github-actions[bot]
|
13cf054a9d
|
Post-release preparation for codeql-cli-2.14.0
|
2023-07-07 14:55:41 +00:00 |
|
github-actions[bot]
|
6484ee106e
|
Release preparation for version 2.14.0
|
2023-07-07 08:22:14 +00:00 |
|
Dave Bartolomeo
|
9631e9f2f1
|
Bump minor version numbers post-GHES
|
2023-07-06 10:10:01 -04:00 |
|
Dave Bartolomeo
|
2bb9adfbf1
|
Merge remote-tracking branch 'origin/main' into dbartol/mergeback-3.10
|
2023-07-06 10:00:46 -04:00 |
|
Maiky
|
08c54767f2
|
Correct Ldap Unauth Bind Sink
|
2023-07-05 17:56:49 +02:00 |
|
Porcupiney Hairs
|
dc0deb5e49
|
Go : Improvements to DSN Injection query
|
2023-07-02 17:38:01 +05:30 |
|
github-actions[bot]
|
668aaa2dc8
|
Post-release preparation for codeql-cli-2.13.5
|
2023-06-30 08:51:48 +00:00 |
|
github-actions[bot]
|
9d7987f822
|
Release preparation for version 2.13.5
|
2023-06-29 09:26:18 +00:00 |
|
amammad
|
fbfc959f82
|
V1 Bombs
|
2023-06-25 01:21:09 +10:00 |
|
Henry Mercer
|
5afdaf8fe1
|
Merge pull request #13525 from github/rc/3.10
Merge `rc/3.10` back to `main`
|
2023-06-21 17:13:36 +01:00 |
|
github-actions[bot]
|
18b678e69e
|
Post-release preparation for codeql-cli-2.13.4
|
2023-06-20 10:20:05 +00:00 |
|
Jeroen Ketema
|
9c774ac97f
|
Merge pull request #13426 from jketema/inline-3
Update inline flow tests to use parameterized module
|
2023-06-19 17:39:29 +02:00 |
|
Tony Torralba
|
8f6d2ed2f9
|
Adjust ZipSlip query description according to review suggestions.
|
2023-06-19 10:27:41 +02:00 |
|
Tony Torralba
|
3c4d938cf1
|
Apply code review suggestions.
Co-authored-by: Asger F <asgerf@github.com>
|
2023-06-19 10:20:19 +02:00 |
|
Tony Torralba
|
433fc680ec
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-06-19 10:17:40 +02:00 |
|
Maiky
|
d654e98650
|
Add empty string as source
|
2023-06-18 22:21:12 +02:00 |
|
Tony Torralba
|
c97868f774
|
Add change notes
|
2023-06-16 09:01:02 +02:00 |
|
Tony Torralba
|
3e96fe60c5
|
Go/Java/JS/Python/Ruby: Update the description and qhelp of the ZipSlip query
All filesystem operations, not just writes, with paths built from untrusted archive entry names are dangerous
|
2023-06-16 08:52:44 +02:00 |
|
Jeroen Ketema
|
eb62df6ece
|
Go: Rewrite InlineFlowTest as a parameterized module
|
2023-06-15 10:51:29 +02:00 |
|
github-actions[bot]
|
e4be303a23
|
Release preparation for version 2.13.4
|
2023-06-08 19:57:37 +00:00 |
|
Maiky
|
1a9bfb38aa
|
Correct barrier
|
2023-06-05 01:25:17 +02:00 |
|
Maiky
|
bf9d0b93d7
|
Add Improper LDAP Auth Query (CWE-287)
|
2023-06-03 23:20:11 +02:00 |
|
github-actions[bot]
|
d2e192020b
|
Post-release preparation for codeql-cli-2.13.3
|
2023-05-24 11:26:12 +00:00 |
|
Chris Smowton
|
99c211955b
|
Hotfix: Go: exclude method receivers from dead-store-of-field query
|
2023-05-23 14:31:25 +01:00 |
|
Chris Smowton
|
8b28848c82
|
Merge pull request #13250 from smowton/smowton/hotfix/golang-field-store-varargs-function
Hotfix: Go: count passing to a vararg function as escaping
|
2023-05-23 12:03:48 +01:00 |
|
Chris Smowton
|
d5d56cde5a
|
Dead store of field: count passing to a vararg function as escaping
|
2023-05-23 10:51:21 +01:00 |
|
github-actions[bot]
|
7aa23cf11d
|
Release preparation for version 2.13.3
|
2023-05-22 20:47:00 +00:00 |
|
Chris Smowton
|
ee64ea59e1
|
Merge pull request #12901 from porcupineyhairs/goDsn
Go: Add query to detect DSN Injection.
|
2023-05-11 22:45:43 +01:00 |
|
Chris Smowton
|
99f4eef9c5
|
Fix spelling
|
2023-05-11 22:12:35 +01:00 |
|
Chris Smowton
|
a10b11e09e
|
Fix spelling and remove dead code
|
2023-05-11 22:12:17 +01:00 |
|
Chris Smowton
|
b6c2db6baf
|
Fix duplicate query ID
|
2023-05-11 22:10:09 +01:00 |
|
Porcupiney Hairs
|
2c518c1fa6
|
Include changes from review
|
2023-05-12 01:59:42 +05:30 |
|
Porcupiney Hairs
|
ae6fda03b7
|
Include changes from review
|
2023-05-11 23:56:50 +05:30 |
|
Porcupiney Hairs
|
d536157c1a
|
Go : Add query to detect potential timing attacks
|
2023-05-11 09:57:50 +05:30 |
|
Owen Mansel-Chan
|
270ba09ffb
|
Merge pull request #11732 from owen-mc/go/fix/model-data-flow-through-varargs
Go: Allow data flow through varargs parameters
|
2023-05-11 05:26:40 +01:00 |
|
Porcupiney Hairs
|
ec424d7e51
|
Go: Add query to detect DSN Injection.
|
2023-05-11 03:45:29 +05:30 |
|
Owen Mansel-Chan
|
1c66564ccc
|
address review comments
|
2023-05-10 14:05:09 +01:00 |
|
Kasper Svendsen
|
46727af948
|
Go: Enable warnings for implicit this receivers
|
2023-05-03 15:41:55 +02:00 |
|
Owen Mansel-Chan
|
3f645e9401
|
Merge pull request #13006 from kaspersv/kaspersv/go-explicit-this-receivers
Go: Make implicit this receivers explicit
|
2023-05-03 13:47:10 +01:00 |
|
Ian Lynagh
|
b56b843d13
|
Merge pull request #12987 from github/post-release-prep/codeql-cli-2.13.1
Post-release preparation for codeql-cli-2.13.1
|
2023-05-03 13:12:10 +01:00 |
|
Kasper Svendsen
|
e969018f99
|
Go: Make implicit this receivers explicit
|
2023-05-03 12:45:42 +02:00 |
|
github-actions[bot]
|
18d4af994d
|
Post-release preparation for codeql-cli-2.13.1
|
2023-05-02 10:50:20 +00:00 |
|
github-actions[bot]
|
3bd29171fb
|
Release preparation for version 2.13.1
|
2023-04-28 12:14:35 +00:00 |
|
Owen Mansel-Chan
|
bc0f9030e3
|
use CallNode.getSyntacticArgument
|
2023-04-28 06:09:10 +01:00 |
|
Michael B. Gale
|
72b082806b
|
Go: Update html-template-escaping-passthrough
Modify this query to apply sanitizers only in the data flow
between untrusted inputs and passthrough conversion types.
|
2023-04-27 17:14:38 +01:00 |
|
Alex Ford
|
924ce250dd
|
Merge pull request #12847 from github/post-release-prep/codeql-cli-2.13.0
Post-release preparation for codeql-cli-2.13.0
|
2023-04-18 14:40:40 +01:00 |
|
Tom Hvitved
|
f6d000eb20
|
Merge pull request #12805 from hvitved/remove-queries-xml
Remove all `queries.xml` files
|
2023-04-18 10:52:14 +02:00 |
|
github-actions[bot]
|
648f0e19ec
|
Post-release preparation for codeql-cli-2.13.0
|
2023-04-17 15:39:24 +00:00 |
|
github-actions[bot]
|
075d063370
|
Release preparation for version 2.13.0
|
2023-04-14 13:31:30 +00:00 |
|
Alex Eyers-Taylor
|
c6a482819a
|
Bump all qlpacks major versions
|
2023-04-13 19:15:27 +01:00 |
|