Tony Torralba
|
0f3918af16
|
Merge pull request #13773 from atorralba/atorralba/java/mdht-xxe-sink
Java: Add XXE sinks for MDHT
|
2023-08-23 13:49:49 +02:00 |
|
Anders Schack-Mulligen
|
bdc5f9cdea
|
Merge pull request #14012 from knewbury01/knewbury01/add-sanitizer-command-query
Java: add sanitizer to command injection query
|
2023-08-22 08:40:49 +02:00 |
|
Michael Nebel
|
ce6fd8ac5f
|
Merge pull request #13432 from michaelnebel/updateissupported
Java/C#: Update telemetry queries to report callables with sink/source neutrals as being supported.
|
2023-08-22 08:39:38 +02:00 |
|
Kristen Newbury
|
5e01e1d464
|
Java: add sanitizer to command injection query
|
2023-08-21 12:33:05 -04:00 |
|
Jeroen Ketema
|
2d0f73d7c2
|
Merge pull request #13881 from jketema/shared-taint-tracking
Introduce shared taint tracking library
|
2023-08-21 12:45:49 +02:00 |
|
Jeroen Ketema
|
a2bb7dee18
|
Java: Delete copy of shared taint tracking library
|
2023-08-21 10:32:28 +02:00 |
|
Michael Nebel
|
51f166d71e
|
Java: Address review comments.
|
2023-08-21 10:22:28 +02:00 |
|
Michael Nebel
|
106ba11e10
|
Address review comments.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
d66fe08661
|
Add QLDoc for the getKind predicate.
|
2023-08-21 09:59:02 +02:00 |
|
Michael Nebel
|
699ed107f3
|
Java: Update SupportedExternalApis expected test output.
|
2023-08-21 09:59:00 +02:00 |
|
Michael Nebel
|
5623ccf4a0
|
Java: Re-factor NeutralCallable to include all neutrals and introduce NeutralSummaryCallable.
|
2023-08-21 09:59:00 +02:00 |
|
Michael Nebel
|
6deeb36a97
|
Java: Update the comments in SupportedExternalApis to include the neutral kind and add a sink neutral example.
|
2023-08-21 09:58:59 +02:00 |
|
github-actions[bot]
|
181b3d0e33
|
Add changed framework coverage reports
|
2023-08-21 00:14:44 +00:00 |
|
Edward Minnix III
|
d109637e2d
|
Merge pull request #13413 from egregius313/egregius313/trust-boundary
Java: Trust Boundary Violation Query
|
2023-08-18 10:33:32 -04:00 |
|
Erik Krogh Kristensen
|
08ef31d452
|
Merge pull request #13916 from erik-krogh/limit-java-field-reg
Java: limit field flow when tracking regex strings
|
2023-08-18 12:14:31 +02:00 |
|
Edward Minnix III
|
8d88af1af0
|
Apply docs review suggestions
Co-authored-by: Sam Browning <106113886+sabrowning1@users.noreply.github.com>
|
2023-08-17 13:05:38 -04:00 |
|
Ed Minnix
|
4eb1035dfe
|
Documentation fixes
|
2023-08-17 13:05:38 -04:00 |
|
Ed Minnix
|
655a98452a
|
Remove escapeHTML models
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
d468ea9e90
|
Add default sanitizers
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
b305962c9a
|
Use more appropriate description
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
a36c12ff1f
|
Add trust-boundary-violation sink kind
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
60642c52aa
|
Use non-extending subtype
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
e22a67e7fe
|
Remove unnecessary methods
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
a3a4c31911
|
Replace servlet source node with RemoteFlowSource
|
2023-08-17 13:05:37 -04:00 |
|
Edward Minnix III
|
929090a847
|
Typos and style fixes
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
52ebf9fff6
|
Java: Add trust boundary change note
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
172b8a6967
|
Documentation fixes
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
b567ec875a
|
Documentation
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
55fae2daaa
|
Added ESAPI sanitizer
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
97d6e82869
|
Stubs for org.owasp.esapi
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
f58590c6a9
|
Trust Boundary Work
|
2023-08-17 13:05:37 -04:00 |
|
Ed Minnix
|
2aba425464
|
TrustBoundary test ql file
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
ab9f0240d3
|
Add taint steps for HTML encoding methods
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
b9f2da7875
|
Comments and import fixes
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
3e7444cd66
|
Style fixes
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
15370506b8
|
Add missing security severity
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
a8b7e70d01
|
Convert trust boundary models to MaD
|
2023-08-17 13:05:36 -04:00 |
|
Ed Minnix
|
76438f13b6
|
Trust Boundary Query
|
2023-08-17 13:05:36 -04:00 |
|
Edward Minnix III
|
41a527cf72
|
Merge pull request #13934 from egregius313/egregius313/add-dashes-to-sha-algorithms
Java: Add dashes to SHA algorithm names in `Encryption.qll`
|
2023-08-17 13:03:15 -04:00 |
|
Anders Schack-Mulligen
|
e27aad9d6c
|
Merge pull request #13987 from aschackmull/java/rangeanalysis-joinorder-fix
Java: Join-order fix in RangeAnalysis.
|
2023-08-17 14:47:26 +02:00 |
|
Anders Schack-Mulligen
|
f8a0b6cd22
|
Java: Add nomagic
|
2023-08-17 11:20:02 +02:00 |
|
Anders Schack-Mulligen
|
0afda68ba1
|
Java: Join-order fix in RangeAnalysis.
|
2023-08-17 11:07:24 +02:00 |
|
github-actions[bot]
|
b0da1ef892
|
Add changed framework coverage reports
|
2023-08-17 00:14:13 +00:00 |
|
Jeroen Ketema
|
33e8310625
|
Merge branch 'main' into shared-taint-tracking
|
2023-08-17 00:14:25 +02:00 |
|
Ian Lynagh
|
1fb4e13e0a
|
Merge pull request #13960 from igfoo/igfoo/parent
Kotlin: Handle Kotlin 2 parents better
|
2023-08-16 16:27:15 +01:00 |
|
Stephan Brandauer
|
20254c3d0a
|
Merge pull request #13886 from github/kaeluka/java-automodel-variadic-args
Java: automodel application mode: use endpoint class like in framework mode
|
2023-08-16 08:49:01 +02:00 |
|
Ed Minnix
|
cafd08521e
|
Add change note
|
2023-08-15 23:46:12 -04:00 |
|
Ed Minnix
|
7cfe78a52d
|
Add dashes to SHA algorithm names in Encryption.qll
|
2023-08-15 23:42:17 -04:00 |
|
Ian Lynagh
|
3b9bd16097
|
Kotlin: Mark some functions as private
|
2023-08-15 12:38:47 +01:00 |
|
Ian Lynagh
|
a8b69e5b55
|
Kotlin: Fix build on old versions
|
2023-08-15 11:30:23 +01:00 |
|