull request #18386 from MathiasVP/more-robust-param-name-matching
C++: Resolve `typedef`s when matching MaD parameters
|
2025-01-06 14:40:17 +00:00 |
|
Geoffrey White
|
9d178ab8d6
|
Rust: Fix the failing integration tests.
|
2025-01-06 14:05:02 +00:00 |
|
Geoffrey White
|
f93aac07c2
|
Rust: Correct / clarify some QLDoc.
|
2025-01-06 13:50:41 +00:00 |
|
Asger F
|
0cdda87161
|
JS: Restrict AP length in prototype-polluting function
|
2025-01-06 14:33:41 +01:00 |
|
Mathias Vorreiter Pedersen
|
99ad184f57
|
Update cpp/ql/lib/semmle/code/cpp/dataflow/ExternalFlow.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2025-01-06 13:32:11 +00:00 |
|
Mathias Vorreiter Pedersen
|
75a3b6b613
|
Update cpp/ql/lib/semmle/code/cpp/dataflow/ExternalFlow.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2025-01-06 13:32:04 +00:00 |
|
Mathias Vorreiter Pedersen
|
f3085fc865
|
Update cpp/ql/lib/semmle/code/cpp/dataflow/ExternalFlow.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2025-01-06 13:30:59 +00:00 |
|
Mathias Vorreiter Pedersen
|
bfd18bc3e3
|
Update cpp/ql/lib/semmle/code/cpp/dataflow/ExternalFlow.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2025-01-06 13:30:50 +00:00 |
|
Asger F
|
7ccb476b1b
|
JS: Restrict AP length in ExceptionXss
|
2025-01-06 14:28:58 +01:00 |
|
Asger F
|
23d7420cec
|
JS: Hide default exceptional return node
|
2025-01-06 14:27:20 +01:00 |
|
Geoffrey White
|
e1e980c2e8
|
Rust: Add sensitive data to summary queries.
|
2025-01-06 13:26:27 +00:00 |
|
Geoffrey White
|
821eb4f3e6
|
Rust: Add sensitive data library.
|
2025-01-06 13:26:26 +00:00 |
|
Geoffrey White
|
c77bf2b4eb
|
Rust: Add a test for sensitive data.
|
2025-01-06 13:26:25 +00:00 |
|
Simon Friis Vindum
|
7248fb70c3
|
Merge pull request #18394 from paldepind/rust-format
Rust: Value flow and taint flow through formatting strings
|
2025-01-06 13:55:04 +01:00 |
|
Jeroen Ketema
|
01a7a5323b
|
Merge pull request #18360 from github/jketema/template-parameters-3
C++: Support arguments and instantiations of template template parameters
|
2025-01-06 13:41:45 +01:00 |
|
Ian Lynagh
|
c5ebc19a28
|
Java: Clarify supported langauge features
|
2025-01-06 12:31:46 +00:00 |
|
Jeroen Ketema
|
0942945fa1
|
Update cpp/ql/lib/semmle/code/cpp/TemplateParameter.qll
Co-authored-by: Calum Grant <42069085+calumgrant@users.noreply.github.com>
|
2025-01-06 13:30:43 +01:00 |
|
Tom Hvitved
|
1b31c90d26
|
Implement FlowSummaryImpl stubs
|
2025-01-06 13:26:51 +01:00 |
|
Tom Hvitved
|
8f6ae6274d
|
Rust: Add support for MaD sources and sinks with access paths
|
2025-01-06 13:26:49 +01:00 |
|
Tom Hvitved
|
37212cc43f
|
Ruby: Add change note
|
2025-01-06 13:26:13 +01:00 |
|
Tom Hvitved
|
978a816f11
|
Ruby: Track types in data flow
|
2025-01-06 13:26:10 +01:00 |
|
Tom Hvitved
|
06ba814929
|
Data flow: Prune parameter-self flow in stage 1
|
2025-01-06 13:23:03 +01:00 |
|