Owen Mansel-Chan
990913519d
Make comment clearer
2026-06-09 12:20:10 +02:00
Owen Mansel-Chan
e22f9fadd7
Fix mistakes in change notes
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-06-09 12:20:08 +02:00
Owen Mansel-Chan
071a0e3d7d
Add change notes
2026-06-09 12:20:06 +02:00
Owen Mansel-Chan
a92349683e
Deprecate FuncTypeExpr.getResultDecl()
...
It is unused in this library. It could easily be used incorrectly and
silently omit results when `getNumResult() > 1`.
2026-06-09 12:20:04 +02:00
Owen Mansel-Chan
8ce543bf4d
Fix: getNumResult() was wrong in some cases
...
It was the number of result declarations, which is
different from the number of results when one
result declaration declares more than one
variable, as in `x, y int`.
2026-06-09 12:20:02 +02:00
Owen Mansel-Chan
da777a455d
Improve QLDoc
2026-06-09 12:19:58 +02:00
Owen Mansel-Chan
f4f17b01c1
Fix result node and remove SPURIOUS test result
2026-06-09 12:19:56 +02:00
Owen Mansel-Chan
1c47084479
Add result node test with SPURIOUS result
2026-06-09 12:19:51 +02:00
Owen Mansel-Chan
c241049384
Add control flow test for result read steps
2026-06-09 12:19:49 +02:00
Owen Mansel-Chan
8d456df26f
Merge pull request #21960 from github/dependabot/go_modules/go/extractor/extractor-dependencies-28a04969f3
...
Bump golang.org/x/mod from 0.36.0 to 0.37.0 in /go/extractor in the extractor-dependencies group
2026-06-09 05:30:45 +01:00
dependabot[bot]
72fcf27d1a
Bump golang.org/x/mod
...
Bumps the extractor-dependencies group in /go/extractor with 1 update: [golang.org/x/mod](https://github.com/golang/mod ).
Updates `golang.org/x/mod` from 0.36.0 to 0.37.0
- [Commits](https://github.com/golang/mod/compare/v0.36.0...v0.37.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/mod
dependency-version: 0.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: extractor-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-09 03:03:37 +00:00
yoff
0cea01c22f
Merge pull request #21926 from github/yoff/python-simplify-decorator-predicates
...
Python: simplify decorator-detection predicates to pure AST match
2026-06-08 22:04:33 +02:00
Anders Schack-Mulligen
a473565256
Merge pull request #21954 from aschackmull/cfg/consistency-child-idx
...
Cfg: Add consistency check for relevant child indices.
2026-06-08 14:44:20 +02:00
Anders Schack-Mulligen
01173bf383
Cfg: Fold getTryInit into indexed getBody.
2026-06-08 14:03:12 +02:00
BazookaMusic
d0ffde8c45
Em-dash - of course :D
2026-06-08 14:03:12 +02:00
BazookaMusic
b6c951e90c
Remove redundant file
2026-06-08 13:47:44 +02:00
Anders Schack-Mulligen
c47135a40b
Cfg: Add consistency check for relevant child indices.
2026-06-08 13:40:33 +02:00
BazookaMusic
2cb0851900
1. Rename AgentSDK -> AgentSdk
...
2. Remove redundant constant comparison barriers. This is already happening by default by the taint tracking library.
2026-06-08 12:55:52 +02:00
Owen Mansel-Chan
3cbc8f0262
Merge pull request #21951 from github/workflow/go-version-update
...
Go: Update to 1.26.4
2026-06-08 11:47:47 +01:00
BazookaMusic
e370af6444
QLDoc + include the queries in the correct expected files per query suite
2026-06-08 12:38:28 +02:00
BazookaMusic
61be37d718
Formatting
2026-06-08 12:15:50 +02:00
BazookaMusic
da05992a09
Better document the new queries
2026-06-08 11:27:40 +02:00
Tom Hvitved
cc1ea25856
Python: Implement ContentApprox
2026-06-08 08:41:28 +02:00
github-actions[bot]
5a38cbd5d5
Go: Update to 1.26.4
2026-06-08 04:30:10 +00:00
tonghuaroot
e93bc11f6f
Add experimental JS query for SSRF guards missing IPv6-transition unwrap
...
Add javascript/ssrf-ipv6-transition-incomplete-guard, an experimental
@kind problem query that flags hand-rolled SSRF host guards which reject
private/loopback IPv4 ranges but never unwrap IPv6-transition forms
(IPv4-mapped ::ffff:, NAT64 64:ff9b::, 6to4 2002::). Such guards can be
bypassed by wrapping an internal IPv4 address in a transition literal.
Includes a .qhelp with good/bad examples, a change note, and a test pack
with two true-positive fixtures (private-ip package guard and a
hand-written RFC 1918 denylist) and two negative-control fixtures
(ipaddr.js range classifier and an explicit ::ffff: unwrap).
Signed-off-by: tonghuaroot <23011166+tonghuaroot@users.noreply.github.com >
2026-06-06 21:47:24 +08:00
Owen Mansel-Chan
cf6d94cf8a
Merge pull request #21324 from github/copilot/automate-go-version-updates-again
...
Automate Go version updates via scheduled workflow
2026-06-06 03:03:03 +01:00
Owen Mansel-Chan
292fc8b777
Fix detection of failed text replacement
...
I checked and the comment seems to be correct.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-06-06 02:52:21 +01:00
Owen Mansel-Chan
a1759d9834
Use --force-with-lease for slightly improved safety
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-06-06 02:51:36 +01:00
Owen Mansel-Chan
6b74874372
Minor improvement to PR text
2026-06-06 02:32:43 +01:00
copilot-swe-agent[bot]
ef29d22c75
Update Go version workflow to include patch numbers in messages
2026-06-06 01:03:44 +00:00
Henry Mercer
9acf0d6dff
Merge pull request #21946 from github/henrymercer/actions-tweak-query-name
...
Correct query metadata for `actions/untrusted-checkout/medium`
2026-06-05 09:54:27 +01:00
Owen Mansel-Chan
1f91f915c7
Merge pull request #21888 from owen-mc/py/remove-imprecise-container-steps
...
Python: Remove imprecise container steps #2
2026-06-04 22:16:24 +01:00
Jon Janego
ba8eebe2b5
Merge pull request #21948 from github/codeql-spark-run-26974832191
...
Update changelog documentation site for codeql-cli-2.25.6
2026-06-04 14:55:17 -05:00
github-actions[bot]
dc1409e5f4
update codeql documentation
2026-06-04 19:36:45 +00:00
Jon Janego
2a8f295a65
Merge pull request #21947 from github/copilot/codeql-cli-2256
...
Fix changelog copy errors in change-notes and CHANGELOG.md files (codeql-cli-2.25.6)
2026-06-04 14:29:33 -05:00
copilot-swe-agent[bot]
b8501f1ec5
Fix changelog copy errors in change-notes and CHANGELOG.md files (codeql-cli-2.25.6)
2026-06-04 18:35:06 +00:00
copilot-swe-agent[bot]
3214253adb
Initial plan
2026-06-04 18:29:50 +00:00
Henry Mercer
f4dc86e645
Correct query metadata for actions/untrusted-checkout/medium
2026-06-04 19:12:02 +01:00
Mario Campos
284f42bb9e
Merge pull request #21945 from github/codeql-spark-run-26947645690
...
Update changelog documentation site for codeql-cli-2.25.6
2026-06-04 13:09:04 -05:00
Mathias Vorreiter Pedersen
44c8a97e2f
JS: Update test output.
2026-06-04 17:55:09 +01:00
Mathias Vorreiter Pedersen
1d884a3979
QL: Add support for YAML comments.
2026-06-04 17:55:07 +01:00
Mathias Vorreiter Pedersen
8c35e089d8
Unified: Add support for YAML comments.
2026-06-04 17:55:04 +01:00
Mathias Vorreiter Pedersen
e1fde60988
Rust: Add upgrade and downgrade scripts.
2026-06-04 17:55:02 +01:00
Mathias Vorreiter Pedersen
1b29c12049
Rust: Add support for YAML comments.
2026-06-04 17:55:00 +01:00
Mathias Vorreiter Pedersen
d38091fe28
Ruby: Add upgrade and downgrade scripts.
2026-06-04 17:54:57 +01:00
Mathias Vorreiter Pedersen
303cb11609
Ruby: Add support for YAML comments.
2026-06-04 17:54:55 +01:00
Mathias Vorreiter Pedersen
b877943b42
Python: Add upgrade and downgrade scripts.
2026-06-04 17:54:53 +01:00
Mathias Vorreiter Pedersen
0aa1abe432
Python: Add support for YAML comments.
2026-06-04 17:54:48 +01:00
Mathias Vorreiter Pedersen
b6521e7c0e
Actions: Support YAML comments.
2026-06-04 17:54:46 +01:00
Mathias Vorreiter Pedersen
e8f7454ea1
JS: Add tests.
2026-06-04 17:54:42 +01:00