Tony Torralba
|
149cae9603
|
Merge pull request #10971 from joefarebrother/android-certificate-pinning
Java: Add Android missing certificate pinning query (CWE-295)
|
2022-12-20 11:03:16 +01:00 |
|
Tony Torralba
|
3e7a819fe7
|
Simplification
|
2022-12-20 09:42:25 +01:00 |
|
Jeroen Ketema
|
edc768b43b
|
Merge pull request #11707 from smowton/smowton/fix/java-empty-multiline-comment
Java: handle printing an empty comment (/**/); add relevant tests
|
2022-12-20 08:07:42 +01:00 |
|
Tony Torralba
|
a47ef17a0d
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning1.java
Co-authored-by: Edward Minnix III <egregius313@github.com>
|
2022-12-19 18:11:54 +01:00 |
|
Chris Smowton
|
ebc0b0c4d6
|
Merge pull request #11665 from smowton/smowton/admin/revert-kotlin-default-method-type-erasure
Kotlin: Revert type erasure within $default functions
|
2022-12-19 16:33:20 +00:00 |
|
Edward Minnix III
|
39a7c7bb12
|
Merge pull request #11282 from egregius313/egregiu313/webview-addjavascriptinterface
Java: Query for detecting addJavascriptInterface method calls
|
2022-12-19 11:28:45 -05:00 |
|
Tony Torralba
|
624c9ff834
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning1.java
|
2022-12-19 17:26:41 +01:00 |
|
Tony Torralba
|
0c6ace350f
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-12-19 16:24:39 +01:00 |
|
Arthur Baars
|
016c7a8ca7
|
Merge pull request #11719 from aibaars/alert-suppression-shared
Shared AlertSuppression library
|
2022-12-19 16:04:44 +01:00 |
|
Chris Smowton
|
2ca56e0c1e
|
Java: handle printing an empty comment (/**/); add relevant tests
|
2022-12-19 14:12:09 +01:00 |
|
Tony Torralba
|
484a16ce1b
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql
|
2022-12-19 12:10:32 +01:00 |
|
Arthur Baars
|
bc646d407e
|
Java: use shared AlertSuppression.qll
|
2022-12-19 12:07:28 +01:00 |
|
Tony Torralba
|
a880fecc8b
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-12-19 11:56:36 +01:00 |
|
erik-krogh
|
ba7321ac5c
|
add qldoc to RegExpCharEscape
|
2022-12-18 17:23:45 +01:00 |
|
erik-krogh
|
26c5480ee6
|
share {js,rb}/regex/missing-regexp-anchor
|
2022-12-18 17:23:41 +01:00 |
|
erik-krogh
|
f67d0bc8c0
|
put the shared HostnameRegexp code in the shared regex pack
|
2022-12-17 17:26:18 +01:00 |
|
Henry Mercer
|
30451ee950
|
Merge pull request #11681 from github/henrymercer/mergeback-3.8
Merge `rc/3.8` back to `main`
|
2022-12-16 17:43:12 +00:00 |
|
Michael Nebel
|
b2856c1f5a
|
Merge pull request #11705 from michaelnebel/dataextensiontests
C#/Java: Migrate tests to use implicitly loaded extensions.
|
2022-12-16 10:50:07 +01:00 |
|
Tom Hvitved
|
e45edcc159
|
Merge pull request #11674 from hvitved/dataflow/param-context
Data flow: Track callable in flow-through pruning
|
2022-12-16 09:25:15 +01:00 |
|
Jami
|
fd63348549
|
Merge pull request #11585 from jcogs33/jcogs33/mad-metrics-query
Java: add MaD metrics query
|
2022-12-15 19:26:51 -05:00 |
|
Jami Cogswell
|
96a0950048
|
Java: update test case
|
2022-12-15 15:49:53 -05:00 |
|
Jami Cogswell
|
c33bc63aed
|
Java: remove extraneous parentheses
|
2022-12-15 15:26:04 -05:00 |
|
Jami Cogswell
|
cfeedb5cb4
|
Java: add float cast
|
2022-12-15 15:23:28 -05:00 |
|
Jami Cogswell
|
b68a9a51e2
|
Java: add coverage, generatedCoverage, and manualCoverage metrics
|
2022-12-15 15:20:08 -05:00 |
|
Jami Cogswell
|
9d10b719d6
|
Java: add match metric
|
2022-12-15 15:10:35 -05:00 |
|
Jami Cogswell
|
1c5d4f8048
|
Java: rename generatedCoverage and manualCoverage
|
2022-12-15 15:03:00 -05:00 |
|
Michael Nebel
|
c34bde962c
|
Java: Update integration tests to use implicit ext.yml data extensions.
|
2022-12-15 19:01:29 +01:00 |
|
Tom Hvitved
|
f8571dd0b6
|
Data flow: Work around functionality-induced misoptimization
|
2022-12-15 15:29:14 +01:00 |
|
Tom Hvitved
|
6eda042229
|
Data flow: Sync files
|
2022-12-15 15:29:13 +01:00 |
|
Michael Nebel
|
31c60e545e
|
Java: Update the flow test generator to create ext.yml files.
|
2022-12-15 14:46:20 +01:00 |
|
Michael Nebel
|
6dc798f970
|
Java: Migrate tests to use implicit ext.yml data extensions.
|
2022-12-15 14:13:07 +01:00 |
|
Michael Nebel
|
a67e02df21
|
Merge pull request #11691 from michaelnebel/renameextensibles
C#/Java: Rename externalflow extensible predicates
|
2022-12-15 11:05:22 +01:00 |
|
Michael Nebel
|
12c1ebd81c
|
C#/Java: Add change note.
|
2022-12-15 09:41:14 +01:00 |
|
Ed Minnix
|
72484b9483
|
Change wording of addJavascriptInterface query description
|
2022-12-14 16:19:03 -05:00 |
|
Jami
|
359e49044f
|
Merge branch 'main' into jcogs33/mad-metrics-query
|
2022-12-14 15:33:29 -05:00 |
|
Jami
|
33955ee4ab
|
Merge pull request #11623 from jcogs33/jcogs33/exclude-funcexpr-from-dataflowtargetapi
Java/C#: exclude `FunctionalExpr`s from `DataFlowTargetApi`
|
2022-12-14 12:22:50 -05:00 |
|
Michael Nebel
|
fe3c8613cd
|
Java: Fix name of extensible in java integration test.
|
2022-12-14 15:25:47 +01:00 |
|
Jami
|
b248b44983
|
Merge pull request #11668 from jcogs33/jcogs33/update-isjdkinternal
Java: update `isJdkInternal`
|
2022-12-14 08:33:18 -05:00 |
|
Jami
|
f61b817751
|
Merge pull request #11631 from jcogs33/jcogs33/update-externalapi-charpredicate
Java/C#: add `isUninteresting` to `ExternalApi` characteristic predicate
|
2022-12-14 08:25:02 -05:00 |
|
Anders Schack-Mulligen
|
598b4c38b7
|
Merge pull request #11619 from aschackmull/java/typetrack-lambda
Java: Switch DispatchFlow to typetracking.
|
2022-12-14 14:08:29 +01:00 |
|
Michael Nebel
|
bc02adb400
|
Java: Make the corresponding rename in all the data extensions.
|
2022-12-14 13:48:31 +01:00 |
|
Michael Nebel
|
b45d079a01
|
Java: Move and rename externalflow related extensible predicates.
|
2022-12-14 13:43:34 +01:00 |
|
Tom Hvitved
|
25b2d11368
|
Merge pull request #11635 from hvitved/dataflow/approx-content
Data flow: Introduce `ApproxContent` in a new pruning stage between stages 2 and 3
|
2022-12-14 12:56:50 +01:00 |
|
Tamás Vajk
|
a6d227d52e
|
Merge pull request #11599 from igfoo/igfoo/diags
Java/Kotlin: Update the diagnostic severity documentation
|
2022-12-14 10:13:30 +01:00 |
|
Jami Cogswell
|
c956589945
|
Java: remove dot before percent
|
2022-12-13 17:46:20 -05:00 |
|
Jami Cogswell
|
dee251e5d6
|
Java: update isJdkInternal
|
2022-12-13 17:46:20 -05:00 |
|
Jami
|
11bd35661c
|
Merge branch 'main' into jcogs33/exclude-funcexpr-from-dataflowtargetapi
|
2022-12-13 17:10:39 -05:00 |
|
Edward Minnix III
|
40c759e61a
|
Add @name property
Co-authored-by: Sam Browning <106113886+sabrowning1@users.noreply.github.com>
|
2022-12-13 16:14:28 -05:00 |
|
Tamás Vajk
|
8e500ec0f3
|
Merge pull request #11675 from tamasvajk/kotlin-error-expr-consistency
Kotlin: Report CFG dead end consistency issues on `ErrorExpr`
|
2022-12-13 20:22:47 +01:00 |
|
Henry Mercer
|
a3933fbf4f
|
Bump minor versions of packs we regularly release
|
2022-12-13 18:59:24 +00:00 |
|