Tony Torralba
|
ad08ccb50b
|
Apply suggestion from code review
|
2021-09-27 12:00:21 +02:00 |
|
mc
|
95751fcc21
|
Update XsltInjection.qhelp
Made a few minor tweaks during editorial review
|
2021-09-27 12:00:21 +02:00 |
|
Tony Torralba
|
13417dbf14
|
Remove DataFlow references from XsltInjection.qll
|
2021-09-27 12:00:20 +02:00 |
|
Tony Torralba
|
ff21662b23
|
Refactor XsltInjection.qll
|
2021-09-27 12:00:18 +02:00 |
|
Tony Torralba
|
6967b06dee
|
Decouple XsltInjection.qll to reuse the taint tracking configuration
|
2021-09-27 11:59:51 +02:00 |
|
Tony Torralba
|
fc58ada92e
|
Add change note
|
2021-09-27 11:58:20 +02:00 |
|
Tony Torralba
|
108118afa3
|
Use InlineExpectationsTest
|
2021-09-27 11:58:18 +02:00 |
|
Tony Torralba
|
d8bb5273e7
|
Refactor to use CSV sink models
|
2021-09-27 11:57:58 +02:00 |
|
Tony Torralba
|
c792567904
|
Move from experimental
|
2021-09-27 11:57:53 +02:00 |
|
Tony Torralba
|
6d9a88d1c8
|
Move to lib
|
2021-09-27 11:43:46 +02:00 |
|
mc
|
3520fed752
|
Update SpelInjection.qhelp
|
2021-09-27 11:40:51 +02:00 |
|
Tony Torralba
|
d10dbbdd9d
|
Apply suggestions from code review
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-09-27 11:40:51 +02:00 |
|
Tony Torralba
|
6bf1e87bbe
|
Remove CSV sinks; make imports private
|
2021-09-27 11:40:47 +02:00 |
|
Tony Torralba
|
91f46624b6
|
Refactor SpelInjection.qll
|
2021-09-27 11:40:26 +02:00 |
|
Tony Torralba
|
94f32d2985
|
Decouple SpelInjection.qll to reuse the taint tracking configuration
|
2021-09-27 11:39:30 +02:00 |
|
Tony Torralba
|
569426b04e
|
Consider subtypes of Expression and ExpressionParser
Add parseRaw as additional taint step
|
2021-09-27 11:38:12 +02:00 |
|
Tony Torralba
|
b0852f6c16
|
Add change note
|
2021-09-27 11:37:46 +02:00 |
|
Tony Torralba
|
b985ddb868
|
Use InlineExpectationsTest
|
2021-09-27 11:37:41 +02:00 |
|
Tony Torralba
|
079769ed2e
|
Refactored SpelInjection.qll to use CSV sink models
|
2021-09-27 11:36:56 +02:00 |
|
Tony Torralba
|
fc6af0476f
|
Moved from experimental
|
2021-09-27 11:36:48 +02:00 |
|
Anders Schack-Mulligen
|
92ffd8c465
|
Merge pull request #6749 from aschackmull/java/istextblock
Java: Add StringLiteral.isTextBlock().
|
2021-09-27 10:54:31 +02:00 |
|
luchua-bc
|
5264936fc3
|
Correct the run method and add Math.min check
|
2021-09-24 21:00:53 +00:00 |
|
alexet
|
49f8f46354
|
Java: Cache params string computation.
|
2021-09-24 14:12:26 +01:00 |
|
Anders Schack-Mulligen
|
854f2a046a
|
Java: Add StringLiteral.isTextBlock().
|
2021-09-24 13:11:18 +02:00 |
|
Benjamin Muskalla
|
70e1724463
|
Exclude methods with non-public parameter types
|
2021-09-24 12:41:12 +02:00 |
|
Benjamin Muskalla
|
38ca5aba98
|
Move test generator into subdirectory
|
2021-09-24 11:13:04 +02:00 |
|
Benjamin Muskalla
|
4e6a8d991e
|
Move stub generator into subdirectory
|
2021-09-24 11:12:41 +02:00 |
|
luchua-bc
|
272e4f6cf9
|
Update the query
|
2021-09-24 01:48:11 +00:00 |
|
github-actions[bot]
|
ceb9a0bd6b
|
Add changed framework coverage reports
|
2021-09-24 00:08:02 +00:00 |
|
luchua-bc
|
2dc38aee54
|
Update qldoc
|
2021-09-23 20:31:24 +00:00 |
|
Anders Schack-Mulligen
|
a031b2a090
|
Merge pull request #6493 from atorralba/atorralba/cleartext-storage-query-refactor
Java: Refactor Cleartext Storage queries
|
2021-09-23 16:31:17 +02:00 |
|
Tony Torralba
|
b52a2cd292
|
Apply code review comments
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-09-23 15:48:15 +02:00 |
|
Anders Schack-Mulligen
|
6be4b3bac6
|
Merge pull request #6725 from emilejq/date-format
Java: Remove requirements for final and access mods from DateFormatThreadUnsafe
|
2021-09-23 15:02:17 +02:00 |
|
Anders Schack-Mulligen
|
4841c3037d
|
Java: Add callback dispatch to more anonymous classes.
|
2021-09-23 14:34:56 +02:00 |
|
Joe Farebrother
|
0919042692
|
Model Bundle and Intent extra methods
|
2021-09-23 12:03:45 +01:00 |
|
Emile El-Qawas
|
83fb41e414
|
Add visibility constraints; Fix non-compliant code
|
2021-09-23 09:55:49 +01:00 |
|
Tony Torralba
|
d0b9920cac
|
Fix encryption sanitizer
It now discards sensitive exprs (sources) instead of sinks for better precision
|
2021-09-23 10:42:30 +02:00 |
|
Tony Torralba
|
51d2b5225e
|
Remove cached property from SensitiveSource::flowsTo
|
2021-09-23 10:42:30 +02:00 |
|
Tony Torralba
|
563e8a2bd6
|
Remove unused library
|
2021-09-23 10:42:30 +02:00 |
|
Tony Torralba
|
a30554e97c
|
Refactored cleartext storage libraries
|
2021-09-23 10:42:30 +02:00 |
|
Chris Smowton
|
93daaf5b5b
|
Merge pull request #6174 from joefarebrother/guava-collections
Java: Model Guava collections package
|
2021-09-23 09:13:24 +01:00 |
|
Chris Smowton
|
3123abfac3
|
Merge pull request #6711 from bananabr/AndroidLoggingFix
Fix Android logging signature
|
2021-09-22 17:23:04 +01:00 |
|
Joe Farebrother
|
522c6e01d2
|
Sort models by class and name
|
2021-09-22 15:23:01 +01:00 |
|
Chris Smowton
|
24e3ad4e18
|
Remove unnecessary type constraint
|
2021-09-22 10:54:24 +01:00 |
|
Joe Farebrother
|
3cd675bfff
|
Manually fill in most of the remaining support method calls
|
2021-09-21 17:56:18 +01:00 |
|
Emile El-Qawas
|
dcae1c5c04
|
DateFormatThreadUnsafe - Remove requirements for final and access modifiers
|
2021-09-21 16:50:48 +01:00 |
|
Joe Farebrother
|
6e9bee1be7
|
Add missing models
|
2021-09-21 16:32:49 +01:00 |
|
Joe Farebrother
|
25d6e00b1a
|
Implement gen methods for MapDifference
|
2021-09-21 16:30:12 +01:00 |
|
Joe Farebrother
|
a47897bdf9
|
Implement Table gen methods
|
2021-09-21 15:29:06 +01:00 |
|
Anders Schack-Mulligen
|
2c41de6648
|
Merge pull request #6720 from aschackmull/java/isunreachableincall-joinorder
Java: Fix join-order in isUnreachableInCall.
|
2021-09-21 16:07:42 +02:00 |
|