Anders Schack-Mulligen
|
1c081eeaed
|
Java: Update coverage.
|
2021-06-01 14:00:05 +02:00 |
|
Anders Schack-Mulligen
|
fc913e744e
|
Java: Minor model fix.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
dbe352f3ff
|
Java: Remove deprecated tests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
901996f9fd
|
Java: Add collection flow test.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
43d1b0ab27
|
Java: Update qltests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
a40880af70
|
Java: Add read-as-taint and config-dependent store-as-taint.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
2f087e17cb
|
Java: Allow <> in types for now.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
3f538e7fac
|
Java: Update some models.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
9e313d0cf6
|
Java: Remove container taint steps.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
3b6cef4f74
|
Java: Add container flow models.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
ffd52bb673
|
Java: Fix bug in matching generic signatures.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
1001dd84e6
|
Java: Switch array steps and one containerstep.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
ce509eb7e1
|
Merge pull request #5927 from aschackmull/dataflow/flowthrough-dispatch-perf
Dataflow: Improve performance in flow-through pruning
|
2021-06-01 11:46:22 +02:00 |
|
Anders Schack-Mulligen
|
a4661e1aca
|
Merge pull request #5704 from edvraa/regexj
Java: Regex injection
|
2021-06-01 11:45:59 +02:00 |
|
Anders Schack-Mulligen
|
5d21c64247
|
Dataflow: qldoc fix.
|
2021-06-01 10:49:47 +02:00 |
|
Anders Schack-Mulligen
|
4f9a6c151b
|
Dataflow: Code review fixes.
|
2021-06-01 10:29:17 +02:00 |
|
Anders Schack-Mulligen
|
683f853fa5
|
Dataflow: Fix another bad join order.
|
2021-05-31 15:14:13 +02:00 |
|
Erik Krogh Kristensen
|
79989cc3f4
|
CPP/Java: Fix getAPrimaryQlClass implementations
|
2021-05-27 21:36:27 +02:00 |
|
Tamás Vajk
|
1997f500c2
|
Merge pull request #5832 from tamasvajk/feature/csv-coverage-report
Java: github action for CSV coverage report
|
2021-05-25 14:51:19 +02:00 |
|
Anders Schack-Mulligen
|
d05f524759
|
Merge pull request #5941 from aschackmull/java/virt-disp-perf
Java: Improve performance of virtual dispatch calculation.
|
2021-05-25 14:44:51 +02:00 |
|
Tamas Vajk
|
70b3066bb8
|
Add regenerated CSV reports
|
2021-05-25 13:38:22 +02:00 |
|
Tamas Vajk
|
d4f1cbe8d8
|
Add updated coverage report
|
2021-05-25 13:33:26 +02:00 |
|
Tamas Vajk
|
3db22ba482
|
Add Java coverage report files
|
2021-05-25 13:33:26 +02:00 |
|
Tamas Vajk
|
f1911e338d
|
Move and generate files to documentation folder + clean up after the script is executed
|
2021-05-25 13:33:26 +02:00 |
|
Anders Schack-Mulligen
|
4884da363f
|
Java: Bugfix.
|
2021-05-25 11:48:35 +02:00 |
|
Anders Schack-Mulligen
|
017bf68906
|
Dataflow: Fix bad join order.
|
2021-05-25 11:40:53 +02:00 |
|
Anders Schack-Mulligen
|
d00618f4f4
|
Java: Improve performance of virtual dispatch calculation.
|
2021-05-21 15:04:08 +02:00 |
|
Sebastian Bauersfeld
|
ffcca4d5e9
|
Add change note.
|
2021-05-20 20:07:14 +07:00 |
|
Sebastian Bauersfeld
|
28f597440f
|
Add method invocations of Spring's SavedRequest as a remote sources.
|
2021-05-20 20:00:14 +07:00 |
|
Anders Schack-Mulligen
|
4406b8e339
|
Dataflow: Sync.
|
2021-05-19 19:22:36 +02:00 |
|
Anders Schack-Mulligen
|
bb258813a1
|
Dataflow: Improve performance for dispatch-join in flow-through.
|
2021-05-19 19:20:57 +02:00 |
|
luchua-bc
|
02aa9c6fc7
|
Optimize the sink and update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
d4323a4a54
|
Update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
9d392263a5
|
Refactor inconsistent method names
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2fa249a8eb
|
Update method name and qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2c1374bdcf
|
Use inline implementation for ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
0ac8453398
|
Allow all arguments of methods in ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
e4699f7fa9
|
Optimize the query
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
d664aa6d6a
|
Include more scenarios and update qldoc
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
852bcfb5c7
|
Refactor the ScriptEngine query and the Rhino code injection query into one
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
b0b5338359
|
Rhino code injection
|
2021-05-18 16:12:22 +00:00 |
|
Chris Smowton
|
4230869ee2
|
Merge pull request #5819 from luchua-bc/java/jpython-injection
Java: CWE-094 Jython code injection
|
2021-05-18 16:38:40 +01:00 |
|
Chris Smowton
|
71f540a755
|
Merge pull request #5844 from haby0/SpringRedirects
[Java] CWE-601 Spring url redirection detect
|
2021-05-18 16:37:40 +01:00 |
|
luchua-bc
|
2a0721b2ae
|
Optimize the sink and update method name
|
2021-05-18 12:18:14 +00:00 |
|
haby0
|
e46de44473
|
Solve errors caused by private ownership
|
2021-05-18 19:56:32 +08:00 |
|
haby0
|
caf5f4d605
|
modified comment
|
2021-05-18 19:10:03 +08:00 |
|
Anders Schack-Mulligen
|
9b0e3b1950
|
Merge pull request #5814 from JLLeitschuh/feat/JLL/jackson_as_taint_step
[Java] Add taint tracking through Jackson deserialization
|
2021-05-18 09:31:16 +02:00 |
|
haby0
|
a0cd551bae
|
Add filtering of String.format
|
2021-05-18 11:05:10 +08:00 |
|
luchua-bc
|
e652d8771c
|
Update method name and qldoc
|
2021-05-17 20:36:15 +00:00 |
|
Anders Schack-Mulligen
|
77c93dcf26
|
Make private
|
2021-05-17 10:35:04 +02:00 |
|