CodeQL CI
4a59e69722
Merge pull request #4564 from asgerf/js/react-hooks
...
Approved by esbena
2020-10-30 21:00:31 +00:00
Taus
ecc52a1bb9
Merge pull request #4541 from RasmusWL/python-port-reflected-xss
...
Python: Port reflected XSS query
2020-10-30 19:17:33 +01:00
Rasmus Lerchedahl Petersen
80360450de
Merge branch 'main' of github.com:github/codeql into RasmusWL-python-port-reflected-xss
2020-10-30 17:56:36 +01:00
Taus
146787bb55
Merge pull request #4539 from yoff/python-port-path-injection
...
Python: port path injection
2020-10-30 17:46:51 +01:00
Rasmus Lerchedahl Petersen
ef9999a4a1
Python: fix test annotation
2020-10-30 17:43:56 +01:00
Rasmus Lerchedahl Petersen
37ad59a92a
Python: subclas of known subclasses
2020-10-30 17:37:54 +01:00
yoff
a3cc9b6982
Update python/ql/src/experimental/semmle/python/frameworks/Flask.qll
...
Co-authored-by: Taus <tausbn@github.com >
2020-10-30 17:29:35 +01:00
Cornelius Riemenschneider
310975bf8d
Merge pull request #4581 from criemen/printast-stmtpexpr
...
C++: Add support for StmtExpr to Print AST.
2020-10-30 17:29:23 +01:00
Asger Feldthaus
c7667d372e
JS: Address review comments
2020-10-30 16:25:30 +00:00
Cornelius Riemenschneider
e7d995313e
C++: Address review.
2020-10-30 16:30:57 +01:00
Cornelius Riemenschneider
84fe7ba199
C++: Add support for StmtExpr to Print AST.
2020-10-30 15:53:54 +01:00
Cornelius Riemenschneider
d3631d8f2e
Merge pull request #4562 from criemen/printast-labels
...
C++: Change PrintAST to provide the predicates that can be used to traverse the AST.
2020-10-30 15:48:46 +01:00
Dave Bartolomeo
36b27add24
Simplify ordering of children with conversions using rank
...
In `getChild(int childIndex)`, the actual values of `childIndex` don't matter, as long as they are in the correct order. Rather than doing complicated math to compute the indices for the synthesized `.getFullyConverted()` children, just use the `rank` aggregate to order all children first by whether or not the child is a conversion, then by the original child index.
2020-10-30 10:00:23 -04:00
Rasmus Lerchedahl Petersen
e7c9bc388b
Python: support some custom subclasses
2020-10-30 14:16:48 +01:00
Rasmus Lerchedahl Petersen
e69349791a
Python: django.http.response.HttpRequest.write
2020-10-30 12:51:23 +01:00
Cornelius Riemenschneider
cf8f802310
C++: Rename predicate.
2020-10-30 12:51:19 +01:00
Cornelius Riemenschneider
ab42ddb0dc
C++: Adjust code for the conversions PR, provide correct childIndexes for the new nodes.
2020-10-30 12:48:53 +01:00
Rasmus Lerchedahl Petersen
ffe10d1b7c
Python: test HttpResponse.write
2020-10-30 12:16:12 +01:00
Rasmus Lerchedahl Petersen
fa3a7e6686
Python: Known subclasses of HttpResponse
2020-10-30 11:53:24 +01:00
Rasmus Lerchedahl Petersen
c962377ef4
Python: test for subclasses
2020-10-30 10:37:40 +01:00
Asger Feldthaus
6ab7846e81
JS: Restrict getAContextInput
2020-10-30 09:28:06 +00:00
Jonas Jensen
ba41417d61
Merge pull request #4553 from geoffw0/samateregtests
...
C++: Additional pointer tests for DefaultTaintTracking.
2020-10-30 10:02:11 +01:00
Tom Hvitved
54e2741064
Merge pull request #4580 from hvitved/csharp/1.26-change-notes
...
C#: Convert 1.26 change notes
2020-10-30 09:17:52 +01:00
Tom Hvitved
91d72945d7
Merge pull request #4568 from hvitved/csharp/cfg/multi-asserts
...
C#: Fix CFG for assertions with multiple assertion arguments
2020-10-30 09:13:38 +01:00
Rasmus Lerchedahl Petersen
08af839757
Python: django.http.response.HttpResponseRedirect
2020-10-30 01:29:49 +01:00
Rasmus Lerchedahl Petersen
52be896666
Python: django.http.response.JsonResponse
...
It s possible this class is not relevant to XSS
2020-10-30 01:05:36 +01:00
Rasmus Lerchedahl Petersen
0f9b8595d1
Python: rename functions by vulnerability
2020-10-30 00:51:09 +01:00
Rasmus Lerchedahl Petersen
97153b56ad
Python: add false negatives to test
2020-10-30 00:48:19 +01:00
Rasmus Lerchedahl Petersen
262b249e10
Merge branch 'main' of github.com:github/codeql into RasmusWL-python-port-reflected-xss
2020-10-30 00:40:39 +01:00
Rasmus Lerchedahl Petersen
2ca86f5ea7
Python: django.http.response.HttpResponse
2020-10-30 00:22:53 +01:00
Dave Bartolomeo
71531af343
Merge pull request #4577 from dbartol/extension-fix/work
...
Fix path transformer handling of extensionless files
2020-10-29 18:10:30 -04:00
Tom Hvitved
0111f140de
C#: Convert 1.26 change notes
2020-10-29 20:23:07 +01:00
yo-h
5ac8475523
Merge pull request #4578 from aschackmull/java/changenotes
...
Java: Add missing change notes for 1.26
2020-10-29 13:32:28 -04:00
Anders Schack-Mulligen
5687b7c158
Java: Move existing change note to new format.
2020-10-29 16:35:27 +01:00
Anders Schack-Mulligen
a9e0f61860
Java: Add change note for https://github.com/github/codeql/pull/4287
2020-10-29 16:33:09 +01:00
Anders Schack-Mulligen
4cd77175ab
Java: Add change note for https://github.com/github/codeql/pull/3542
2020-10-29 16:27:51 +01:00
Anders Schack-Mulligen
eddd1ef29c
Java: Add change note for https://github.com/github/codeql/pull/4081
2020-10-29 16:25:11 +01:00
Anders Schack-Mulligen
e671b463dc
Java: Add change note for https://github.com/github/codeql/pull/4123
2020-10-29 16:20:35 +01:00
Anders Schack-Mulligen
d6f595f6af
Java: Add change note for https://github.com/github/codeql/pull/3543
2020-10-29 16:14:56 +01:00
Anders Schack-Mulligen
8b6c3ab9d2
Java: Add change note for https://github.com/github/codeql/pull/4088
2020-10-29 16:11:26 +01:00
Anders Schack-Mulligen
1efb377465
Java: Add change note for https://github.com/github/codeql/pull/3855
2020-10-29 16:09:01 +01:00
Anders Schack-Mulligen
d9cef5bd48
Java: Add change note for https://github.com/github/codeql/pull/4044
2020-10-29 16:05:43 +01:00
Anders Schack-Mulligen
4677eb649e
Java: Add change note for https://github.com/github/codeql/pull/3938
2020-10-29 16:02:34 +01:00
Anders Schack-Mulligen
9dbfc835fe
Java: Add change note for https://github.com/github/codeql/pull/3881
2020-10-29 15:54:25 +01:00
Tom Hvitved
51f71d4e1d
C#: Fix CFG for assertions with multiple assertion arguments
2020-10-29 15:44:13 +01:00
Tom Hvitved
5cd707f17e
C#: Add CFG test for assertion with multiple assertion arguments
2020-10-29 15:44:13 +01:00
Anders Schack-Mulligen
b3fe333957
Merge pull request #4576 from aschackmull/java/adjust-beanvalidation-qhelp
...
Java: Tweak qhelp to make it markdown-compatible.
2020-10-29 15:43:40 +01:00
Anders Schack-Mulligen
1beb3bdccd
Java: Add change note for extensible security queries.
...
This covers #3928 , #3968 , and #4172 , among others.
2020-10-29 15:37:35 +01:00
Anders Schack-Mulligen
e3ba05937f
Java: Add change note for https://github.com/github/codeql/pull/3948
2020-10-29 15:30:09 +01:00
Anders Schack-Mulligen
7f9713956f
Java: Add change note for https://github.com/github/codeql/pull/4312 .
2020-10-29 15:24:28 +01:00