Anders Schack-Mulligen
|
1188e18837
|
Java: Whitelist Cookie::getName for HTTP response splitting.
|
2018-10-25 12:02:33 +02:00 |
|
semmle-qlci
|
c78f3f8edf
|
Merge pull request #336 from aschackmull/java/dataflow-cleanup
Approved by yh-semmle
|
2018-10-20 03:43:49 +01:00 |
|
semmle-qlci
|
465a55f8ac
|
Merge pull request #333 from aschackmull/java/useless-comp-concurrent
Approved by yh-semmle
|
2018-10-20 01:37:13 +01:00 |
|
Anders Schack-Mulligen
|
6f11849fef
|
Java: Add test.
|
2018-10-19 15:02:52 +02:00 |
|
calumgrant
|
6811d527e1
|
Merge pull request #327 from hvitved/csharp/compiler-flag-linux
C#: Pass `--compiler` flag to extractor on Linux
|
2018-10-19 11:18:46 +01:00 |
|
Tom Hvitved
|
826d15e6c1
|
C#: Address review comments
|
2018-10-19 10:42:13 +02:00 |
|
Robert Marsh
|
36a1ac52ac
|
Merge pull request #331 from geoffw0/av-35b
CPP: Speed up startsWithIfndef.
|
2018-10-18 14:22:37 -07:00 |
|
semmle-qlci
|
4dd868fb3d
|
Merge pull request #334 from aschackmull/java/autoformat-rangeanalysis
Approved by yh-semmle
|
2018-10-18 15:38:33 +01:00 |
|
Anders Schack-Mulligen
|
0b46ffa7d7
|
Java/CPP: Sync files.
|
2018-10-18 15:10:23 +02:00 |
|
Anders Schack-Mulligen
|
bf58b6c9ab
|
Java: Remove self-ref tracking; improve AccessPath.toString on numbers.
|
2018-10-18 15:05:04 +02:00 |
|
Anders Schack-Mulligen
|
187918396c
|
Java: Autoformat the last 5 files (RangeAnalysis).
|
2018-10-18 10:03:08 +02:00 |
|
Anders Schack-Mulligen
|
0c37ea876d
|
Java: Fix FPs for concurrent modification checks.
|
2018-10-18 09:44:26 +02:00 |
|
semmle-qlci
|
3af91d5d0a
|
Merge pull request #301 from aschackmull/java/modulus-analysis
Approved by yh-semmle
|
2018-10-18 08:24:32 +01:00 |
|
calumgrant
|
0ddb7027ee
|
Merge pull request #284 from hvitved/csharp/null-guards
C#: Teach null-guards library about pattern matching
|
2018-10-17 17:49:51 +01:00 |
|
Geoffrey White
|
6e10f39612
|
Merge pull request #319 from raulgarciamsft/users/raulga/c6277
C++ : NULL application name with an unquoted path in call to CreateProcess
|
2018-10-17 17:36:59 +01:00 |
|
Geoffrey White
|
b8d7292b46
|
CPP: Speed up startsWithIfndef.
|
2018-10-17 15:26:05 +01:00 |
|
Anders Schack-Mulligen
|
3dc9071a44
|
Java: Add missing word in deprecation comments.
|
2018-10-17 15:59:52 +02:00 |
|
Arthur Baars
|
749206a9ce
|
Merge pull request #324 from hvitved/lgtm-yml
Add `.lgtm.yml` file
|
2018-10-17 13:24:20 +02:00 |
|
Tom Hvitved
|
976e5ed80f
|
C#: Pass --compiler flag to extractor on Linux
|
2018-10-17 10:25:53 +02:00 |
|
Tom Hvitved
|
8158d456f3
|
C#: Use hashing to detect duplicate trap files
|
2018-10-17 10:25:05 +02:00 |
|
semmle-qlci
|
1da873e819
|
Merge pull request #315 from esben-semmle/js/conditional-bypass-early-return
Approved by xiemaisi
|
2018-10-17 08:25:55 +01:00 |
|
Tom Hvitved
|
29f655b0dc
|
Add .lgtm.yml file
|
2018-10-16 20:43:44 +02:00 |
|
Raul Garcia
|
7ab723ae79
|
Fixing typos & incorporating feedback.
(MSFT feedback) Adding a new tag in the header @msrc.severity important
|
2018-10-16 10:00:51 -07:00 |
|
semmle-qlci
|
6172c95e60
|
Merge pull request #320 from geoffw0/deprecated
Approved by yh-semmle
|
2018-10-16 15:45:06 +01:00 |
|
calumgrant
|
2836743c03
|
Merge pull request #322 from hvitved/csharp/compiler-settings
C#: Add `csharp-compiler-settings` files
|
2018-10-16 13:36:06 +01:00 |
|
semmle-qlci
|
e55eaefded
|
Merge pull request #310 from esben-semmle/js/additional-client-request-data-nodes
Approved by xiemaisi
|
2018-10-16 12:59:22 +01:00 |
|
semmle-qlci
|
e319159a59
|
Merge pull request #316 from xiemaisi/js/odasa-7355-workaround
Approved by esben-semmle
|
2018-10-16 12:47:58 +01:00 |
|
Anders Schack-Mulligen
|
26009065af
|
Java: Fix regression.
|
2018-10-16 11:29:15 +02:00 |
|
Esben Sparre Andreasen
|
870811a509
|
JS: change note for improved ClientRequests (overdue)
|
2018-10-16 08:51:32 +02:00 |
|
Esben Sparre Andreasen
|
c7fe96d4bd
|
JS: implement getADataNode for Electron::ClientRequest
|
2018-10-16 08:51:32 +02:00 |
|
Esben Sparre Andreasen
|
e7836d74ab
|
JS: implement getADataNode for NodeHttpUrlRequest
|
2018-10-16 08:51:32 +02:00 |
|
Esben Sparre Andreasen
|
3c07b4faf1
|
JS: implement getADataNode for SuperAgentUrlRequest
|
2018-10-16 08:51:32 +02:00 |
|
Esben Sparre Andreasen
|
eef0b8c94d
|
JS: implement getADataNode for GotUrlRequest
|
2018-10-16 08:51:32 +02:00 |
|
Esben Sparre Andreasen
|
977b287129
|
JS: implement getADataNode for FetchUrlRequest
|
2018-10-16 08:51:30 +02:00 |
|
Esben Sparre Andreasen
|
c21a0472d4
|
JS: implement getADataNode for AxiosUrlRequest
|
2018-10-16 08:50:56 +02:00 |
|
Esben Sparre Andreasen
|
1e115bce2c
|
JS: add SourceNode support for chained method calls
|
2018-10-16 08:48:09 +02:00 |
|
Esben Sparre Andreasen
|
ffbbb807f4
|
JS: avoid flagging early returns in js/user-controlled-bypass
|
2018-10-16 08:39:59 +02:00 |
|
Max Schaefer
|
df5a8651c3
|
JavaScript: Reinstate override.
|
2018-10-16 07:31:28 +01:00 |
|
semmle-qlci
|
1e7696664e
|
Merge pull request #302 from xiemaisi/js/google-spanner
Approved by esben-semmle
|
2018-10-16 06:48:43 +01:00 |
|
Raul Garcia
|
22d54801e5
|
Removed one false-positive scenario (no space on lpCommandLine)
Improved the query to avoid multiple calls to hasGlobalName
Fixed typos
Simplified the test case file
|
2018-10-15 15:53:02 -07:00 |
|
Raul Garcia
|
cd5e788aa7
|
Update UnsafeCreateProcessCall.ql
|
2018-10-15 13:41:21 -07:00 |
|
Raul Garcia
|
1d853691eb
|
Update UnsafeCreateProcessCall.qhelp
|
2018-10-15 13:40:40 -07:00 |
|
Raul Garcia
|
b8f8c99529
|
Update UnsafeCreateProcessCall.qhelp
|
2018-10-15 13:39:46 -07:00 |
|
Raul Garcia
|
bc398733b3
|
Update .gitignore
|
2018-10-15 13:38:00 -07:00 |
|
Max Schaefer
|
6835815673
|
JavaScript: Address review comments.
|
2018-10-15 20:14:40 +01:00 |
|
semmle-qlci
|
7543fa4a10
|
Merge pull request #298 from asger-semmle/partial-calls-merged
Approved by xiemaisi
|
2018-10-15 14:58:22 +01:00 |
|
Tom Hvitved
|
0754abc03f
|
C#: Add csharp-compiler-settings files
|
2018-10-15 13:14:40 +02:00 |
|
Tom Hvitved
|
5548524a39
|
Merge pull request #321 from esben-semmle/js/newlines-csharp
C#: use unix newlines in analysis-csharp.md
|
2018-10-15 12:39:34 +02:00 |
|
Esben Sparre Andreasen
|
2652ba78d7
|
C#: use unix newlines in analysis-csharp.md
|
2018-10-15 12:08:41 +02:00 |
|
Tom Hvitved
|
603c3d6a43
|
C#: Teach null-guards library about pattern matching
|
2018-10-15 10:55:16 +02:00 |
|