Owen Mansel-Chan
|
056aa342fe
|
Change @security-severity for log injection queries from 7.8 to 6.1
|
2026-03-13 10:02:01 +00:00 |
|
Owen Mansel-Chan
|
f58a6e5d3a
|
Change @security-severity for XSS queries from 6.1 to 7.8
|
2026-03-13 10:01:02 +00:00 |
|
Mario Campos
|
6fb10555ff
|
Correct comment about AES crypto algorithm strength
|
2026-03-11 09:27:03 -05:00 |
|
Owen Mansel-Chan
|
b2f878229d
|
Use shared getASuccessor and getAPredecessor
|
2026-01-28 22:12:23 +00:00 |
|
Owen Mansel-Chan
|
16113e6550
|
Use type cast to make QL more succinct
|
2026-01-14 11:50:56 +00:00 |
|
Owen Mansel-Chan
|
76bba60383
|
Fix misspelling in comment
|
2026-01-14 11:50:55 +00:00 |
|
Anders Schack-Mulligen
|
78e1879c9e
|
Use more flowTo.
|
2025-12-03 14:12:08 +01:00 |
|
Anders Schack-Mulligen
|
dc6d3fe7ba
|
Use flowFrom.
|
2025-12-03 14:04:18 +01:00 |
|
Owen Mansel-Chan
|
b8ccaf3b11
|
Improve formatting of tags metadata
|
2025-11-28 02:26:58 +00:00 |
|
Joe Farebrother
|
c6110ed541
|
Split SecureCookies into query specific files
|
2025-11-25 14:35:47 +00:00 |
|
Joe Farebrother
|
1bd5005fc1
|
Fix typos
|
2025-11-25 14:35:17 +00:00 |
|
Joe Farebrother
|
6282c34396
|
Update formatting
|
2025-11-25 14:35:09 +00:00 |
|
Joe Farebrother
|
fa30041498
|
Add qhelp & fix tests
|
2025-11-25 14:34:28 +00:00 |
|
Joe Farebrother
|
2b1cd846b3
|
Fixes and doc updates
|
2025-11-25 14:34:10 +00:00 |
|
Joe Farebrother
|
74c424dc4c
|
Fixes, add secure query
|
2025-11-25 14:33:33 +00:00 |
|
Joe Farebrother
|
7d76619bea
|
Implement cookie write concepts and httponly query
|
2025-11-25 14:33:23 +00:00 |
|
Owen Mansel-Chan
|
adbc1efe59
|
Fix diff-informed predicates
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
8d7b2757bf
|
Add query help examples
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
52d7e2dd18
|
Add query for hashing sensitive data with weak hashing algorithm
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
713e19f6f1
|
Make non-path query for encryption only
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
34b2e3e2bf
|
Copy the structure of the Javascript query
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
5c403d374e
|
Move crypto qll files from query pack to library pack
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
92a3bccfd6
|
Align metadata with related queries
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
188b25f11f
|
Remove experimental tag from query metadata
|
2025-11-19 14:36:26 +00:00 |
|
Owen Mansel-Chan
|
2c20d3ffeb
|
Move weak crypto algorithm query out of experimental
|
2025-11-19 14:36:26 +00:00 |
|
Nora Dimitrijević
|
59a8e9b78c
|
Go/InsufficientKeySize
|
2025-10-28 09:39:27 +01:00 |
|
Owen Mansel-Chan
|
2ffb638b7e
|
Delete WriteNode.writesFieldOnSsaWithFields
This can be easily expressed in terms of `WriteNode.writesFieldPreUpdate`.
|
2025-10-01 16:13:27 +01:00 |
|
Owen Mansel-Chan
|
489b8431ea
|
Add and use WriteNode.writesFieldPreUpdate
|
2025-10-01 16:13:25 +01:00 |
|
Owen Mansel-Chan
|
748c53a791
|
Refactor: Create writesFieldOnSsaWithFields
|
2025-10-01 16:12:56 +01:00 |
|
Owen Mansel-Chan
|
cf6cfe2a1e
|
Non-initializing writes should target post-update nodes
|
2025-10-01 16:12:54 +01:00 |
|
Owen Mansel-Chan
|
9068315f03
|
Fix IncorrectIntegerConversion for use-use flow
We were assuming that `sink` only had one successor, the TypeCastNode, but it
can now have an adjacent use as well.
|
2025-10-01 16:12:19 +01:00 |
|
Arthur Baars
|
5d3ec35e29
|
Remove non-breaking spaces from code
|
2025-09-05 09:41:15 +02:00 |
|
Nora Dimitrijević
|
8824677e87
|
[DIFF-INFORMED] Go: BadRedirectCheck
|
2025-07-17 11:46:54 +02:00 |
|
Nora Dimitrijević
|
b4010ac2b4
|
[DIFF-INFORMED] Go: InsecureHostKeyCallback
|
2025-07-17 11:46:53 +02:00 |
|
Nora Dimitrijević
|
51826c72d0
|
Go: mass-add none() location overrides
|
2025-06-17 17:02:08 +02:00 |
|
Nora Dimitrijević
|
e233501144
|
Go: mass enable diff-informed data flow
An auto-generated patch that enables diff-informed data flow in the obvious cases.
Builds on https://github.com/github/codeql/pull/18345 and https://github.com/github/codeql-patch/pull/88
|
2025-06-11 18:44:24 +02:00 |
|
Owen Mansel-Chan
|
ef5e605cc4
|
Merge pull request #19386 from owen-mc/go/promote/html-template-escaping-bypass-xss
Go: promote `html-template-escaping-bypass-xss`
|
2025-06-06 12:36:27 +01:00 |
|
Michael Nebel
|
03ecd24469
|
Lower the precision of a range of harcoded password queries to remove them from query suites.
|
2025-05-19 09:26:45 +02:00 |
|
Owen Mansel-Chan
|
c933ab4ae2
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2025-05-12 16:24:56 -04:00 |
|
Owen Mansel-Chan
|
8283d30d94
|
Avoid deprecated function in qhelp examples in same folder
|
2025-05-01 16:06:31 +01:00 |
|
Owen Mansel-Chan
|
00cc430ac3
|
Make examples in qhelp shorter and more realistic
|
2025-05-01 16:06:29 +01:00 |
|
Owen Mansel-Chan
|
6e3b959f61
|
Reword qhelp slightly
|
2025-05-01 16:06:28 +01:00 |
|
Owen Mansel-Chan
|
f8791861c7
|
Add missing metadata
|
2025-05-01 16:06:19 +01:00 |
|
Owen Mansel-Chan
|
38dcc1cb84
|
Fix QLDoc
|
2025-05-01 15:40:17 +01:00 |
|
Owen Mansel-Chan
|
3b934b8898
|
Add comment on importance of Function.getACall()
|
2025-05-01 15:40:15 +01:00 |
|
Owen Mansel-Chan
|
cba0bec3c6
|
Rename files
|
2025-05-01 15:40:12 +01:00 |
|
Owen Mansel-Chan
|
3cce4ba437
|
Improve QLDocs
|
2025-05-01 15:40:10 +01:00 |
|
Owen Mansel-Chan
|
7f007e10c4
|
Minor refactor - removed unused argument
|
2025-05-01 15:40:09 +01:00 |
|
Owen Mansel-Chan
|
b90aba291e
|
Refactor class for unescaped types
|
2025-05-01 15:40:07 +01:00 |
|
Owen Mansel-Chan
|
4e5a865337
|
Manually fix copilot's mistakes and get query working
|
2025-05-01 15:40:04 +01:00 |
|