Tom Hvitved
b582844f96
Merge pull request #22049 from hvitved/csharp/dead-store-cleanup
...
C#: Remove redundant code from `DeadStoreOfLocal.ql`
2026-06-25 13:51:21 +02:00
Geoffrey White
b9a132dac6
Rust: Remove redundant cast.
2026-06-25 12:51:18 +01:00
Geoffrey White
351d4954d7
Rust: Change note.
2026-06-25 12:26:40 +01:00
Geoffrey White
4bda03fe8d
Rust: Make arithmetic operations a barrier for rust/hard-coded-cryptographic-value (including string concatenation).
2026-06-25 12:19:08 +01:00
Asger F
89cd6770ae
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-06-25 13:18:27 +02:00
Jeroen Ketema
9b2e6077f1
Kotlin: Address review comments
2026-06-25 12:58:27 +02:00
Michael Nebel
18913ce4b8
C#: Add change-note.
2026-06-25 11:50:49 +02:00
Michael Nebel
a45ef5845a
C#: Address review comments.
2026-06-25 11:50:47 +02:00
Michael Nebel
d32c4d838d
C#: Make the NuGetExeWrapper respect the CheckFeeds flag, private registries configuration and provide sources via the command line instead of creating a file.
2026-06-25 11:50:44 +02:00
Michael Nebel
8042fba94a
C#: Inject the feed manager into the NugetExeWrapper.
2026-06-25 11:50:42 +02:00
Michael Nebel
bbad4f6069
C#: Take a the feed logic out of the try/catch for NuGet downloading.
2026-06-25 11:50:40 +02:00
Tom Hvitved
929fa1e977
C#: Remove redundant code from DeadStoreOfLocal.ql
2026-06-25 08:50:40 +02:00
Mario Campos
3324d07985
Merge pull request #22046 from github/mario-campos/mirror-maven-central/maven
...
Use Maven Central mirror in Java Maven integration tests
2026-06-24 16:42:29 -05:00
Jeroen Ketema
f6b3d1eade
Kotlin: Remove unneeded pytest imports
2026-06-24 23:34:39 +02:00
Jeroen Ketema
402c0f89bc
Kotlin: Update tests to use new kotlin_2_3_20 fixture
2026-06-24 22:50:32 +02:00
Mario Campos
af11f6e618
Use Maven Central mirror in Java Maven integration tests
2026-06-24 17:45:27 +00:00
Jaroslav Lobačevski
7fc4b4856e
Fix formatting
2026-06-24 17:17:16 +00:00
Paolo Tranquilli
4b8cb3ffac
Fix false negative for branching nested reusable workflows
...
The previous fix required all outermost callers of a reusable workflow to
be protected, which collapsed distinct safe/unsafe inner paths that share
the same outermost caller. Track protection per caller chain instead: a
node inside a reusable workflow is only considered protected if there is
no unprotected caller path up to an outer workflow.
Adds a branching nested regression test where one inner job is protected
by a permission check and a sibling inner job is not.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-06-24 18:22:01 +02:00
Geoffrey White
0c72a2b982
Add test cases involving string appends.
2026-06-24 17:09:27 +01:00
Jeroen Ketema
b8c78fdcb7
Merge pull request #21970 from github/andersfugmann/kotlin-2.4-v2
...
Kotlin: add Kotlin 2.4.0 support
2026-06-24 16:40:40 +02:00
Anders Schack-Mulligen
bcf71d0db6
Merge pull request #22043 from github/copilot/tweak-ruby-ast-caseexpr
...
Ruby: synthesize implicit `true` value for valueless `CaseExpr`
2026-06-24 15:43:04 +02:00
Anders Schack-Mulligen
5047bee432
Ruby: Adjust qldoc.
2026-06-24 13:36:54 +02:00
Anders Schack-Mulligen
29eba2f38e
Merge pull request #22017 from aschackmull/cfg/catchclause-pattern
...
Cfg: Change AST/CFG for CatchClauses to use a pattern.
2026-06-24 13:21:54 +02:00
copilot-swe-agent[bot]
4fa8a9fb1d
Synthesize true value for valueless Ruby CaseExpr
2026-06-24 10:36:23 +00:00
Michael Nebel
a24d222d96
Merge pull request #22011 from michaelnebel/csharp/removeafallback
...
C#: Re-factor feed handling logic into its own component.
2026-06-24 11:58:56 +02:00
Anders Schack-Mulligen
bcfee987f0
Apply suggestion from @aschackmull
2026-06-24 10:26:26 +02:00
Mathias Vorreiter Pedersen
933338f627
C++: Accept test changes.
2026-06-23 20:33:34 +01:00
Mathias Vorreiter Pedersen
662f522032
C++: Properly instantiate the new reverse flow feature.
2026-06-23 20:33:31 +01:00
Mathias Vorreiter Pedersen
a4e3761dea
Swift: Fixes after changes to the flow summary API.
2026-06-23 20:33:29 +01:00
Mathias Vorreiter Pedersen
8129107ebf
Rust: Fixes after changes to the flow summary API.
2026-06-23 20:33:26 +01:00
Mathias Vorreiter Pedersen
09c7329488
Ruby: Fixes after changes to the flow summary API.
2026-06-23 20:33:24 +01:00
Mathias Vorreiter Pedersen
f9e1305da3
Python: Fixes after changes to the flow summary API.
2026-06-23 20:33:22 +01:00
Mathias Vorreiter Pedersen
be56df7ad1
JS: Fixes after changes to the flow summary API.
2026-06-23 20:33:19 +01:00
Mathias Vorreiter Pedersen
9865b66308
Java: Fixes after changes to the flow summary API.
2026-06-23 20:33:17 +01:00
Mathias Vorreiter Pedersen
e8fee23093
Go: Fixes after changes to the flow summary API.
2026-06-23 20:33:14 +01:00
Mathias Vorreiter Pedersen
bf50e377c5
C#: Fixes after changes to the flow summary API.
2026-06-23 20:33:10 +01:00
Mathias Vorreiter Pedersen
076b01cbfc
C++: Fixes after changes to the flow summary API.
2026-06-23 20:33:08 +01:00
Mathias Vorreiter Pedersen
bb2ec1240a
Shared: Support "reverse flow" summaries. That is, summaries starting from the return value of a call.
2026-06-23 20:33:04 +01:00
Mathias Vorreiter Pedersen
03c3ef9528
C++: Add tests with missing reverse flow.
2026-06-23 19:48:21 +01:00
Anders Schack-Mulligen
e1d4fe8605
C#: Accept test changes.
2026-06-23 14:42:20 +02:00
Anders Schack-Mulligen
11725e8921
Java: Accept test changes.
2026-06-23 14:28:44 +02:00
Anders Schack-Mulligen
41297c588c
Cfg: Change AST/CFG for CatchClauses to use a pattern.
2026-06-23 14:28:44 +02:00
yoff
53cae687f7
Merge pull request #21931 from github/yoff/python-shared-cfg-loop-else
...
Shared CFG: add defaulted getWhileElse/getForeachElse to AstSig
2026-06-23 14:25:16 +02:00
Anders Schack-Mulligen
cfbf4a3927
Merge pull request #22037 from github/copilot/update-csharp-extractor-catch-clause
...
C# extractor: extract `catch(ExceptionType)` type as `TypeAccess` instead of `TypeMention`
2026-06-23 14:21:43 +02:00
Jaroslav Lobačevski
31f6e713c5
Fix "The variable event is only used in one side of disjunct."
2026-06-23 12:06:01 +00:00
copilot-swe-agent[bot]
b254aa7e0b
C#: Extract catch(Ex) type as TypeAccess instead of TypeMention
2026-06-23 13:55:39 +02:00
Jaroslav Lobačevski
e2347a5c7d
Fix for independent checks
2026-06-23 11:52:11 +00:00
yoff
d26102b263
Merge pull request #21920 from github/yoff/python-flow-py-namespace
...
Python: qualify Flow.qll's AST references with Py:: prefix
2026-06-23 13:20:26 +02:00
yoff
73ab3e6888
Update shared/controlflow/codeql/controlflow/ControlFlowGraph.qll
...
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com >
2026-06-23 12:41:02 +02:00
yoff
15cbbb82eb
Shared CFG: add defaulted getLoopElse to AstSig
...
Adds a new defaulted signature predicates to the shared CFG library:
- getLoopElse: `else` block of a loop statement, if
any (used by Python's `while-else` / `for-else` constructs).
The predicate defaults to `none()`, so behaviour is unchanged for any
language that doesn't override it (verified by re-running
java/ql/test/library-tests/controlflow/).
The Make0 succession rules are extended:
- WhileStmt/ForeachStmt: route the loop-exit edge through the else
block before reaching the after-position.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-06-23 12:41:02 +02:00