yo-h
|
eedc385b37
|
Java 15: adjust test options
|
2020-11-26 00:14:24 -05:00 |
|
Anders Schack-Mulligen
|
89361a3b75
|
Merge pull request #3812 from luchua-bc/java-android-remote-source
Java: Add remote source of Android intent extra
|
2020-11-03 09:35:40 +01:00 |
|
luchua-bc
|
864411b4b9
|
Updates to Android stub classes
|
2020-11-02 14:06:44 +00:00 |
|
luchua-bc
|
8da9b9d3ea
|
Add documentation to new library method and use the singular form
|
2020-11-02 10:53:46 +00:00 |
|
luchua-bc
|
7ac3fb41d5
|
Clean up query and test files
|
2020-10-31 13:37:36 +00:00 |
|
Anders Schack-Mulligen
|
0d926dcf70
|
Java: Tweak qhelp to make it markdown-compatible.
|
2020-10-29 14:39:01 +01:00 |
|
luchua-bc
|
b1d6bc5ba9
|
Use getDeclaringType() for getIntent() method call
|
2020-10-29 12:55:03 +00:00 |
|
luchua-bc
|
2ee9a45e69
|
Use proper class inheritance
|
2020-10-28 22:05:30 +00:00 |
|
Anders Schack-Mulligen
|
f3e2bd0fd9
|
Merge pull request #3141 from pwntester/InsecureBeanValidation
Insecure Bean Validation query
|
2020-10-28 12:04:12 +01:00 |
|
Anders Schack-Mulligen
|
34ae6e0576
|
Apply suggestions from code review
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-28 09:15:08 +01:00 |
|
luchua-bc
|
3cc3fe9d37
|
Switch to TaintPreservingCallable and add test cases
|
2020-10-28 00:33:07 +00:00 |
|
Alvaro Muñoz
|
77b551b693
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:12:17 +01:00 |
|
Alvaro Muñoz
|
b9c75ea462
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:12:00 +01:00 |
|
Alvaro Muñoz
|
ac116da0dc
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:48 +01:00 |
|
Alvaro Muñoz
|
d5b470ea0c
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:27 +01:00 |
|
Alvaro Muñoz
|
9785013c29
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:15 +01:00 |
|
Alvaro Muñoz
|
d221930c81
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:10:56 +01:00 |
|
Alvaro Muñoz
|
1fdf0556d2
|
more fixes to make qlhelp linter happy
|
2020-10-27 17:05:00 +01:00 |
|
Alvaro Muñoz
|
aa981caea5
|
more fixes to make qlhelp linter happy
|
2020-10-27 16:32:13 +01:00 |
|
Alvaro Muñoz
|
8974f252ac
|
fix format and qlhelp errors blocking the merge
|
2020-10-27 16:19:39 +01:00 |
|
Alvaro Muñoz
|
11e57bd2f8
|
add change note for new Insecure Bean Validation query
|
2020-10-27 16:11:51 +01:00 |
|
Alvaro Muñoz
|
3378dd526e
|
remove compiled classes from stubs
|
2020-10-27 15:56:26 +01:00 |
|
Alvaro Muñoz
|
99044fc6ab
|
remove experimental query forr bean validation
|
2020-10-27 15:55:19 +01:00 |
|
Alvaro Muñoz
|
40a2007497
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:52:25 +01:00 |
|
Alvaro Muñoz
|
8b5aed2fe1
|
move md links to <a>
|
2020-10-27 15:52:25 +01:00 |
|
Alvaro Muñoz
|
8904411fe6
|
address review comments
|
2020-10-27 15:52:24 +01:00 |
|
Alvaro Muñoz
|
debfc686d1
|
Insecure Bean Validation query
|
2020-10-27 15:52:24 +01:00 |
|
Alvaro Muñoz
|
7d7933a054
|
move query out of experimental
|
2020-10-27 15:52:20 +01:00 |
|
Alvaro Muñoz
|
d990f7a470
|
move md links to <a>
|
2020-10-27 15:51:40 +01:00 |
|
Alvaro Muñoz
|
65d01f5c9e
|
address review comments
|
2020-10-27 15:51:36 +01:00 |
|
Alvaro Muñoz
|
f85778e9c7
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
6ca28a8bc6
|
move md links to <a>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
27bd9044e7
|
address review comments
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
73fc9fda77
|
Insecure Bean Validation query
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
a36970f306
|
Add beanValidation remote source
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
3dcd8acf97
|
add expected results
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
671ea2f6c6
|
add test and stubs
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
a274a1516a
|
move source to FlowSources.qll
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
2bab9d22e9
|
move query out of experimental
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
df4164f2c0
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
c1decf4d0d
|
move md links to <a>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
0bf3895327
|
address review comments
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
3b23cd5be3
|
Insecure Bean Validation query
|
2020-10-27 15:47:54 +01:00 |
|
Chris Smowton
|
3f298f3dc8
|
Add basic tests for Android intents as flow sources
|
2020-10-27 12:03:05 +00:00 |
|
Chris Smowton
|
54c1480fd6
|
Replace explicit extra step with TaintPreservingCallable
|
2020-10-27 12:02:29 +00:00 |
|
Chris Smowton
|
60e8910330
|
Follow taint across getExtras without qualifier
|
2020-10-27 12:01:30 +00:00 |
|
Joe Farebrother
|
2050f82553
|
Merge pull request #4383 from joefarebrother/guava-strings
Java: Add modelling for Guava
|
2020-10-26 10:16:55 +00:00 |
|
Tom Hvitved
|
492b1141ef
|
Merge pull request #4445 from hvitved/csharp/sign-analysis-cfg
C#: Use CFG nodes instead of AST nodes in sign/modulus analysis
|
2020-10-26 09:45:38 +01:00 |
|
luchua-bc
|
9ae5689af6
|
Use AndroidIntentInput source
|
2020-10-24 11:55:00 +00:00 |
|
luchua-bc
|
f5f7259937
|
Revamp the query to implement AdditionalTaintStep
|
2020-10-23 12:00:36 +01:00 |
|