Rasmus Wriedt Larsen
|
1ab04a7276
|
Python: Model Connection.execution_options
|
2021-09-02 10:19:57 +02:00 |
|
Rasmus Wriedt Larsen
|
2acf518037
|
Python: Model exec_driver_sql
|
2021-09-02 10:19:57 +02:00 |
|
Rasmus Wriedt Larsen
|
fe143c7dfa
|
Python: Rewrite most of SQLAlchemy modeling
|
2021-09-02 10:19:57 +02:00 |
|
Rasmus Wriedt Larsen
|
b39bb24fcf
|
Python: Add more SQLAlchemy tests
|
2021-09-02 10:19:57 +02:00 |
|
Rasmus Lerchedahl Petersen
|
a01fca5d48
|
Merge branch 'main' of github.com:github/codeql into python-regex-parsing-consistency-checks
To fix conflicts
|
2021-08-30 18:40:12 +02:00 |
|
Rasmus Lerchedahl Petersen
|
a855074588
|
Python: Try to remove py2/3 differences
|
2021-08-30 15:41:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
a762373ad6
|
Python: Implement simple barrier guard
The one found in the original test case
|
2021-08-30 11:04:27 +02:00 |
|
jorgectf
|
64b305cf7a
|
Add .qhelp along with its example
|
2021-08-26 23:29:45 +02:00 |
|
Rasmus Lerchedahl Petersen
|
49ae549e89
|
Python: Implement modifying syntax
|
2021-08-26 14:29:18 +02:00 |
|
Rasmus Lerchedahl Petersen
|
097c23e437
|
Python: add inline expectations test
Consider removing the original test
|
2021-08-26 14:08:52 +02:00 |
|
Rasmus Wriedt Larsen
|
47377c7197
|
Merge branch 'main' into more-modeling
|
2021-08-26 13:40:17 +02:00 |
|
jorgectf
|
786edb72df
|
Update .expected
|
2021-08-26 12:36:34 +02:00 |
|
Rasmus Lerchedahl Petersen
|
d834cec9b9
|
Python: test simple sanitizer
|
2021-08-26 11:31:20 +02:00 |
|
Rasmus Lerchedahl Petersen
|
8614563b42
|
Python: More tests of syntactic constructs
|
2021-08-26 10:56:41 +02:00 |
|
Andrew Eisenberg
|
3660c64328
|
Packaging: Rafactor Python core libraries
Extract the external facing `qll` files into the codeql/python-all
query pack.
|
2021-08-24 13:23:45 -07:00 |
|
yoff
|
2f5ed03798
|
Merge pull request #6323 from RasmusWL/sec-test-layout
Python: Restructure security tests to contain query name
|
2021-08-24 16:50:08 +02:00 |
|
Rasmus Lerchedahl Petersen
|
e865a290de
|
Python: straight port of query
The old query uses `pointsTo` to limit the sinks
to methods on lists and dictionaries.
That constraint is omitted here which could hurt performance.
|
2021-08-24 16:35:11 +02:00 |
|
Rasmus Lerchedahl Petersen
|
e3765ced78
|
Python: Add tests for modification of defaults
|
2021-08-24 16:35:11 +02:00 |
|
Rasmus Wriedt Larsen
|
ca341bde08
|
Merge pull request #5612 from jty-team/jty/python/nosqlInjection
Python: CWE-943 - Add NoSQL injection query
|
2021-08-24 11:29:25 +02:00 |
|
Rasmus Lerchedahl Petersen
|
c4554836ca
|
Python: merge test.py into unittests.py
|
2021-08-19 10:24:32 +02:00 |
|
Rasmus Wriedt Larsen
|
b649f5f38c
|
Merge branch 'main' into peewee-modeling
|
2021-08-17 12:03:18 +02:00 |
|
Rasmus Lerchedahl Petersen
|
dee5535fbb
|
Python: condense tests
This also avoids potential licensing issues.
|
2021-08-17 11:24:39 +02:00 |
|
Erik Krogh Kristensen
|
46959234b7
|
Merge pull request #6288 from erik-krogh/emptyRedos
JS/Python: Fix FP in redos related to empty lookaheads
|
2021-08-16 13:48:22 +02:00 |
|
Rasmus Lerchedahl Petersen
|
54e65ce765
|
Python: Add consistency tests
for all the projects that went out of disk as a result of ReDoS
|
2021-08-12 13:33:44 +02:00 |
|
Rasmus Lerchedahl Petersen
|
c08f94ec04
|
Python: Fix parsing of octal escapes
|
2021-08-11 15:01:26 +02:00 |
|
Rasmus Lerchedahl Petersen
|
34b054ff53
|
Python: Add consistency checks
|
2021-08-11 14:58:27 +02:00 |
|
jorgectf
|
e6ce10b5c5
|
Merge remote-tracking branch 'origin/main' into jty/python/nosqlInjection
|
2021-08-10 20:01:08 +02:00 |
|
jorgectf
|
f9b244ecad
|
Polish documentation
|
2021-07-24 01:06:05 +02:00 |
|
Jorge
|
f02b6d60a5
|
Merge branch 'github:main' into jorgectf/python/ldapinsecureauth
|
2021-07-22 18:49:51 +02:00 |
|
jorgectf
|
b03e75e3d1
|
Extend ldap3's start_tls and fix tests
|
2021-07-22 18:42:41 +02:00 |
|
jorgectf
|
a34d6d390e
|
Port to ApiGraphs and finish the query
|
2021-07-22 18:34:57 +02:00 |
|
Rasmus Wriedt Larsen
|
71e6db8a01
|
Merge branch 'main' into jorgectf/python/ldapimproperauth
|
2021-07-22 15:57:43 +02:00 |
|
Rasmus Wriedt Larsen
|
802d9bda83
|
Merge pull request #5680 from mrthankyou/python-use-sqlalchemy
Python: Add SqlAlchemy model
|
2021-07-22 15:31:39 +02:00 |
|
Rasmus Wriedt Larsen
|
38875ca0c7
|
Python: Improve handling of async methods
|
2021-07-22 14:17:07 +02:00 |
|
Rasmus Wriedt Larsen
|
6e9d9fcbbd
|
Python: Improve taint steps in for & iterable unpacking
These were written way before the ones in DataFlowPrivate, but
apparently didn't cover quite as much :|
|
2021-07-22 14:16:17 +02:00 |
|
Taus
|
e9a4114c04
|
Python: Hotfix: Disable ReDoS queries
|
2021-07-22 10:58:49 +00:00 |
|
Rasmus Wriedt Larsen
|
d3163d8a76
|
Python: Add iterable-unpacking in for test
|
2021-07-22 11:59:46 +02:00 |
|
Rasmus Wriedt Larsen
|
e2d3fa7093
|
Python: Add list-comprehension taint test
|
2021-07-22 11:59:46 +02:00 |
|
Rasmus Wriedt Larsen
|
6f63c03558
|
Python: Model http.cookies.Morsel and usage in Tornado
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
7e09a1cbfd
|
Python: Model tornado.httputil.HTTPHeaders
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
7020e4132b
|
Python: Model BaseHTTPRequestHandler.rfile as file-like object
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
d388dd547e
|
Python: Model HTTPMessage from Stdlib
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
dac71ded9d
|
Python: Add Authorization modeling in Flask
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
133632119d
|
Python: Model werkzeug Headers
Also removed a misleading comment link to method on wrong class :D
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
4d9c86a252
|
Python: Model Werkzeug FileStorage.save as FileSystemAccess
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
9cb4899c5c
|
Python: Add FileStorage modeling in Flask
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
04190ea308
|
Python: Add file-like modeling to werkzeug FileStorage
|
2021-07-22 10:43:18 +02:00 |
|
Rasmus Wriedt Larsen
|
4f4dec50f2
|
Python: Model ResovlerMatch in Django
Like before, omitted ClassInstantiation
|
2021-07-22 10:43:13 +02:00 |
|
jorgectf
|
68f79f054b
|
Update .expected
|
2021-07-21 21:32:08 +02:00 |
|
jorgectf
|
8d84d63b94
|
Add Python-Jose modeling and tests
|
2021-07-21 21:31:53 +02:00 |
|