Asger F
|
0039cb141e
|
Merge branch 'main' into rb/tracking-on-demand
|
2023-06-23 12:55:54 +02:00 |
|
Henry Mercer
|
5afdaf8fe1
|
Merge pull request #13525 from github/rc/3.10
Merge `rc/3.10` back to `main`
|
2023-06-21 17:13:36 +01:00 |
|
Jami
|
5259a6ecfc
|
Merge pull request #13324 from jcogs33/jcogs33/shared-sink-kind-validation
Shared: share MaD kind validation across languages
|
2023-06-20 11:56:12 -04:00 |
|
Erik Krogh Kristensen
|
2341c82450
|
Merge pull request #13342 from erik-krogh/once-again-deps
Py: delete more old deprecations
|
2023-06-20 15:29:17 +02:00 |
|
Owen Mansel-Chan
|
d7c97f8759
|
Merge pull request #13455 from owen-mc/dataflow/add-flowCheckNodeSpecific
Dataflow: add language-specific hook for breaking up big step relation
|
2023-06-20 13:24:26 +01:00 |
|
github-actions[bot]
|
18b678e69e
|
Post-release preparation for codeql-cli-2.13.4
|
2023-06-20 10:20:05 +00:00 |
|
yoff
|
579c56c744
|
Merge pull request #13178 from yoff/python-ruby/track-through-summaries-pm
ruby/python: Shared module for typetracking through flow summaries
|
2023-06-20 11:19:45 +02:00 |
|
Asger F
|
0110610c6a
|
Ruby: overhaul API graphs
|
2023-06-19 12:01:42 +02:00 |
|
Rasmus Wriedt Larsen
|
afafaac0d7
|
Python: Fix typo
|
2023-06-16 14:41:36 +02:00 |
|
Rasmus Lerchedahl Petersen
|
4fded84a49
|
python: implement missing predicates
|
2023-06-14 21:30:58 +02:00 |
|
Rasmus Lerchedahl Petersen
|
2491fda58e
|
python: update comment
|
2023-06-14 21:16:39 +02:00 |
|
Rasmus Lerchedahl Petersen
|
0e713e6fc1
|
ruby/python: more consistent naming of parameters
|
2023-06-14 21:02:42 +02:00 |
|
yoff
|
af72509ce6
|
Update python/ql/lib/semmle/python/dataflow/new/internal/TypeTrackerSpecific.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-06-14 20:57:14 +02:00 |
|
yoff
|
2ae5dae474
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-06-14 20:55:45 +02:00 |
|
yoff
|
f5f822ca2d
|
Merge pull request #13395 from yoff/python/container-summaries-3
|
2023-06-14 17:13:49 +02:00 |
|
Owen Mansel-Chan
|
3ff6d033d3
|
Rename to neverSkipInPathGraph
|
2023-06-14 15:29:54 +01:00 |
|
Owen Mansel-Chan
|
ee185ae204
|
Python: Move hack from CastNode into flowCheckNodeSpecific
|
2023-06-14 14:46:39 +01:00 |
|
Owen Mansel-Chan
|
5f72ce0935
|
Add stub implementations of flowCheckNodeSpecific
|
2023-06-14 14:46:35 +01:00 |
|
Owen Mansel-Chan
|
e0f7437d40
|
Sync dataflow library
|
2023-06-14 14:29:56 +01:00 |
|
Rasmus Lerchedahl Petersen
|
9a1e895fdc
|
Python: missed removing these
`set.add` and `list.append` do not return a value
|
2023-06-14 14:51:21 +02:00 |
|
Jami
|
35591113c2
|
Merge branch 'main' into jcogs33/shared-sink-kind-validation
|
2023-06-14 08:06:34 -04:00 |
|
Michael Nebel
|
afec9b05e9
|
Merge pull request #13147 from michaelnebel/csharp/entityframeworkrefactor
C#: Use synthetic global in the EntityFramework code instead of jump steps.
|
2023-06-14 13:47:56 +02:00 |
|
Rasmus Lerchedahl Petersen
|
3b558a0044
|
python: remove spurious return flow
|
2023-06-14 13:35:37 +02:00 |
|
yoff
|
38cca08a86
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-06-14 13:27:33 +02:00 |
|
Anders Schack-Mulligen
|
1a4fca334f
|
Merge pull request #13273 from aschackmull/dataflow/summarynode-refactor
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-14 09:38:36 +02:00 |
|
erik-krogh
|
8663a8ba1c
|
add change-note
|
2023-06-14 08:31:57 +02:00 |
|
erik-krogh
|
df61c4dd62
|
reintroduce the experiemental queries that use deprecated features
|
2023-06-14 08:31:57 +02:00 |
|
erik-krogh
|
1f8f111ef6
|
reintroduce DataFlowType - otherwise nothing in the old DataFlow library would compile
|
2023-06-14 08:31:57 +02:00 |
|
erik-krogh
|
6e001ec062
|
deprecate SqlInjectionSink - it's not used anywhere
|
2023-06-14 08:31:57 +02:00 |
|
erik-krogh
|
ae8bf5ed3c
|
delete old deprecations
|
2023-06-14 08:31:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
f1de753400
|
python: add changenote
|
2023-06-13 21:59:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
4b4b9bf9da
|
python: add missing summaries
For append/add:
The new results in the experimental tar slip query
show that we do not recognize the sanitisers.
|
2023-06-13 20:22:21 +02:00 |
|
Rasmus Lerchedahl Petersen
|
b72c93ff4f
|
python: remove remaining explicit taint steps
|
2023-06-13 20:22:20 +02:00 |
|
yoff
|
1d65284011
|
Merge pull request #13209 from yoff/python/container-summaries-2
python: Container summaries, part 2
|
2023-06-13 18:17:09 +02:00 |
|
Rasmus Lerchedahl Petersen
|
775f3eaf56
|
python: make copy a dataflow step
|
2023-06-13 17:07:41 +02:00 |
|
Rasmus Lerchedahl Petersen
|
e11f6b5107
|
ruby/python: adjust shared file
- move `isNonLocal` to the top
- missing backtics
|
2023-06-13 11:49:30 +02:00 |
|
Rasmus Lerchedahl Petersen
|
203f8226cb
|
ruby/python: make SummaryTypeTracker private
|
2023-06-13 11:32:06 +02:00 |
|
Anders Schack-Mulligen
|
2d616d494e
|
C#/Ruby: Add fields as per review comments.
|
2023-06-13 11:26:30 +02:00 |
|
yoff
|
2a5173c331
|
Update python/ql/lib/semmle/python/frameworks/Stdlib.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2023-06-13 10:04:46 +02:00 |
|
Rasmus Wriedt Larsen
|
6526364045
|
Python: Add modeling of flask.render_template_string
|
2023-06-12 21:18:31 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Anders Schack-Mulligen
|
5062442982
|
Go/Python/Ruby/Swift: Add stub.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
98f51d7f29
|
Dataflow: Sync.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
6020e4d0e3
|
C#/Go/Python/Ruby/Swift: Fix some more references.
|
2023-06-09 15:30:38 +02:00 |
|
Rasmus Lerchedahl Petersen
|
7e87a7c1f7
|
python: rewrite argumentPositionMatch
to not use the call graph.
|
2023-06-09 15:29:13 +02:00 |
|
Anders Schack-Mulligen
|
1e3b960c1b
|
Python: Adjust to FlowSummaryImpl changes.
|
2023-06-09 15:27:17 +02:00 |
|
Anders Schack-Mulligen
|
2cc5bde925
|
Dataflow: Sync.
|
2023-06-09 15:27:17 +02:00 |
|
erik-krogh
|
42d67d0137
|
add change-note
|
2023-06-09 15:24:12 +02:00 |
|
erik-krogh
|
6dfeb2536b
|
delete old deprecations
|
2023-06-09 15:12:23 +02:00 |
|
Rasmus Lerchedahl Petersen
|
b294f48dbe
|
Merge branch 'main' of https://github.com/github/codeql into python-ruby/track-through-summaries-pm
|
2023-06-09 14:16:34 +02:00 |
|