calumgrant
f2663d43aa
Merge pull request #311 from hvitved/mergeback-2018-10-11
...
Merge master into next
2018-10-11 14:40:33 +01:00
Tom Hvitved
b29b314f4e
Merge remote-tracking branch 'upstream/master' into mergeback-2018-10-11
2018-10-11 14:36:44 +02:00
Tom Hvitved
98db3f89c2
C#: Extend pre-SSA consistency tests
2018-10-11 13:59:06 +02:00
Tom Hvitved
68dae60927
Merge pull request #295 from calumgrant/cs/extractor/open-source
...
C#: Open-source extractor
2018-10-11 13:57:16 +02:00
Asger F
da3e960e39
JS: address review comments
2018-10-11 12:45:45 +01:00
Tom Hvitved
cc14328be5
C#: Add change note
2018-10-11 13:20:24 +02:00
Felicity Chapman
e2629728ba
Merge pull request #235 from jbj/hresult-boolean-qhelp
...
C++: Finalise docs for cpp/hresult-boolean-conversion and cpp/unsafe-dacl-security-descriptor
2018-10-11 11:02:17 +01:00
Anders Schack-Mulligen
73f1beecfd
Java: Fix likely bug in ExposeRepresentation and re-autoformat.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
6a8a27201e
Java: Autoformat ExposeRepresentation, revealing likely bug.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
236c79b561
Java: Adjust comment position and re-autoformat.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
c16f0df823
Java: Autoformat 1.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
e291b5ec2b
Java: Break line and re-autoformat.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
62e942bb8b
Java: Autoformat 1.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
62ef811169
Java: Autoformat.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
766b07ba59
Java: Adjust comment style.
2018-10-11 11:31:38 +02:00
Anders Schack-Mulligen
dd5a8f0c14
Java: Autoformat most queries.
2018-10-11 11:31:37 +02:00
calum
a06c8bd2f5
C#: Address review comments.
2018-10-11 10:28:34 +01:00
Anders Schack-Mulligen
1a66f7e249
Java: Add change note.
2018-10-11 11:27:53 +02:00
Anders Schack-Mulligen
ca8ca55828
Java: Deprecate ParityAnalysis.
2018-10-11 11:26:17 +02:00
Anders Schack-Mulligen
5c53249612
Java: Add ModulusAnalysis.
2018-10-11 11:26:17 +02:00
Anders Schack-Mulligen
e7b0d399d1
Java: Refactor parts of RangeAnalysis needed for ModulusAnalysis.
2018-10-11 11:26:17 +02:00
Anders Schack-Mulligen
a78a0b52ec
Java: Add test.
2018-10-11 11:26:17 +02:00
Anders Schack-Mulligen
8659bedbd9
Java: Extract Bound class to its own file.
2018-10-11 11:26:17 +02:00
Anders Schack-Mulligen
6dfbb72fc8
Java: Add constant array lengths to ConstantIntegerExpr.
2018-10-11 11:26:16 +02:00
Anders Schack-Mulligen
85cca69721
Merge pull request #220 from yh-semmle/java/update-tests
...
Java: refine `java/unreachable-catch-clause`
2018-10-11 11:12:15 +02:00
Anders Schack-Mulligen
fc359b75d3
Java: Add qldoc to a few libraries.
2018-10-11 11:05:39 +02:00
Max Schaefer
cd284b2f97
JavaScript: Add support for Google Cloud Spanner.
2018-10-11 09:30:39 +01:00
semmle-qlci
6a03bd8f5c
Merge pull request #300 from esben-semmle/js/http-file-access-polish
...
Approved by asger-semmle
2018-10-11 09:00:00 +01:00
yh-semmle
c1473f5425
Java: add query ID in change note for java/unreachable-catch-clause
2018-10-10 19:16:57 -04:00
Asger F
9b10254cd4
JS: support label-specific sanitizer guards
2018-10-10 18:27:14 +01:00
calumgrant
e6e4502cdb
Merge pull request #148 from aschackmull/docs/ql-style-guide
...
QL style guide: Clarify some outstanding issues
2018-10-10 18:22:05 +01:00
Asger F
5e720486d5
JS: recognize req.query.x as deep object taint
2018-10-10 17:15:56 +01:00
Asger F
d72d7345b8
JS: make NosqlInjection use object taint
2018-10-10 17:05:59 +01:00
Asger F
b70f70f722
JS: Add TaintedObject flow label library
2018-10-10 17:05:59 +01:00
Asger F
396ad336a3
JS: add RemoteFlowSource.isDeepObject() and populate it
2018-10-10 17:05:59 +01:00
Asger F
46b2015065
JS: fix an outdated comment
2018-10-10 17:05:59 +01:00
Asger F
03b479114f
JS: preserve document.url label out of .href property
2018-10-10 17:05:59 +01:00
Asger F
ea297dd442
JS: bugfix in handling of custom flow labels
2018-10-10 16:06:44 +01:00
Jonas Jensen
a10c3bcffb
C++: Suppress UnsignedGEZero in template inst.
...
It still runs on uninstantiated templates because its underlying
libraries do. It's not clear whether that leads to other false
positives, but that's independent of the change I'm making here.
2018-10-10 17:06:24 +02:00
Jonas Jensen
383dafac5c
C++: Test for UnsignedGEZero with templates
2018-10-10 17:04:35 +02:00
Anders Schack-Mulligen
99846474eb
QL style guide: Adjust style rules for if-then-else.
2018-10-10 16:42:34 +02:00
Anders Schack-Mulligen
31e1706c98
QL style guide: Address some review comments.
2018-10-10 16:42:34 +02:00
Anders Schack-Mulligen
6feb1d0766
QL style guide: Clarify some outstanding issues.
2018-10-10 16:42:34 +02:00
Esben Sparre Andreasen
6687dfd558
JS: improve model of express' req.sendFile
2018-10-10 15:46:43 +02:00
calum
518c901ddc
C#: Merge latest changes.
2018-10-10 14:40:52 +01:00
calum
103d140e71
C#: Migrate extractor to this repository.
2018-10-10 14:40:52 +01:00
Esben Sparre Andreasen
358b6c3413
JS: change "remote request" to "network request"
2018-10-10 15:34:39 +02:00
Esben Sparre Andreasen
e93545d16e
JS: address more review comments
2018-10-10 15:28:42 +02:00
Jonas Jensen
3e022ad36f
Merge pull request #270 from geoffw0/negindex
...
CPP: Improvements to Buffer.qll
2018-10-10 14:59:41 +02:00
Esben Sparre Andreasen
c885490c7e
JS: address review comments
2018-10-10 12:18:30 +02:00