Jeroen Ketema
|
9c774ac97f
|
Merge pull request #13426 from jketema/inline-3
Update inline flow tests to use parameterized module
|
2023-06-19 17:39:29 +02:00 |
|
Tony Torralba
|
5cb451b040
|
Merge pull request #13475 from atorralba/atorralba/many/zipslip-docs-update
C#/Go/Java/JS/Python/Ruby: Update the description and qhelp of the Zipslip query
|
2023-06-19 14:33:44 +02:00 |
|
Arthur Baars
|
ea97c3ea83
|
Merge pull request #13423 from aibaars/update-grammar-3
Ruby: update grammar
|
2023-06-19 10:54:12 +02:00 |
|
Jeroen Ketema
|
6a84e6cbfd
|
Add the merged PathGraph to all copies of the InlineFlowTest library
|
2023-06-19 10:28:10 +02:00 |
|
Tony Torralba
|
8f6d2ed2f9
|
Adjust ZipSlip query description according to review suggestions.
|
2023-06-19 10:27:41 +02:00 |
|
Tony Torralba
|
3c4d938cf1
|
Apply code review suggestions.
Co-authored-by: Asger F <asgerf@github.com>
|
2023-06-19 10:20:19 +02:00 |
|
Tony Torralba
|
433fc680ec
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-06-19 10:17:40 +02:00 |
|
Maiky
|
849e732c48
|
typos
|
2023-06-19 01:16:27 +02:00 |
|
Tony Torralba
|
c97868f774
|
Add change notes
|
2023-06-16 09:01:02 +02:00 |
|
Tony Torralba
|
3e96fe60c5
|
Go/Java/JS/Python/Ruby: Update the description and qhelp of the ZipSlip query
All filesystem operations, not just writes, with paths built from untrusted archive entry names are dangerous
|
2023-06-16 08:52:44 +02:00 |
|
Jeroen Ketema
|
d82c3ce11a
|
Ruby: Rewrite InlineFlowTest as a parameterized module
|
2023-06-15 10:52:23 +02:00 |
|
Michael Nebel
|
afec9b05e9
|
Merge pull request #13147 from michaelnebel/csharp/entityframeworkrefactor
C#: Use synthetic global in the EntityFramework code instead of jump steps.
|
2023-06-14 13:47:56 +02:00 |
|
Anders Schack-Mulligen
|
1a4fca334f
|
Merge pull request #13273 from aschackmull/dataflow/summarynode-refactor
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-14 09:38:36 +02:00 |
|
Anders Schack-Mulligen
|
2d616d494e
|
C#/Ruby: Add fields as per review comments.
|
2023-06-13 11:26:30 +02:00 |
|
Jeroen Ketema
|
c3ba206b6a
|
Merge pull request #13346 from jketema/inline-2
Update inline expectation tests to use parameterized module
|
2023-06-13 10:10:55 +02:00 |
|
Asger F
|
0d45074caa
|
Merge pull request #13422 from asgerf/rb/map_filter
Ruby: fix bug in filter_map summary
|
2023-06-13 09:43:47 +02:00 |
|
Arthur Baars
|
fad73d71e5
|
Merge pull request #13307 from hmac/amammad-ruby-YAMLunsafeLoad
Ruby: Add YAML unsafe deserialization sinks
|
2023-06-12 10:43:37 +02:00 |
|
Asger F
|
452af312ff
|
Ruby: change note
|
2023-06-12 10:07:26 +02:00 |
|
Arthur Baars
|
dbcb1c2224
|
Ruby: update grammar
|
2023-06-09 16:23:28 +02:00 |
|
Anders Schack-Mulligen
|
5062442982
|
Go/Python/Ruby/Swift: Add stub.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
98f51d7f29
|
Dataflow: Sync.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
0c62901a67
|
Ruby: Fix tests.
|
2023-06-09 15:39:18 +02:00 |
|
Anders Schack-Mulligen
|
6020e4d0e3
|
C#/Go/Python/Ruby/Swift: Fix some more references.
|
2023-06-09 15:30:38 +02:00 |
|
Anders Schack-Mulligen
|
4e531af71b
|
Ruby: Adjust to FlowSummaryImpl changes.
|
2023-06-09 15:30:35 +02:00 |
|
Anders Schack-Mulligen
|
2cc5bde925
|
Dataflow: Sync.
|
2023-06-09 15:27:17 +02:00 |
|
Asger F
|
d47477bd3b
|
Ruby: update line numbers in expectation file
|
2023-06-09 14:52:21 +02:00 |
|
Asger F
|
a50d91ea48
|
Ruby: fix bug in filter_map summary
|
2023-06-09 14:31:10 +02:00 |
|
Anders Schack-Mulligen
|
1b7bbf6320
|
Merge pull request #13083 from aschackmull/dataflow/typestrengthen
Dataflow: Strengthen tracked types.
|
2023-06-09 13:23:30 +02:00 |
|
Jeroen Ketema
|
4485560f43
|
Ruby: Rewrite inline expectation tests to use parameterized module
|
2023-06-09 10:43:05 +02:00 |
|
Asger F
|
bdbbde347e
|
Merge pull request #13407 from asgerf/rb/restrict-orm-tracking
Ruby: restrict ORM tracking to calls
|
2023-06-09 09:13:01 +02:00 |
|
Anders Schack-Mulligen
|
d230509905
|
Dataflow: Address review comments.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
4399138c82
|
Dataflow: Fix QL4QL alert.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
53f2b8aab0
|
Dataflow: Sync.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
fd832416d8
|
Dataflow: Add empty type strengthening predicate for languages without type pruning.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
e8cea79f1d
|
Dataflow: Sync.
|
2023-06-09 08:37:35 +02:00 |
|
Asger F
|
74a9d9fa37
|
Revert "Ruby: update tree-sitter-ruby"
|
2023-06-08 15:29:36 +02:00 |
|
Asger F
|
d6741f655d
|
Ruby: restrict ORM tracking to calls
|
2023-06-08 14:01:51 +02:00 |
|
Alex Ford
|
22b9ab43c6
|
Merge pull request #13259 from alexrford/rb/actiondispatch-refactor
Ruby: Refactor and slightly expand `ActionDispatch` modelling
|
2023-06-08 11:08:36 +01:00 |
|
Tom Hvitved
|
cee70883f0
|
Merge pull request #12964 from hvitved/ruby/remove-synth-returns
Ruby: Remove canonical return nodes
|
2023-06-08 10:07:48 +02:00 |
|
Arthur Baars
|
dcd254adf8
|
Merge pull request #13399 from aibaars/update-ruby-grammar
Ruby: update tree-sitter-ruby
|
2023-06-07 19:53:33 +02:00 |
|
Arthur Baars
|
0efa212c40
|
Ruby: update tree-sitter-ruby
|
2023-06-07 19:27:46 +02:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|
Tom Hvitved
|
88c5700c24
|
Ruby: Use CallGraphConstruction in call graph construction
|
2023-06-07 09:02:03 +02:00 |
|
Tom Hvitved
|
4bf124bffe
|
Ruby/Python: Add CallGraphConstruction module for recursive type-tracking based call graph construction
|
2023-06-07 09:02:03 +02:00 |
|
Arthur Baars
|
7324d1705e
|
Merge branch 'main' into amammad-ruby-YAMLunsafeLoad
|
2023-06-06 12:09:06 +02:00 |
|
Alex Ford
|
c95cf5ad6f
|
Merge pull request #13062 from maikypedia/maikypedia/sqli-sink
Ruby: Add MySQL as SQL Injection Sink
|
2023-06-02 17:06:35 +01:00 |
|
Erik Krogh Kristensen
|
219ec9d05d
|
Merge pull request #13127 from erik-krogh/polReDoS
ReDoS: revert new superlinear algorithm.
|
2023-06-02 16:10:24 +02:00 |
|
Jeroen Ketema
|
5f64354a70
|
Merge pull request #13353 from jketema/expecation
Fix typo in spelling of expectation
|
2023-06-02 12:29:49 +02:00 |
|
erik-krogh
|
ac9ede4ec0
|
add change-notes
|
2023-06-02 11:58:11 +02:00 |
|
erik-krogh
|
c3e57382f7
|
Ruby: fix compilation
|
2023-06-02 11:58:08 +02:00 |
|