Benjamin Muskalla
|
060862ab3b
|
Avoid certain test sources in models
|
2021-11-10 16:30:21 +01:00 |
|
Benjamin Muskalla
|
e607953b9c
|
Simplify query
|
2021-11-10 16:30:21 +01:00 |
|
Benjamin Muskalla
|
9a859334d4
|
Formatting
|
2021-11-10 16:30:21 +01:00 |
|
Benjamin Muskalla
|
6c59333716
|
Remove workaround that accounted for missing flow
|
2021-11-10 16:30:21 +01:00 |
|
Benjamin Muskalla
|
7dae6122d9
|
Support CharSequence#toString
Given CharSequence is often used as an
alias for String, ensure taint through toString is flowing
|
2021-11-10 16:30:20 +01:00 |
|
Benjamin Muskalla
|
ca9d5439f0
|
Restrict source configuration to return nodes
|
2021-11-10 16:30:20 +01:00 |
|
Benjamin Muskalla
|
7a7ec06819
|
Simplify sink configuration
|
2021-11-10 16:30:20 +01:00 |
|
Benjamin Muskalla
|
1a4fd7bc7d
|
Allow camelcase names
|
2021-11-10 16:30:20 +01:00 |
|
Benjamin Muskalla
|
2b2ac82fb7
|
Fix bug in sink detection
|
2021-11-10 16:30:20 +01:00 |
|
Benjamin Muskalla
|
c616eb1473
|
Fix finding more sources
|
2021-11-10 16:30:19 +01:00 |
|
Benjamin Muskalla
|
38579ef25b
|
Add proper metadata to queries
|
2021-11-10 16:30:19 +01:00 |
|
Benjamin Muskalla
|
a80d50cbc0
|
Simplify field flow
|
2021-11-10 16:30:19 +01:00 |
|
Benjamin Muskalla
|
a1d8dfb524
|
Initial support for source models
|
2021-11-10 16:30:19 +01:00 |
|
Benjamin Muskalla
|
c844f5382f
|
Add script to generate flow models
|
2021-11-10 16:30:19 +01:00 |
|
Benjamin Muskalla
|
f9fea15a52
|
Initial support for capturing sink models
|
2021-11-10 16:30:18 +01:00 |
|
Benjamin Muskalla
|
364de55b8d
|
Support parameter->parameter flow
|
2021-11-10 16:30:18 +01:00 |
|
Benjamin Muskalla
|
cd11ef3bf6
|
Support outgoing taint flow from fields
|
2021-11-10 16:30:18 +01:00 |
|
Benjamin Muskalla
|
c3462be2c9
|
Capture argument->return value flows
|
2021-11-10 16:30:18 +01:00 |
|
Benjamin Muskalla
|
4ca006ba3d
|
Only expose visible innner classes
|
2021-11-10 16:30:18 +01:00 |
|
Benjamin Muskalla
|
88032afdc3
|
Add test for final class
|
2021-11-10 16:30:17 +01:00 |
|
Benjamin Muskalla
|
ec772fb6b2
|
Add support for qualifier flow
|
2021-11-10 16:30:17 +01:00 |
|
Benjamin Muskalla
|
32ef40c77b
|
Add scaffolding for summary model generator
|
2021-11-10 16:30:17 +01:00 |
|
Mathias Vorreiter Pedersen
|
e0b876d2f6
|
Merge pull request #7102 from MathiasVP/fix-map-test
C++: Fix a testcase
|
2021-11-10 13:51:10 +00:00 |
|
Mathias Vorreiter Pedersen
|
ccdaf49464
|
C++: Fix the same bug in the test for ordered maps.
|
2021-11-10 13:24:27 +00:00 |
|
Mathias Vorreiter Pedersen
|
86d78b34aa
|
C++: Use the correct variable in the 'test'.
|
2021-11-10 13:04:48 +00:00 |
|
Rasmus Wriedt Larsen
|
de926dc2a1
|
Merge pull request #7085 from yoff/python/model-aiopg
Python: model aiopg
|
2021-11-10 13:10:30 +01:00 |
|
Benjamin Muskalla
|
0f086056a1
|
Merge pull request #7100 from bmuskalla/bmuskalla/ioAsFile
Java: Extract Commons IO into seperate file
|
2021-11-10 12:04:12 +01:00 |
|
Rasmus Lerchedahl Petersen
|
92a7114b72
|
Python: Add API references
|
2021-11-10 11:06:58 +01:00 |
|
Rasmus Lerchedahl Petersen
|
c6d285dd2a
|
Python: Fix test
|
2021-11-10 11:06:45 +01:00 |
|
yoff
|
a856395d56
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-11-10 10:51:40 +01:00 |
|
Benjamin Muskalla
|
f9fa22c14d
|
Removed unused import
|
2021-11-10 10:21:54 +01:00 |
|
Benjamin Muskalla
|
1a751608de
|
Extract Commons IO into seperate file
|
2021-11-10 10:15:27 +01:00 |
|
Tony Torralba
|
4da1dce811
|
Merge pull request #7099 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-11-10 08:54:11 +01:00 |
|
github-actions[bot]
|
f5426336c3
|
Add changed framework coverage reports
|
2021-11-10 00:09:06 +00:00 |
|
Tom Hvitved
|
8195ebf4b3
|
Merge pull request #7059 from hvitved/ruby/basic-store-step-postupdate
Ruby: Fix `basicStoreStep`
|
2021-11-09 15:16:07 +01:00 |
|
Benjamin Muskalla
|
40e47c0ea3
|
Merge pull request #7082 from bmuskalla/filterOutputStream
Java: Model taint for `FilterOutputStream`
|
2021-11-09 15:06:15 +01:00 |
|
Benjamin Muskalla
|
bfe2e2e0b9
|
Model taint for FilterOutputStream
|
2021-11-09 14:21:50 +01:00 |
|
Rasmus Wriedt Larsen
|
1e31416049
|
Merge pull request #7031 from yoff/python/taint-through-with
Python: Taint through `async with`
|
2021-11-09 14:08:07 +01:00 |
|
Alex Ford
|
c708b6b76f
|
Merge pull request #7077 from github/ruby/downgrade-hardcoded-credentials
Ruby: Downgrade `rb/hardcoded-credentials` precision from high to medium
|
2021-11-09 12:08:10 +00:00 |
|
Rasmus Lerchedahl Petersen
|
ac5a46f24f
|
Python: split test as suggested in review
|
2021-11-09 13:04:52 +01:00 |
|
yoff
|
5f4aad40c1
|
Update python/ql/test/experimental/meta/InlineTaintTest.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-11-09 13:00:35 +01:00 |
|
Rasmus Lerchedahl Petersen
|
aa1541a5c3
|
Python: add changenote
|
2021-11-09 12:57:36 +01:00 |
|
Rasmus Lerchedahl Petersen
|
a58c47b07b
|
Python: model aiopg.sa
|
2021-11-09 12:49:57 +01:00 |
|
Rasmus Lerchedahl Petersen
|
f53314019a
|
Python: test aiopg.sa
|
2021-11-09 12:42:03 +01:00 |
|
CodeQL CI
|
d9d304fc13
|
Merge pull request #7076 from asgerf/js/tainted-path-regexp-guard2
Approved by erik-krogh
|
2021-11-09 03:40:37 -08:00 |
|
Rasmus Lerchedahl Petersen
|
cd332a75fc
|
Python: model aiopg
|
2021-11-09 12:32:21 +01:00 |
|
Rasmus Lerchedahl Petersen
|
cb8f1b4593
|
Python: Add tests for aiopg
|
2021-11-09 11:49:31 +01:00 |
|
Geoffrey White
|
d9e02e83fe
|
Merge pull request #6825 from MathiasVP/use-shared-ssa-in-ir-dataflow
C++: Redesign IR dataflow using the shared SSA library
|
2021-11-09 10:19:50 +00:00 |
|
James Fletcher
|
1bacce487e
|
Merge pull request #7056 from jf205/sarif-query-help
Add new option to database analyze tutorial
|
2021-11-09 10:19:29 +00:00 |
|
CodeQL CI
|
954fd8d6f7
|
Merge pull request #7081 from github/revert-6924-js/skip-files-with-unsupported-encoding
Approved by esbena
|
2021-11-09 02:18:16 -08:00 |
|