Robin Neatherway
f378513ea3
Add lines-of-code tags
...
This is a proposed method for advertising which queries are measuring
the lines of code in a project in a more robust manner than inspecting
the rule id.
Note that the python "LinesOfUserCode" query should _not_ have this
property, as otherwise the results of the two queries will be summed.
2021-05-14 11:20:43 +01:00
haby0
498c99e26c
Add left value, Add return expression tracing flow
2021-05-14 16:31:59 +08:00
Ethan P
406fb1e383
Update with Go custom build options
2021-05-13 17:29:34 -04:00
Erik Krogh Kristensen
9d60ec035f
fix casing on the uid regexp
2021-05-13 23:04:30 +02:00
Erik Krogh Kristensen
662e335424
keep python in sync
2021-05-13 22:54:39 +02:00
Erik Krogh Kristensen
51067af784
add "uid" (and friends) as maybe being sensitive account info
2021-05-13 22:34:10 +02:00
CodeQL CI
9b0c24abc2
Merge pull request #5876 from erik-krogh/moreAxios
...
Approved by asgerf
2021-05-13 08:03:33 -07:00
haby0
02e415045f
Delete RedirectBuilderFlowConfig
2021-05-13 15:48:15 +08:00
haby0
effa2b162a
Add spring url redirection detect
2021-05-13 09:55:37 +08:00
Erik Krogh Kristensen
34fbafafde
remove redundant "put" case
2021-05-12 22:34:44 +02:00
Mathias Vorreiter Pedersen
7d26aca793
C++: Add change-note.
2021-05-12 16:34:23 +02:00
Erik Krogh Kristensen
e0f78dde56
make the axios error catch match the non-error case
2021-05-12 16:23:37 +02:00
Mathias Vorreiter Pedersen
e94dab70b5
C++: Add sanitizers to cpp/uncontrolled-arithmetic.
2021-05-12 15:44:09 +02:00
Jonathan Leitschuh
48b50f93c2
Update java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll
...
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com >
2021-05-12 08:58:01 -04:00
Anders Schack-Mulligen
7974e3ad38
Merge pull request #5883 from zbazztian/consider-boxed-booleans-to-avoid-xxe-fps
...
Consider boxed booleans to avoid false positives for XXE.ql
2021-05-12 12:51:22 +02:00
Sebastian Bauersfeld
b05512a958
Add change notes.
2021-05-12 16:58:24 +07:00
Sebastian Bauersfeld
bf4d88175c
Consider boxed booleans to avoid false positives for XXE.ql
2021-05-12 16:40:00 +07:00
Geoffrey White
8f152b7380
Merge pull request #5877 from MathiasVP/detect-more-abs-in-overflow-library
...
C++: Detect more uses of `abs`
2021-05-12 10:02:12 +01:00
Tom Hvitved
fc121e1cbd
Merge pull request #5865 from tamasvajk/feature/remove-base-class-dependency-id
...
C#: Remove base class from type IDs in trap files
2021-05-12 10:30:31 +02:00
Tom Hvitved
961467e06e
C#: Always pass /p:UseSharedCompilation=false to dotnet build in auto builder
2021-05-12 10:15:04 +02:00
Anders Schack-Mulligen
a247ae4357
Merge pull request #5843 from JLLeitschuh/feat/JLL/improve_kryo_support
...
[Java] Fix Kryo FP & Kryo 5 Support
2021-05-12 09:52:24 +02:00
Anders Schack-Mulligen
74ae2e0857
Merge pull request #5773 from hvitved/dataflow/aggressive-caching
...
Data flow: Cache most language-dependent predicates
2021-05-12 09:41:55 +02:00
Tamas Vajk
8e371fd05a
Adjust expected IR test file
2021-05-11 21:54:05 +02:00
Mathias Vorreiter Pedersen
948f1d8e34
C++: Add testcase with INTMAX_MIN.
2021-05-11 19:43:21 +02:00
luchua-bc
e7cd6c9972
Optimize the query
2021-05-11 16:56:12 +00:00
Jonathan Leitschuh
5a68ac88ef
Cleanup Jackson logic after code review
2021-05-11 10:48:22 -04:00
Jonathan Leitschuh
bacc3ef5b3
[Java] Jackson add support for 2 step deserialization taint flow
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
e97bad3b33
Support field access data flow for JacksonDeserializedTaintStep
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
83d527ed19
Apply suggestions from code review
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
b871f48c50
[Java] Add release note to Jackson change
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
d0b0b767a2
Apply suggestions from code review
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
d0638db6e7
[Java] Add data flow through Iterator deserializers for Jackson
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
56b1f15dda
[Java] Add taint tracking through Jackson deserialization
2021-05-11 10:36:47 -04:00
Geoffrey White
d7e560c611
Merge pull request #5767 from ihsinme/ihsinme-patch-268
...
CPP: Add query for CWE-1126: Declaration of Variable with Unnecessarily Wide Scope
2021-05-11 15:24:25 +01:00
Mathias Vorreiter Pedersen
3e21f479a9
C++: Add change-note.
2021-05-11 14:58:48 +02:00
Tom Hvitved
d66506b0a3
Data flow: Rename {Argument,Parameter}NodeExt to {Arg,Param}Node
2021-05-11 14:40:10 +02:00
Mathias Vorreiter Pedersen
48e783184c
C++: Fix false positive by recognizing more absolute value functions in Overflow.qll
2021-05-11 14:30:28 +02:00
Jonathan Leitschuh
0d9a85ca6b
Update java/change-notes/2021-05-05-kryo-improvements.md
...
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com >
2021-05-11 08:29:50 -04:00
Mathias Vorreiter Pedersen
24d8abd2c2
C++: Add false positive testcase when an absolute value is used in comparison.
2021-05-11 14:27:53 +02:00
CodeQL CI
922b276fac
Merge pull request #5728 from asgerf/js/source-sink-queries
...
Approved by erik-krogh
codeql-cli/v2.5.5
2021-05-11 05:04:47 -07:00
Tamas Vajk
717070c7e4
Fix/cleanup passed and default arguments values
2021-05-11 13:11:35 +02:00
yoff
a7f97895ac
Merge pull request #5863 from erik-krogh/printReg
...
JS: add printAst.ql support for regular expressions
2021-05-11 12:45:49 +02:00
yoff
0e5a2c4573
Merge pull request #5442 from jorgectf/jorgectf/python/redos
...
Python: Add Regular Expression Injection query
2021-05-11 12:11:35 +02:00
yoff
549c9eee1a
Merge pull request #5739 from RasmusWL/share-sensitive-data-modeling
...
Python/JS: Share sensitive data modeling
2021-05-11 11:53:59 +02:00
CodeQL CI
a87731115a
Merge pull request #5860 from max-schaefer/js/improve-sql-modelling
...
Approved by asgerf
2021-05-11 02:24:52 -07:00
Erik Krogh Kristensen
99e98419dc
add support for error values in an axios client request
2021-05-11 11:24:21 +02:00
Erik Krogh Kristensen
52991dc4a1
rewrite the axios model to use API graphs
2021-05-11 11:23:51 +02:00
Erik Krogh Kristensen
54f191cfe3
add support for rejected promise values in API graphs
2021-05-11 11:23:03 +02:00
CodeQL CI
beb66fc4db
Merge pull request #5719 from asgerf/js/nestjs
...
Approved by esbena
2021-05-11 02:08:27 -07:00
Anders Schack-Mulligen
744c495ac2
Merge pull request #5824 from JLLeitschuh/feat/JLL/guava_first_non_null
...
[Java] Add support for com.google.common.base.MoreObjects#firstNonNull
2021-05-11 09:42:20 +02:00