Ian Lynagh
|
1b83aeb25d
|
Merge pull request #13393 from igfoo/igfoo/remove_explorer
Kotlin: Remove kotlin-explorer
|
2023-06-07 16:32:00 +01:00 |
|
Ian Lynagh
|
c4e829f1d4
|
Merge pull request #13385 from igfoo/igfoo/kotlin_version_relax
Kotlin: Relax version requirements
|
2023-06-07 16:31:49 +01:00 |
|
Tamás Vajk
|
ccb622348b
|
Merge pull request #13382 from tamasvajk/feature/standalone-dll-unsafe
C#: Change standalone extraction to allow unsafe code
|
2023-06-07 14:37:11 +02:00 |
|
Tony Torralba
|
6d7234f8ed
|
Merge pull request #13225 from atorralba/atorralba/java/path-injection-mad-sinks-2
Java: Migrate path injection sinks to models-as-data (simplified)
|
2023-06-07 14:27:36 +02:00 |
|
yoff
|
911835c30e
|
Merge pull request #13392 from yoff/java/test-type-tracking-through-flow-summaries
java: test type tracking through flow summaries
|
2023-06-07 14:10:23 +02:00 |
|
Ian Lynagh
|
d6ac5cdc94
|
Kotlin: Remove kotlin-explorer
This was an exploration tool that I don't think has been used for some
time.
|
2023-06-07 12:39:00 +01:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|
Tony Torralba
|
46b30453e3
|
Merge pull request #13386 from github/java/update-mad-decls-after-triage-2023-06-06T14-38-29
Java: Update MaD Declarations after Triage
|
2023-06-07 12:33:26 +02:00 |
|
Tamás Vajk
|
8fe025eb64
|
Merge pull request #13384 from tamasvajk/fix/standalone-explicit-interface-error
C#: Improve error message for missing explicit interface implementation
|
2023-06-07 12:19:08 +02:00 |
|
Rasmus Lerchedahl Petersen
|
aec1e4a713
|
java: address ql alert
|
2023-06-07 11:40:50 +02:00 |
|
Rasmus Lerchedahl Petersen
|
76e1c6f76f
|
java: test type tracking through flow summaries
|
2023-06-07 11:18:53 +02:00 |
|
Tamas Vajk
|
0f75449abb
|
Improve code quality
|
2023-06-07 10:40:58 +02:00 |
|
Tony Torralba
|
416d3d587d
|
Accept test changes
An uncovered test case is now correctly covered
|
2023-06-07 10:33:17 +02:00 |
|
Paolo Tranquilli
|
357542a160
|
Merge pull request #13258 from github/redsun82/swift-synth-properties
Codegen: allow `synth` properties of non-`synth` classes
|
2023-06-07 10:31:06 +02:00 |
|
Geoffrey White
|
aa8878ba86
|
Merge pull request #13356 from geoffw0/qualname
Swift: Add FieldDecl.getQualifiedName
|
2023-06-07 09:08:16 +01:00 |
|
Tony Torralba
|
b5bbe63144
|
Merge pull request #13389 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2023-06-07 09:48:44 +02:00 |
|
Tony Torralba
|
27763d6bbe
|
Improve ZipSlip exclusion to take varargs into account
|
2023-06-07 09:25:56 +02:00 |
|
Paolo Tranquilli
|
700e3d5e53
|
Codegen: rename ipa to synth
|
2023-06-07 09:12:39 +02:00 |
|
Tony Torralba
|
8001ae9669
|
Update java/ql/lib/semmle/code/java/security/ZipSlipQuery.qll
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-06-07 09:08:24 +02:00 |
|
Tony Torralba
|
60725e9580
|
Update java/ql/lib/ext/org.springframework.core.io.model.yml
|
2023-06-07 09:07:22 +02:00 |
|
Tony Torralba
|
2f12ae2e0d
|
Update java/ql/lib/ext/okhttp3.model.yml
|
2023-06-07 08:57:12 +02:00 |
|
github-actions[bot]
|
a14e7fa694
|
Add changed framework coverage reports
|
2023-06-07 00:16:58 +00:00 |
|
Stephan Brandauer
|
b31131d33a
|
Merge pull request #13344 from github/java/update-mad-decls-after-triage-2023-06-01T12-58-13
Java: Update MaD Declarations after Triage
|
2023-06-06 17:08:50 +02:00 |
|
Stephan Brandauer
|
75cbcdd72e
|
Update MaD Declarations after Triage
|
2023-06-06 16:38:31 +02:00 |
|
Tamás Vajk
|
e8f56f2981
|
Update csharp/extractor/Semmle.Extraction.CSharp/Entities/Method.cs
Co-authored-by: Michael B. Gale <mbg@github.com>
|
2023-06-06 16:20:48 +02:00 |
|
Nora Dimitrijević
|
2529312d1d
|
Codegen: fix test.qlgen failure
|
2023-06-06 15:58:19 +02:00 |
|
Nora Dimitrijević
|
928da77d10
|
Merge branch 'main' into redsun82/swift-synth-properties
|
2023-06-06 15:34:02 +02:00 |
|
Ian Lynagh
|
ca63122ce4
|
Kotlin: Relax version requirements
If the latest version we know about is 1.9, and we are faced with 1.10,
then we try 1.9 rather than failing with an exception.
|
2023-06-06 14:09:55 +01:00 |
|
Tamas Vajk
|
a4dec591c7
|
C#: Improve error message for missing explicit interface implementation
|
2023-06-06 15:01:54 +02:00 |
|
Tamas Vajk
|
75bc8756f2
|
C#: Change standalone extraction to allow unsafe code
|
2023-06-06 14:43:09 +02:00 |
|
Tony Torralba
|
49c6ea27a0
|
Merge pull request #13379 from atorralba/atorralba/kotlin/use-with-flow
Kotlin: Add flow through kotlin.io.use and kotlin.with
|
2023-06-06 13:44:14 +02:00 |
|
Taus
|
f4fd908f7f
|
Java: Comment out sinks for which no query exists
|
2023-06-06 13:01:59 +02:00 |
|
Ian Lynagh
|
f690d150b0
|
Merge pull request #13373 from igfoo/igfoo/kotlin-loc
Java/Kotlin: Split lines of code by language
|
2023-06-06 11:49:18 +01:00 |
|
Taus
|
c4bfb21f0f
|
Merge pull request #13371 from github/nickrolfe/python-location-tostring
Python: avoid selecting `getLocation()`
|
2023-06-06 12:05:51 +02:00 |
|
Erik Krogh Kristensen
|
0e6693bdea
|
Merge pull request #12874 from erik-krogh/ts51
JS: Add support for TS 5.1
|
2023-06-06 11:51:51 +02:00 |
|
Rasmus Wriedt Larsen
|
a1f20f84d4
|
Merge pull request #13359 from jorgectf/jorgectf/unsafe-deserialization-name-convention
Python: Make `py/unsafe-deserialization` `@name` consistent with other languages
|
2023-06-06 11:28:41 +02:00 |
|
Tony Torralba
|
1d8ca88aca
|
Add change note
|
2023-06-06 11:25:07 +02:00 |
|
Tony Torralba
|
72af634575
|
Kotlin: Add flow through use and with
|
2023-06-06 11:22:16 +02:00 |
|
Nick Rolfe
|
6c5c338e6b
|
Merge pull request #13348 from github/nickrolfe/java-location-tostring
Java: avoid call to `Location.toString()`
|
2023-06-06 09:55:42 +01:00 |
|
Nick Rolfe
|
3d0ecbed39
|
Merge pull request #13361 from github/nickrolfe/csharp-location-tostring
C#: avoid calls to `Location::toString()`
|
2023-06-06 09:55:09 +01:00 |
|
Tony Torralba
|
1601846478
|
Add exclusion to the ZipSlip query to avoid FPs
|
2023-06-06 10:28:49 +02:00 |
|
Tony Torralba
|
0065e6e1d6
|
Apply suggestions from code review
Fix incorrect models-as-data rows
|
2023-06-06 10:04:22 +02:00 |
|
Tony Torralba
|
1ccec90c6f
|
Apply suggestions from code review
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-06-06 09:10:18 +02:00 |
|
Erik Krogh Kristensen
|
b78cd48954
|
Merge pull request #13329 from erik-krogh/sqlhelp
JS: improve the sql-injection help page
|
2023-06-06 08:44:44 +02:00 |
|
Erik Krogh Kristensen
|
29bbf58a29
|
Merge pull request #13377 from github/dependabot/cargo/ql/regex-1.8.4
Bump regex from 1.8.3 to 1.8.4 in /ql
|
2023-06-06 07:57:04 +02:00 |
|
dependabot[bot]
|
d38bca1e8c
|
Bump regex from 1.8.3 to 1.8.4 in /ql
Bumps [regex](https://github.com/rust-lang/regex) from 1.8.3 to 1.8.4.
- [Release notes](https://github.com/rust-lang/regex/releases)
- [Changelog](https://github.com/rust-lang/regex/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rust-lang/regex/compare/1.8.3...1.8.4)
---
updated-dependencies:
- dependency-name: regex
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-06-06 04:02:46 +00:00 |
|
Jeroen Ketema
|
272ced6ea5
|
Merge pull request #13374 from jketema/ptr-deref-min
C++: Remove `cpp/invalid-pointer-deref` results duplicating ones with smaller `k`
|
2023-06-05 19:31:24 +02:00 |
|
erik-krogh
|
3cb2ec4e87
|
fix nits from doc review
|
2023-06-05 19:06:07 +02:00 |
|
Taus
|
7ad860fc98
|
Java: Update MaD declarations after triage
Co-authored-by: Stephan Brandauer <kaeluka@github.com>
|
2023-06-05 18:00:40 +02:00 |
|
Ian Lynagh
|
e49b278d61
|
Java/Kotlin: Add a changenote for the lines-of-code changes.
|
2023-06-05 16:33:12 +01:00 |
|