CodeQL CI
|
17afbdf258
|
Merge pull request #5635 from RasmusWL/port-weak-crypto-algorithm
Approved by yoff
|
2021-05-20 01:22:32 -07:00 |
|
Rasmus Wriedt Larsen
|
753dca91b1
|
Python: weak-crypto: Make algorithm selection less brittle
As discussed in https://github.com/github/codeql/pull/5635#discussion_r633477154
|
2021-05-19 17:47:09 +02:00 |
|
Rasmus Wriedt Larsen
|
22d4d7956a
|
Python: Fix typo in QLDoc
|
2021-05-19 17:47:05 +02:00 |
|
Rasmus Wriedt Larsen
|
8d1e7da851
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2021-05-19 17:42:46 +02:00 |
|
Mathias Vorreiter Pedersen
|
c4f604bafe
|
Merge pull request #5896 from geoffw0/weak_crypto
C++: Improve cpp/weak-cryptographic-algorithm
|
2021-05-19 13:17:13 +02:00 |
|
Alexander Eyers-Taylor
|
c80495fbdd
|
Merge pull request #5851 from github/alexet/patch
Use only_bind_out to force a good join order.
|
2021-05-19 12:00:07 +01:00 |
|
CodeQL CI
|
9bdfdb02d3
|
Merge pull request #5916 from erik-krogh/scriptSink
Approved by esbena
|
2021-05-19 03:46:17 -07:00 |
|
Geoffrey White
|
aaae717328
|
Merge branch 'main' into weak_crypto
|
2021-05-19 11:19:08 +01:00 |
|
CodeQL CI
|
c793ac933a
|
Merge pull request #5921 from erik-krogh/expressChain
Approved by esbena
|
2021-05-19 03:17:40 -07:00 |
|
Geoffrey White
|
e985204a62
|
C++: Add change note.
|
2021-05-19 11:14:23 +01:00 |
|
CodeQL CI
|
23e8092452
|
Merge pull request #5864 from RasmusWL/some-framework-modeling
Approved by tausbn
|
2021-05-19 02:31:06 -07:00 |
|
Geoffrey White
|
e66b5559a4
|
Merge pull request #5924 from MathiasVP/cleanup-modelFlow
C++: Remove a disjunction from `modelFlow`
|
2021-05-19 10:12:20 +01:00 |
|
Geoffrey White
|
99833f16e1
|
Merge pull request #5923 from MathiasVP/range-analysis-in-overflow-static
C++: Add range analysis to `cpp/static-buffer-overflow`
|
2021-05-19 10:12:02 +01:00 |
|
Mathias Vorreiter Pedersen
|
4d00513606
|
C++: Use the isParameterDerefOrQualifierObject predicate to remove a disjunction.
|
2021-05-19 10:47:04 +02:00 |
|
Mathias Vorreiter Pedersen
|
741eed93b2
|
C++: Replace minimum(any(...)) with a min aggregate. Also removed the min aggregate further down since it's no longer needed.
|
2021-05-19 09:03:05 +02:00 |
|
yoff
|
60da193620
|
Update python/ql/src/semmle/python/frameworks/Cryptodome.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-05-19 08:08:59 +02:00 |
|
Erik Krogh Kristensen
|
9a1f80aa93
|
accept updated test output for express test
|
2021-05-18 22:23:29 +02:00 |
|
Erik Krogh Kristensen
|
e9d2dd0b57
|
support the chaining methods on Express apps
|
2021-05-18 22:23:27 +02:00 |
|
Chris Smowton
|
0c970b5f1f
|
Merge pull request #5802 from luchua-bc/java/rhino-injection
Java: CWE-094 Rhino code injection
|
2021-05-18 19:25:53 +01:00 |
|
Mathias Vorreiter Pedersen
|
6103aabdce
|
C++: Add change-note.
|
2021-05-18 19:17:11 +02:00 |
|
luchua-bc
|
02aa9c6fc7
|
Optimize the sink and update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
d4323a4a54
|
Update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
9d392263a5
|
Refactor inconsistent method names
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2fa249a8eb
|
Update method name and qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2c1374bdcf
|
Use inline implementation for ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
0ac8453398
|
Allow all arguments of methods in ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
e4699f7fa9
|
Optimize the query
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
d664aa6d6a
|
Include more scenarios and update qldoc
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
852bcfb5c7
|
Refactor the ScriptEngine query and the Rhino code injection query into one
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
b0b5338359
|
Rhino code injection
|
2021-05-18 16:12:22 +00:00 |
|
Mathias Vorreiter Pedersen
|
26c4a66dc4
|
C++: Add range analysis to fix FPs.
|
2021-05-18 17:54:30 +02:00 |
|
Mathias Vorreiter Pedersen
|
df9981de4f
|
C++: Add testcases with false positives.
|
2021-05-18 17:53:20 +02:00 |
|
Ethan Palm
|
9deaace756
|
Merge pull request #5898 from ethanpalm/go-build-commands
Docs: Document Go tracer support
|
2021-05-18 11:49:31 -04:00 |
|
Ethan Palm
|
610e041e28
|
Add reviewer feedback
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2021-05-18 11:42:08 -04:00 |
|
Chris Smowton
|
4230869ee2
|
Merge pull request #5819 from luchua-bc/java/jpython-injection
Java: CWE-094 Jython code injection
|
2021-05-18 16:38:40 +01:00 |
|
Chris Smowton
|
71f540a755
|
Merge pull request #5844 from haby0/SpringRedirects
[Java] CWE-601 Spring url redirection detect
|
2021-05-18 16:37:40 +01:00 |
|
Geoffrey White
|
cdf261b54b
|
C++: In fact it's just not good enough to get additional evidence from the declaring type.
|
2021-05-18 14:31:19 +01:00 |
|
Geoffrey White
|
88dc0861ac
|
C++: Fix copy-paste error.
|
2021-05-18 14:27:31 +01:00 |
|
Geoffrey White
|
c7382ee06d
|
C++: Repair for function call macros.
|
2021-05-18 14:27:08 +01:00 |
|
Geoffrey White
|
012840e602
|
C++: Add more test cases.
|
2021-05-18 14:26:12 +01:00 |
|
Geoffrey White
|
3d8513c1e0
|
C++: Add 'MAC' as additional evidence.
|
2021-05-18 13:24:51 +01:00 |
|
Geoffrey White
|
da83e9142b
|
C++: Replace getAnExpandedElement with getAGeneratedElement as it's all we really need.
|
2021-05-18 13:23:49 +01:00 |
|
luchua-bc
|
2a0721b2ae
|
Optimize the sink and update method name
|
2021-05-18 12:18:14 +00:00 |
|
CodeQL CI
|
1d120824ac
|
Merge pull request #5920 from erik-krogh/clone
Approved by esbena
|
2021-05-18 05:13:57 -07:00 |
|
Rasmus Wriedt Larsen
|
97fadd9970
|
Merge branch 'main' into port-weak-crypto-algorithm
|
2021-05-18 14:04:18 +02:00 |
|
Rasmus Wriedt Larsen
|
6c755024ac
|
Python: Refactor code, inline some type-tracking
|
2021-05-18 14:03:36 +02:00 |
|
Rasmus Wriedt Larsen
|
770429fd68
|
Python: Autoformat
|
2021-05-18 14:02:46 +02:00 |
|
haby0
|
e46de44473
|
Solve errors caused by private ownership
|
2021-05-18 19:56:32 +08:00 |
|
Erik Krogh Kristensen
|
06514a2bb6
|
move clone model to Extend.qll
|
2021-05-18 13:16:41 +02:00 |
|
haby0
|
caf5f4d605
|
modified comment
|
2021-05-18 19:10:03 +08:00 |
|