Edward Minnix III
|
1f37e70d83
|
Fix typos
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2024-01-08 09:38:51 -05:00 |
|
Ed Minnix
|
51006aa088
|
Formatting fix
|
2024-01-08 09:38:50 -05:00 |
|
Ed Minnix
|
6eff72f99a
|
Include other map mutations
|
2024-01-08 09:38:49 -05:00 |
|
Ed Minnix
|
4fc6f710a4
|
Fix alert message
|
2024-01-08 09:38:48 -05:00 |
|
Ed Minnix
|
1550f5df2a
|
Environment variable injection query documentation
|
2024-01-08 09:38:47 -05:00 |
|
Ed Minnix
|
f1f0f50c92
|
TaintedEnvironmentVariableQuery docs
|
2024-01-08 09:38:47 -05:00 |
|
Ed Minnix
|
818c5de8d5
|
security-severity metadata
|
2024-01-08 09:38:46 -05:00 |
|
Ed Minnix
|
d4e2b84348
|
Cleanup helper dataflow configuration
|
2024-01-08 09:38:45 -05:00 |
|
Ed Minnix
|
f05f16116b
|
Testing for Environment variable injection
|
2024-01-08 09:38:45 -05:00 |
|
Ed Minnix
|
8ed3f3c865
|
Move to library
|
2024-01-08 09:38:44 -05:00 |
|
Ed Minnix
|
814885f7f6
|
Hudson environment variables models
|
2024-01-08 09:38:43 -05:00 |
|
Ed Minnix
|
028bd49211
|
org.apache.commons.exec models
|
2024-01-08 09:38:42 -05:00 |
|
Ed Minnix
|
b482b36b5f
|
Initial ProcessBuilder support
|
2024-01-08 09:38:41 -05:00 |
|
Ed Minnix
|
ad32b81492
|
environment-injection sink
|
2024-01-08 09:38:41 -05:00 |
|
Ed Minnix
|
93025cc8cf
|
Argument injection initial commit
|
2024-01-08 09:38:40 -05:00 |
|
Tony Torralba
|
7e6f2d1fc5
|
Merge pull request #14681 from atorralba/atorralba/java/weak-randomness-cve-coverage
Java: Add more sinks to the Insecure Randomness query
|
2024-01-08 15:33:03 +01:00 |
|
Chris Smowton
|
8144d90d4d
|
Merge pull request #15227 from smowton/smowton/admin/add-test-buildless-maven-multimodule
Add test for Java buildless vs Maven multimodule projects
|
2024-01-04 16:36:44 +00:00 |
|
Ian Wright
|
dab28edfa9
|
0.0.11 release of automodel extraction queries
|
2024-01-04 13:10:46 +00:00 |
|
Chris Smowton
|
c90171c73f
|
Add test for Java buildless vs Maven multimodule projects
|
2024-01-04 12:30:13 +00:00 |
|
Ian Wright
|
468454645e
|
better
|
2024-01-04 11:15:05 +00:00 |
|
Ian Wright
|
4530510450
|
check if provided argument is valid
|
2024-01-04 11:02:58 +00:00 |
|
Ian Wright
|
545b5e7e83
|
better comment
|
2024-01-04 11:02:58 +00:00 |
|
Ian Wright
|
fb44b9c7dd
|
better comment
|
2024-01-04 11:02:57 +00:00 |
|
Ian Wright
|
e4a798e9cc
|
better comment
|
2024-01-04 11:02:57 +00:00 |
|
Ian Wright
|
af940f5e41
|
don't specify defaults
|
2024-01-04 11:02:57 +00:00 |
|
Ian Wright
|
45b1790fa2
|
add publication warning
|
2024-01-04 11:02:57 +00:00 |
|
Ian Wright
|
337512174f
|
wip
wip
wip
more checks
fix bug if release folder already exists
fix bug if release folder already exists
ensure branch has correct release; dry-run
simplify branches
step by step
fix paths
pushd/popd
pushd/popd
use bash
simplify
simplify
simplify
simplify
add dry run
|
2024-01-04 11:02:57 +00:00 |
|
Ian Wright
|
6572be668c
|
get release version
|
2024-01-04 11:02:57 +00:00 |
|
Ian Lynagh
|
7b48e2e4ae
|
Merge pull request #15049 from igfoo/igfoo/UnderscoreIdentifier
Kotlin 2: Accept changes in query-tests/UnderscoreIdentifier
|
2024-01-03 13:43:24 +00:00 |
|
Aditya Sharad
|
bbe3269b8c
|
Merge pull request #15189 from github/adityasharad/merge/3.12-main
Merge `rc/3.12` into `main`
|
2023-12-22 11:26:37 -08:00 |
|
Edward Minnix III
|
d6d76fa4f1
|
Merge pull request #15183 from egregius313/egregius313/java/fix-weak-hashing-adddition
Java: Fix minor error in `java/potentially-weak-cryptographic-algorithm`
|
2023-12-22 11:38:55 -05:00 |
|
Arthur Baars
|
c5b6f48569
|
Merge pull request #15127 from smowton/smowton/feature/buildless-tests
Add buildless tests
|
2023-12-22 11:39:16 +01:00 |
|
Tony Torralba
|
67f8bcce44
|
Merge pull request #14752 from masterofnow/LoadClassNoSignatureCheck
Java: Insecure Loading of Class in Android App without Package Signature Checking
|
2023-12-22 10:24:34 +01:00 |
|
Tony Torralba
|
8ad787f3b8
|
Java: Generelize MaybeBrokenCryptoAlgorithmQuery.qll
|
2023-12-22 10:15:40 +01:00 |
|
Ed Minnix
|
8051cfcef5
|
Fix tests and fix getStringValue method
|
2023-12-21 22:48:08 -05:00 |
|
Ed Minnix
|
6455e1893d
|
Add more test cases
|
2023-12-21 22:48:08 -05:00 |
|
Ed Minnix
|
7f9dff2dc7
|
Fix minor error in Weak Hashing
|
2023-12-21 22:48:07 -05:00 |
|
Aditya Sharad
|
b1803d0ac2
|
Merge rc/3.12 into main
|
2023-12-21 16:40:51 -08:00 |
|
masterofnow
|
0fd09759df
|
Added sample java file for qhelp to render correctly.
|
2023-12-22 08:31:23 +08:00 |
|
masterofnow
|
cb5733d647
|
Apply suggestions from code review
Update to documentation.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-22 08:25:05 +08:00 |
|
masterofnow
|
7162540faf
|
Added options, .qhelp and .expected file for unit test.
|
2023-12-21 19:57:37 +08:00 |
|
masterofnow
|
8dc522fb5f
|
Merge remote-tracking branch 'origin/LoadClassNoSignatureCheck' into LoadClassNoSignatureCheck
|
2023-12-21 12:15:06 +08:00 |
|
masterofnow
|
25c818f425
|
Added unit test files.
|
2023-12-21 12:13:00 +08:00 |
|
github-actions[bot]
|
d77e8df800
|
Add changed framework coverage reports
|
2023-12-21 00:16:28 +00:00 |
|
Tony Torralba
|
1b9f59efa7
|
Merge pull request #14646 from github/java/update-mad-decls-after-triage-2023-10-31T15-52-01
Java: Update MaD Declarations after Triage
|
2023-12-20 15:37:19 +01:00 |
|
Tony Torralba
|
39708524e7
|
Minor fixes
- Query ID
- MethodAccess -> MethodCall
- Redundant import
- Formatting
|
2023-12-20 15:31:09 +01:00 |
|
Tony Torralba
|
e744d974e8
|
Merge pull request #14580 from github/java/update-mad-decls-after-triage-2023-10-24T15-42-01
Java: Update MaD Declarations after Triage
|
2023-12-20 15:01:24 +01:00 |
|
Tony Torralba
|
2df8bcb9dc
|
Update java/ql/lib/change-notes/2023-10-31-new-models.md
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-12-20 14:59:07 +01:00 |
|
masterofnow
|
e85c4b5bf6
|
Update query from code review feedback to express it as a dataflow problem.
|
2023-12-20 18:28:16 +08:00 |
|
Ed Minnix
|
a93d6dd956
|
Change note
|
2023-12-19 10:28:23 -05:00 |
|